Assignment- E-mail Forensics

The purpose of this lab is to learn more about forensic analysis of e-mail using FTK to present evidence and create a report.

Use the version of FTK (1.81.2) available on the Nelson textbook CD or downloaded from the shared course drive to process the Lab file under Course Content.

As with other labs, it is important in this lab to not only discuss the processes and results but also show them. Make sure take screenshots and discuss them. Please make sure to embed them in your document and label them (e.g., Lab4-Image1: Complete E-Mail Header).


For this lab, analyze the <Jim_Shu.pst> file to collect and present evidence that implicates him in industrial espionage. Jim's company suspects him of selling designs and other information to a competitor. The company has hired you to collect and present evidence that supports their suspicions.

You will need the image in the Course Content called Lab4.pst

1. Use FTK to analyze all e-mail messages found in the pst file.

2. Find correspondence that supports the company's suspicions. The company wants a solid case, so showing the information was exchanged is important.

3. Write a report that will be presented to the company that includes screens of e-mail messages to support your findings.

