Ask Question, Ask an Expert

+61-413 786 465

info@mywordsolution.com

Ask Homework Help/Study Tips Expert

In this assignment , you will be asked to forensically examine a hard drive for evidence. Your assignment is to examine the drive, gather evidence in a forensically-sound manner, and present a report of your investigation. The incident in question occurred in October, 2016. You should focus your investigation on that time window.

1. The Investigation Report - this is really the whole package

2. Physical evidence tag/label. Refer to textbook for information that should be included. If you use a template or example from the Interwebs, site your sources. ("Appendix A" to investigation report.)

3. Key Evidence listing. Should be a table of (at a minimum) files examined and their hashes. ("Appendix B" to the investigation report.)

4. Tools listing. Should be a table of (at a minimum) executables used to examine or process files, and their hashes. Definitely list a tool like "pasco". You probably don't need to include commands like "cd" or "ls". Unless you're doing a live system acquisition. ("Appendix C" to the investigation report.)

5. Your case investigation activity log (your notes). Either include scans of your notebook, or photos of the pages, or if you use electronic notes, the notes file.

A note on presenting actual evidence files. Do NOT create a printed version of the super timeline. In your report, highilight key events (e.g. software was installed, a document was deleted) and include the key timeline entry rows for the event, or the start/end of the event (software installation may produce many dozens of pages). Also Do NOT try to hexdumpthe entire hard drive and print it out.

INVESTIGATION REPORT:

The report should clearly and concisely present evidence. Avoid drawing any conclusions in the report. Start each section with a summary of the key findings for that section. List the basic steps you took to arrive at that conclusion. Make references to your notes ("see Case 001 notes, page 2"). Pictures with labels, or screenshots of tool output, are appropriate. Hashes are appropriate. Time and date labels of the steps are appropriate. Explanations such as "this file is of type XYZ and includes data about ABC" are appropriate. Pasting your command history from the terminal is too much detail. Use "Page X of YY" on every page. Label every page with the Case Number (you can make one up).

1. Title Page:

"CS 447/547: Case 0000-001, October 2016", author's name. File name.pdf.

2. Executive Summary

This should begin something like: "In the investigation of Case 0000-001, involving the examination of a suspect harddrive, I reviewed the filesystem, including X user profile(s), examined the activity of user "", and recovered Z deleted files. The evidence included in this report includes the following:" Use your own words, or mine.

3. Physical Evidence:

List the information you can determine from the drive you received, without opening it up and exposing the platters. Not necessary for this investigation.

4. File Systems and Partitions:

List the information you can determine about the file systems contained on this drive. Demonstrate that you have not altered the evidence.

5. Computer System Information

Mount the partitions and examine their contents. List the information you can determine about the system this was running on (e.g. what OS?, what users present? what software installed? important registry key values?)

6. Deleted files

Recover key deleted files and report on them.

7. Web browsing history

In one user's home directory, there is evidence of web-browsing activity. What can you determine from it?

8. Recovered emails

In one user's home directory, there is email. What can you recover from it?

9. Appendix A: Physical evidence

10. Appendix B: Key digital evidence

11. Appendix C: Tools used during investigation

12. Appendix D: Investigator's Notes

Homework Help/Study Tips, Others

  • Category:- Homework Help/Study Tips
  • Reference No.:- M92026171

Have any Question?


Related Questions in Homework Help/Study Tips

Question watch the video how to write an abstract of a

Question: Watch the video How to: Write an Abstract of a Research Paper (By Educator) Discuss how you narrow the research topic and what information sources are acceptable in research. Identify the source qualities that ...

Learning objectivesassessed1 explain the research process

Learning Objectives Assessed: 1. Explain the research process that underpins the evidence base for nursing practice 2. Discuss and critique commonly used research designs that inform health care practice Graduate Outcome ...

Question elaborate on the topic for your critical

Question: Elaborate on the Topic for Your Critical Review This assignment will be a continuation of the written assignment from Week One. Research a minimum of three peer-reviewed articles in addition to information from ...

Question your assignments for the term contain several

Question: Your assignments for the term contain several research papers based on a provided article or series of articles that mirrors a concept we will study for that week. Your weekly assignment page poses the question ...

Leading lean projects assessment - case study continuous

Leading Lean Projects Assessment - Case study: Continuous Improvement Introduction - Precision Engineering Works Private Limited (PEW) is an original equipment manufacturer specialising in plastic moulding parts for the ...

Process recordingsthe assignment 2-4 pagesprovide a

Process Recordings The Assignment (2-4 pages): Provide a transcript of what happened during your field education experience, including a dialogue of interaction witha client. Explain your interpretation of what occurred ...

Discussionnbsp topic selectionyour written response to

Discussion  : Topic Selection Your written response to this discussion prompt assesses your ability to explain the role of action research from the viewpoint of an educational professional. This discussion also supports ...

Discussion 1very young children are usually highly

Discussion 1 Very young children are usually highly motivated to learn (such as exploring gravity by dropping things from the highchair), but this often declines as they grow. With your readings in mind, think about your ...

Case questions 1the universal power supply may be

Case Questions: 1. The universal power supply may be considered a postponement strategy by reducing the anticipated risks that may arise in a supply chain. It also may design generic parts that may be shared between ware ...

Assignmentnbsp - religion and americans moral implications

Assignment  - Religion and Americans: Moral Implications. One of the more common arguments I hear when discussing ethics, morals, and values is that in the United States we were founded on religious, primarily Christian, ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As