Identify the system state and potential evidence

Assignment Help Software Engineering
Reference no: EM131451724

Introduction

The objective of computer forensics is to recover, analyze, and present computer-based material in such a way that it can be used as evidence in a court of law. However, whenever forensic investigators explore a machine in search of evidence, they risk changing the very data they seek, potentially invalidating evidence. For this reason, they use tools that incorporate write-blocking technologies and can be run without having to be installed on the target machine. These bootable tools provide ease of access within the imaged, virtualized, or write-blocked copy of the original system without compromising the workstation or user profiles.

These tools can collect valuable forensic data from a workstation as well as from a specific user without changing the workstation environment or user profiles. Potential data sources can include the following:

Current running processes
Popular Internet browsers, used such as Internet Explorer, Chrome, and Firefox
Browser cache, cookies, history, favorites, or bookmarks that have been created, used, or accessed
Search engine queries from sources such as Google, Bing, and Yahoo!
Social networking sites visited (Twitter, Facebook, and so on)

The data gathered can then be analyzed to identify evidence. The difference between data and evidence is that data is a collection of facts from which you can draw conclusions, while evidence is a specific type of data that proves or disproves a hypothesis or accusation.
In this lab, you will use a variety of forensic tools. These tools are independent executables, meaning they run locally on the workstation or server under investigation. You will document specific data from each tool.

In the first part of the lab, you will use a tool to identify system information and gather details about the images on the machine under investigation.

In the second part of the lab, you will explore different forensic utility tools to get additional data on running processes, favorites, cached items, cookies, and browser searches.

If assigned by your instructor, you will explore the virtual environment on your own to answer a set of challenge questions that allow you to use the skills you learned in the lab to conduct independent, unguided work, similar to what you will encounter in a real-world situation.

Learning Objectives

Upon completing this lab, you will be able to:

Gather potential forensic evidence from a running system.

Identify the system state and potential evidence in a forensically sound manner.

Explore a variety of bootable forensic utilities to uncover potential evidence and preserve forensic integrity.

Distinguish which forensic evidence or investigative tools can be used to collect specific data.

Create a report of the running processes and browser usage for a Windows workstation.

Using Helix, run a WinAudit report and save it as yourname_WinAuditChallenge.pdf, replacing yourname with your own name. Save the file to the Storage (E:) folder.

In your Challenge Questions file, describe the errors found in the error logs of the Helix WinAudit report.

What is the main advantage of a bootable forensic suite like Helix?

Describe five ways in which Process Explorer (procexp) can be used in computer forensics as part of an investigation.

Which forensics tool would you use to reveal recent searches via the Internet Explorer browser?

How would IECacheView help a forensic investigator?

All the tools used in this lab are intended to analyze data. What is the difference between data and evidence?

Verified Expert

This assignment was to write the assessment question and answer for Helix lab. We have answered all of the questions in word doc. Along with this, we have written one challenging question also in word.

Reference no: EM131451724

Questions Cloud

Is email the best way to convey such a message : Imagine receiving the following email from your CEO: We are getting less than 40 hours of work from a large number of our EMPLOYEES.
Analyze two data transmission technologies associated : WAN Technologies Paper: Define each protocol and describe at least two data transmission technologies associated with the protocol.
Research scholarly articles or free media such as ted talks : select one of the toolssuch as: strategic planning, re-engineering, quality management, benchmarking, team management, and leveraging the private sector.
What were the sources of conflict between bell and sharpe : Two friends and neighbours arrange to go into business together and then become bitter rivals: This is the story of Bob Bell and Michael Sharpe.
Identify the system state and potential evidence : What is the main advantage of a bootable forensic suite like Helix - Describe five ways in which Process Explorer (procexp) can be used in computer forensics as part of an investigation.
Explain why the police might choose that course of action : Post two challenges the police faced in the Supreme Court cases related to using force against suspected offenders.
Calculate the expected return for the portfolio : Calculate the Expected return for the portfolio using the CAPM and the beta value for the portfolio
Determine the cloud computing needs of the organization : Determine the cloud computing needs of the organization. Identify three vendors that could address the cloud computing needs of the organization.
What was the instructors response : In one of your classes practise giving feedback to your instructor. Talk with your instructor outside class, indicating what you like about the class.

Reviews

inf1451724

4/14/2017 6:25:07 AM

Hi, Really great cost, OK quality work, and accommodating support groups. Incredible experience in general, would prescribe it to other individuals, Best wishes.

Write a Review

Software Engineering Questions & Answers

  Describe the relationship between nmap and zenmap

What are some reasons an information security professional would scan a system or network of systems and  why is it important to learn at least a few commonly used ports and their associated services?

  Is it possible to combine process models

Read the 'Manifesto for Agile Software Development" at the beginning of this chapter. Can you think of a situation in which one or more of the four 'values" could get a soft¬ware team into trouble?

  In this class weve stressed the importance of various

in this class weve stressed the importance of various system analysis and design tools and techniques. by now you

  Research the web to recognize a systemssoftware development

research the web to identify a systemssoftware development lifecycle. in a report format discuss selected sdlc by

  What were the actual values from your testing?

What were the actual values from your testing? Did these match your expected values? What did you do to make sure you get the expected values?

  Why is software architecture important to a company

Why is software architecture important to a company? What is the role of a software architect? Define business problems that can be solved using software architecture concepts and standards.

  Embedded system development spring

Embedded System Development Spring, Multiply the Number 0x 00000DBF by Decimal 9 using shift instruction consider the result Minuend. Divide 0x00000CD8 by Decimal 4 by shift instruction and consider the result Subtrahend.

  Program for alpha testing

At this point, you want to put together the work that has been completed to deliver a working program for alpha testing. You will combine the elements you have written to this point and deliver a working solution

  Key to managing change in projects

What do you think is the key to managing change in projects? Why do you think this is the key?

  Q1 what is a test plan list out the processes that are

q.1 what is a test plan? list out the processes that are covered in a test plan.q.2 what is the need to identify test

  Calculation of the hypotenuse

Construct a C# console application that calculate the hypotenuse of a right triangle. The calculation of the hypotenuse of a right triangle is based on the Pythagorean Theorem:

  Apply the buying center concept to a firm a nonprofit

apply the buying center concept to a firm a nonprofit organization or a government agency you work for or are familiar

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd