Ask Question, Ask an Expert

+61-413 786 465

info@mywordsolution.com

Ask Software Engineering Expert

Introduction

The objective of computer forensics is to recover, analyze, and present computer-based material in such a way that it can be used as evidence in a court of law. However, whenever forensic investigators explore a machine in search of evidence, they risk changing the very data they seek, potentially invalidating evidence. For this reason, they use tools that incorporate write-blocking technologies and can be run without having to be installed on the target machine. These bootable tools provide ease of access within the imaged, virtualized, or write-blocked copy of the original system without compromising the workstation or user profiles.

These tools can collect valuable forensic data from a workstation as well as from a specific user without changing the workstation environment or user profiles. Potential data sources can include the following:

Current running processes
Popular Internet browsers, used such as Internet Explorer, Chrome, and Firefox
Browser cache, cookies, history, favorites, or bookmarks that have been created, used, or accessed
Search engine queries from sources such as Google, Bing, and Yahoo!
Social networking sites visited (Twitter, Facebook, and so on)

The data gathered can then be analyzed to identify evidence. The difference between data and evidence is that data is a collection of facts from which you can draw conclusions, while evidence is a specific type of data that proves or disproves a hypothesis or accusation.
In this lab, you will use a variety of forensic tools. These tools are independent executables, meaning they run locally on the workstation or server under investigation. You will document specific data from each tool.

In the first part of the lab, you will use a tool to identify system information and gather details about the images on the machine under investigation.

In the second part of the lab, you will explore different forensic utility tools to get additional data on running processes, favorites, cached items, cookies, and browser searches.

If assigned by your instructor, you will explore the virtual environment on your own to answer a set of challenge questions that allow you to use the skills you learned in the lab to conduct independent, unguided work, similar to what you will encounter in a real-world situation.

Learning Objectives

Upon completing this lab, you will be able to:

Gather potential forensic evidence from a running system.

Identify the system state and potential evidence in a forensically sound manner.

Explore a variety of bootable forensic utilities to uncover potential evidence and preserve forensic integrity.

Distinguish which forensic evidence or investigative tools can be used to collect specific data.

Create a report of the running processes and browser usage for a Windows workstation.

Using Helix, run a WinAudit report and save it as yourname_WinAuditChallenge.pdf, replacing yourname with your own name. Save the file to the Storage (E:) folder.

In your Challenge Questions file, describe the errors found in the error logs of the Helix WinAudit report.

What is the main advantage of a bootable forensic suite like Helix?

Describe five ways in which Process Explorer (procexp) can be used in computer forensics as part of an investigation.

Which forensics tool would you use to reveal recent searches via the Internet Explorer browser?

How would IECacheView help a forensic investigator?

All the tools used in this lab are intended to analyze data. What is the difference between data and evidence?

Software Engineering, Computer Science

  • Category:- Software Engineering
  • Reference No.:- M92260464
  • Price:- $45

Priced at Now at $45, Verified Solution

Have any Question?


Related Questions in Software Engineering

Assignment lab - statement of workclient liberty vacation

Assignment Lab - Statement of Work Client: Liberty Vacation Planning Inc. (LVP) Project: Website Assessment 1. Project Objectives With this statement of work, LVP is engaging you to conduct a website assessment to determ ...

Proposaldesign of an efficient gps tracking system tag for

Proposal Design of an efficient GPS Tracking System (tag) for monitoring small species IMPLEMENTING EMBEDDED SYSTEMS USING SYSML Task Using PapyrusSysML Software (Downloadable online - Evaluation Copy- Latest Version) Mo ...

Assignment part 1objectives to learn to identify the

Assignment Part 1 Objectives: To learn to identify the relevant use cases for a given application, describe the use cases and develop an object-oriented domain model. Problem Statement - Standing Orders Management System ...

Write review on this article with apa formatgovernment

Write review on this article with APA format. Government surveillance is a major issue in the United States and globally. Surveillance refers to any collection and processing of personal data, whether, identifiable or no ...

In this assignment you will answer the following review

In this assignment, you will answer the following review questions from the reading materials of the module/week. 1. "What are the key components of a typical P2P application? Describe their functions." 2. "What are the ...

The research paper for this course is about some of the

The research paper for this course is about some of the best sources of digital evidence for child abuse and exploitation, domestic violence, and gambling according to the National Institute of Justice. Research commerci ...

Instructionsprivacy-preserving data miningdata mining

INSTRUCTIONS PRIVACY-PRESERVING DATA MINING Data mining technology can be exploited to reveal sensitive information from the original data. Thus it is important to preservethe privacy of the parties that the data refer t ...

In this assignment you will answer the following questions

In this assignment, you will answer the following questions related to Android platform and Android security design. 1. Describe Android architecture in detail by explaining the four conceptual layers. 2. Describe Androi ...

Write review on this article with apa formatalthough

Write review on this article with APA format. Although computer crimes are being seen in our society more and more each day, it is still difficult to prosecute people who commit these crimes mainly because everything is ...

Instructions - onion routingin this assignment you will

INSTRUCTIONS - ONION ROUTING In this assignment, you will answer the following questions related to Onion Routing and Tor. 1. Describe the infrastructure of Onion Routing and explain how it works for providing anonymity ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As