Create a file-system-based timeline

Assignment Help Computer Engineering
Reference no: EM131688373

Lab: Evidence Acquisition and Analysis Lab

For this lab, you will practice acquiring a digital image of your own laptop or computer and setting up a forensic analysis workstation. You will NOT have to turn in the image of your own laptop (for privacy reasons), but you will have to turn in evidence that you have completed this task. For all the required information that needs to be turned in, a Word document is sufficient.

For this exercise, you will need to do the following:

Download a Linux-based forensics live CD.

Use this to acquire the harddrive on your own computer by booting into the LiveCD and then storing an image file on a portable hard drive. You can use any of the commandline-based acquisition tools you like (recommended to us: dcfldd for on-the-fly hashing).

Take an MD5 and SHA256 hash of the drive before AND after you do the acquisition; turn these in. If you use a program that has on-the-fly hashing, turn that in as well. Compare your results to the hash of the image file; ensure that they match.

Describe how you ensured that the drive you were acquiring was not modified during the acquisition.

During the running of the hashing algorithms, I made sure nothing was running in the background or open except for the hashing program itself. If I was in the field I would also use a write block to make sure there definitely was no modification and keep the data untouched.

On your laptop, install the virtualization software of your choice to create a forensics workstation. Ideally this would be dedicated hardware, but use your own device. It is recommended you install the SIFT Kit, but any other Forensic distro will do.

Using Autopsy, load the image into a new case and verify that the hashes still match.

Create a file-system-based timeline and turn in the first 10 and last 10 entries as well as the hash value of the file.

In Autopsy, perform a keyword search for the name of your university; how many files were returned that matched? (Just provide the count, not the filenames or their contents.)

Attachment:- Assignment File.rar

Reference no: EM131688373

Questions Cloud

What warner brothers do to ensure successful repatriation : The director of sales and marketing for a Warner Brothers theme park has been working in Madrid. She is getting ready to return to the United States.
Discuss component of network transportation : What is the answer to this question and what are three main points that I can talk about in my essay
Operate within the time and budget constraints : Proper scope identification and management will help the project evolve smoothly and operate within the time and budget constraints.
Describe illegal immigrants should be provided a path : Describe illegal immigrants should be provided a path for citizenship. Pay fines, learn English, obey the laws and wait your turn to considered for citizenship.
Create a file-system-based timeline : Create a file-system-based timeline and turn in the first 10 and last 10 entries as well as the hash value of the file
Monopolistically competitive : Think of an industry that is close to being purely competitive and compare it with another industry of your choice that is monopolistically competitive.
Discuss steps in developing a succession planning system : List and discuss the steps involved in developing a succession planning system. How might a succession planning system differ between high-potential employees.
Reconstruct and analyze monetary : Reconstruct and analyze monetary The Mexico Peso Crisis. what the effect was, what impact it had on trade and on living conditions in the country.
Hire workers under a matching strategy : What is the total cost to hire workers under a matching (chase) strategy?

Reviews

Write a Review

Computer Engineering Questions & Answers

  Mathematics in computing

Binary search tree, and postorder and preorder traversal Determine the shortest path in Graph

  Ict governance

ICT is defined as the term of Information and communication technologies, it is diverse set of technical tools and resources used by the government agencies to communicate and produce, circulate, store, and manage all information.

  Implementation of memory management

Assignment covers the following eight topics and explore the implementation of memory management, processes and threads.

  Realize business and organizational data storage

Realize business and organizational data storage and fast access times are much more important than they have ever been. Compare and contrast magnetic tapes, magnetic disks, optical discs

  What is the protocol overhead

What are the advantages of using a compiled language over an interpreted one? Under what circumstances would you select to use an interpreted language?

  Implementation of memory management

Paper describes about memory management. How memory is used in executing programs and its critical support for applications.

  Define open and closed loop control systems

Define open and closed loop cotrol systems.Explain difference between time varying and time invariant control system wth suitable example.

  Prepare a proposal to deploy windows server

Prepare a proposal to deploy Windows Server onto an existing network based on the provided scenario.

  Security policy document project

Analyze security requirements and develop a security policy

  Write a procedure that produces independent stack objects

Write a procedure (make-stack) that produces independent stack objects, using a message-passing style, e.g.

  Define a suitable functional unit

Define a suitable functional unit for a comparative study between two different types of paint.

  Calculate yield to maturity and bond prices

Calculate yield to maturity (YTM) and bond prices

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd