Reference no: EM133844197
Assignment:
Course Project II: Analyzing A Case
Purpose
The course project is aligned with the course learning objectives:
- Discuss computer forensics as a field and career.
- Collect digital evidence on a variety of computer systems using accepted forensic processes.
- Correctly use court accepted imaging and analysis tools.
- Identify the legal challenges to collecting and analyzing digital evidence.
Directions
Case Facts
Virginia Beach Police informed that Over 20 weapons were stolen from a Virginia gun store. Federal agents have gotten involved in seeking the culprits who police say stole more than 20 firearms from a Norfolk Virginia gun shop this week. The U.S. Bureau of Alcohol, Tobacco, Firearms, and Explosives is working with Virginia Beach police to locate the weapons, which include handguns and rifles. News Outlets report they were stolen from a store called DOA Arms during a Tuesday morning burglary.
Based on the 'Probable Cause of Affidavit,' a search warrant was obtained to search the apartment occupied by Mr. John Doe and Mr. Don Joe in Manassas, Virginia. When the search warrant was executed, it yielded miscellaneous items and a computer. The Special Agent conducting the investigation seized the hard drive from the computer and sent it to Forensics Lab for imaging.
You are to conduct a forensic examination of the image to determine if any relevant electronic files exist that may help with the case. The examination process must preserve all evidence.
Your Job
Forensic analysis of the image
- The image file, suspect_Image, was provided to you by someone who imaged the suspect drive as you did in the first part of the course project.)
- You have to think critically and evaluate the merits of different possibilities by applying your knowledge of what you have learned so far. As you can see, this assignment is about "investigating" a case. There is no right or wrong answer to this investigation. However, to assist you with the investigation, some questions have been created to guide you while you create a complete expert witness report. Remember, you must not only identify the evidence concerning the crime but tie the image back to the suspects showing which computer the image came from. Please note: -there isn't any disc Encryption like BitLocker. You can safely assume that the chain of custody was maintained.
- There is a Course Project Forum for the project. I enjoy seeing students develop their skills in critical thinking and the expression of their ideas. Feel free to discuss your thoughts without divulging your findings.
While you prepare your Expert Witness Report, trying to find answers to the following questions may help you prepare the report.
1. What is the first step you took to analyze the image?
2. What did you find in the image:
- What file system was installed on the hard drive, and how many volumes?
- Which operating system was installed on the computer?
- How many user accounts exist on the computer?
- Which computer did this image come from? Is there any indicator that it's a VM?
3. What actions did you take to analyze the artifacts you found in the image/computer? (While many files in the computer are irrelevant to the case, how did you search for artifactual/interesting files in the huge pile?
4. Can you describe the backgrounds of the people who used the computer, for example, Internet surfing habits, potential employers, known associates, etc.?
5. Is there any evidence related to the theft? Why do you think so?
- Who was possibly involved? Where do they live?
- What are the possible dates associated with the theft?
6. Are there any files related to this crime or another potential crime? Why did you think they were possible artifacts? What type of files are those? Any hidden file? Any Hidden data?
NOTE: Your report must be an expert witness report. A list of answered questions will not be accepted.