Reference no: EM134042195 , Length: Word Count:2500
Assessment
Purpose: The primary objective of this assignment is to (i) Apply the computer forensics methodologies, (ii) Write an analysis of a case study, and (iii) Prepare an outline of a professional computer forensic plan. This assessment contributes to the learning outcomes a, b, c, d, e.
Assessment topic: Professional computer forensic planning and Investigation
Task Details
This assignment is based on the following case. Please read it carefully:
M57.biz is a new company that researches patent information for clients. Facts of the case:
- 1 president / CEO
- 3 additional employees
- The firm is planning to hire more employees, so they have a lot of inventory on hand (computers, printers, etc.).
Current employees:
- President: Pat McGoo
- Information Technology: Terry
- Patent Researchers: Jo, Charlie
Employees work onsite and conduct most business exchanges over email. All the employees work in Windows environments, although each employee prefers different software (e.g. Outlook vs. Thunderbird).
Network Configuration:
- Pat – CEO
- Terry – IT
- Charlie – Patent Search
- Jo – Patent Search
- Jo – Patent Search Old Computer
- Terry’s Phone
- USB Drive
- DOMEX – local server managing external network access and email
- Router/Switch
- Internet
Note: In the above figure “DOMEX” is the local server managing external network access and email.
One of the employees in M57 is stealing proprietary research from the company and passing it on to an outside entity. This employee has taken some measures to cover their tracks, but probably did not count on the company machines being imaged in the ongoing investigation of other criminal activity.
You are tasked with determining the following questions:
- Who is exfiltrating the data?
- How are they doing it? Can you identify the specific items they have stolen? What is required to access the data?
- Who is the outside contact?
- Is there anything in your analysis to suggest that this person might be charged with more than one criminal offense?
At the end of your investigation you should prepare a report in order to find the above questions. You must find relevant evidences after performing the investigation on the following images:
- charlie-2009-12-11.E01
- jo-2009-12-11-001.E01
- charlie-work-usb-2009-12-11.E01
- jo-work-usb-2009-12-11.E01
- terry-workusb-2009-12-11.E01
Investigation Requirements
Your investigation should answer questions asked in the case and formulate a conclusion. Your conclusion should be supported by your investigated evidence. Use the forensic software's you have learnt in the lab for this investigation but if required feel free to use other available forensic tools available out there for free (or trial).
Electronic identities:
- Pat McGoo (President):
1. (email password: mcgoo01)
2. Terry Johnson (IT Administrator):
3. (email password: johnson01)
4. Jo Smith (Patent Researcher):
5. (email password: smith01)
6. Charlie Brown (Patent Researcher):
Further information (such as a copy of the detective reports, along with the search warrant and affidavit) about this case can be found in the provided case links.
Instructions
In capacity of a computer forensics specialist, your task is to prepare a computer forensics investigation plan to enable a systematic collection of evidence and subsequent forensic analysis of the electronic and digital data. Briefly, you should discuss a general overview of the methodology that you will use and provide a reasoned argument as to why the particular methodology chosen is relevant. You should also discuss the process that you will use to collect evidence and discuss the relevant guidelines that need to be followed when collecting digital evidence.
This plan should detail the following:
1. Justify why the use of the digital forensic methodology and approach is warranted including appropriate procedures for the Company's investigation.
2. Describe the resources required to conduct a digital forensic investigation, including skill sets and the required software and hardware for the forensics team members.
3. Outline an approach for data/evidence identification and acquisition that should occur in order to be able to identify and review the digital evidence.
4. Outline an approach and steps to be taken during the analysis phase.
5. Develop relevant security policies for the Company.
6. Provide recommendations to the Company for dealing with similar future problems.
Instructions for the Report
Tips for preparing your computer forensics investigative plan
In writing the computer forensics investigative plan, students need to address the following points. Do note that points listed below are not exhaustive and need to be considered as helpful tips.
Introduction
Justify a need for computer forensics methodology and consider the scope of the case including the nature of alleged misconduct leading to consideration of how electronic and digital evidence may support the investigation. The plan should consider how computer forensics differs from other techniques (such as network forensics, data recovery) and detail the overall steps for the systematic computer forensics approach.
Resource requirements
Consider the required resources and include details regarding preparation plan for evidence gathering (such as evidence forms, types, storage media and containers), forensics workstation and peripherals needed, software/tools for analysis depending on the type of evidence to be gathered including rationale for selected tools, and consideration of team member skills in digital analysis (such as OS knowledge, skills for interview, consultation, working as per the needs of the auditing team and understanding of law and corporate policies).
Data acquisition
Detail the approach for data acquisition including the different types of evidence that can be gathered and their source depending upon the nature of the case and scope of investigation, develop a plan for data acquisition including rationale for selected plan and contingency planning, detail type of data acquisition tools needed including rationale and an outline for the data validation & verification procedures.
Forensics analysis
Provide an outline of the forensic analysis procedures/steps depending upon the nature of evidence to be collected, and detail the validation approach. This can include techniques to counter data hiding, recovering deleted files, procedures for network and e-mail analysis. Each student needs to do the analysis.
Security policies
Develop suitable security policies for the Company.
Conclusion
Provide appropriate recommendations to the Company for dealing with the problems.
Presentation and Demonstration
All sources used in this assessment must be properly cited using Harvard referencing style. Failure to do so will be treated as plagiarism. For guidance, refer to KOI referencing slides or consult your lecturer. In-text citations are essential.
Instructions for the Presentation and Demonstration
- Each group will deliver a 10–12 minute in-class presentation using slides.
- Slides do not need to be uploaded.
- The presentation must focus only on key investigation processes and summarised findings.
- After the group presentation, each student must individually demonstrate their practical forensic work.
- Individual demonstrations must be 3–5 minutes, depending on task complexity.
- Students must demonstrate the forensic software, tools, or analysis techniques they personally used.
- Students must ensure their own computer is ready, with all required forensic software and files accessible.
- The demonstration will be used to assess individual contribution, practical competence, and understanding of the investigation tasks.
Note on Recorded Presentation and Demonstration (Alternative Option)
Depending on class size, time constraints, or task complexity, students may opt for a recorded presentation and demonstration. This option requires prior approval through an Expression of Interest, supported by a valid reason, or may be advised due to time constraints.
In such cases, students must:
- Arrange the recording within their group
- Present and demonstrate their work during the session
- Record the session and share the recorded video
The recorded video must:
- Use slides, evidence, and forensic software
- Include voice-over explanation
- Have the camera on and screen sharing enabled
- Clearly show the demonstration of tools and analysis