Reference no: EM133913109
Digital Forensics
Lab: Digital forensics investigation
Practical Tasks 1:
The case in this project involves a suspicious death. Joshua Zarkan found his girlfriend's dead body in her apartment and reported it. The first responding law enforcement officer seized a USB drive. A crime scene evidence technician skilled in data acquisition made an image of the USB drive with ProDiscover and named it C1Prj01.eve. Following the acquisition, the technician transported and secured the USB drive and placed it in a secure evidence locker at the police station. You have received the image file from the detective assigned to this case. He directs you to examine it and identify any evidentiary artifacts that might relate to this case. To process this case, follow these steps to evaluate what's on the image of the USB drive:
1. Start ProDiscover Basic. (If you're using Windows Vista or later, right-click the ProDiscover desktop icon and click Run as administrator.)
2. In the Launch Dialog box, click the New Project tab, if necessary. Enter a project number. If your company doesn't have a standard numbering scheme, you can use the date followed by the number representing the case that day in sequence, such as 20190124 01.
3. Enter C1Prj01 as the project name, enter a brief description of the case, and then click Open.
4. To add an image file, click Action from the menu, point to Add, and click Image File.
5. Navigate to your work folder, click C1Prj01.eve, and then click Open. If the Auto Image Checksum message box opens, click Yes.
6. In the tree view, click to expand Content View. Click to expand Images, and then click the pathname containing the image file. In the work area, notice the files that are listed.
7. Right-click any file and click View to start the associated program, such as Word or Excel. View the file, and then exit the program.
8. If you decide to export a file, right-click the file and click Copy File.(Note: Creating a separate folder for exports is a good idea to keep your files organized.) In the Save As dialog box that opens, navigate to the location where you want to save the file, and then click Save.
9. To save the project to view later, click File, Save Project from the menu. The default project name is the one you entered in Step 3. Select the drive and folder (WorknChap01nProjects, for example), and then click Save. After you have finished examining the files, exit ProDiscover Basic and save the project again, if prompted.
Practical Tasks 2
In this project, you work for a large corporation's IT security company. Your duties include conducting internal computing investigations and forensics examinations on company computing systems. A paralegal from the Law Department, Ms. Jones, asks you to examine a USB drive belonging to an employee who left the company and now works for a competitor. The Law Department is concerned that the former employee might possess sensitive company data. Ms. Jones wants to know whether the USB drive contains anything significant. In addition, she informs you that the former employee might have had access to confidential documents because a co-worker saw him accessing his manager's computer on his last day of work. These confidential documents consist of 24 files with the text "book." She wants you to locate any occurrences of these files on the USB drive's bit-stream image. To process this case, make sure you have extracted the C1Prj02.eve file to your work folder, and then follow these steps:
1. Start ProDiscover Basic. In the New Project tab, enter a project number, the project name C1Prj02, and a project description, and then click Open. It's a good idea to get in the habit of saving the project immediately, so click File, Save Project from the menu, and save the file in your work folder (WorknChap01nProjects).
2. Click Action from the menu, point to Add, and click Image File. Navigate to and click C1Prj02.eve in your work folder, and then click Open. If the Auto Image Checksum message box opens, click Yes.
3. In the tree view, click to expand Content View, if necessary. Click to expand Images, and then click the pathname containing the image file. In the work area, examine the files that are listed.
4. To search for the keyword "book," click the Search toolbar button to open the Search dialog box.
5. If necessary, click the Content Search tab, and then click the ASCII option button and the Search for the pattern(s) option button type book in the list boxforsearchkeywords.UnderSelecttheDisk(s)/Image(s)youwanttosearch in, click the drive you' researching(see Figure1),and then click OK.
6. In the tree view, click to expand Search Results, if necessary, and then click Content Search Results to specify the type of search. Figure 1-25 shows the search results pane. Get top-rated assignment help now.
7. Next, open the Search dialog box again, click the Cluster Search tab, and run the same search. Note that it takes longer because each cluster on the drive is searched.
8. In the tree view, click Cluster Search Results, and view the search results pane. Remember to save your project and exit ProDiscover Basic before starting the next case.
9. When you're finished, write a memo to Ms. Jones with the following information: the filenames in which you found a hit for the keyword and, if the hit occurred in unallocated space, the cluster number.