Explain computer forensic investigation procedures

Assignment Help Computer Engineering
Reference no: EM131740429

Assignment: Forensic Investigation

Purpose

The purpose of this project is to provide an opportunity for students to apply forensic investigation competencies gained throughout this course.

Required Source Information and Tools

The following tools and resources will be needed to complete this project:

- Course textbook
- Internet access
- Computer with Paraben
- P2 Commander installed
- Mac OS JSmith.img (a Mac OS X image file used in Project Part 3)

Note: Check with your instructor if you do not have access to Paraben P2 Commander. You may be able to download a trial version or use other software, such as Forensic Toolkit (FTK) or EnCase Forensic to complete this project.

Learning Objectives and Outcomes

You will:

• Explain the rationale for computer forensic activities.
• Explain computer forensic investigation procedures.
• Evaluate sources of evidence.
• Analyze laws related computer forensics.
• Apply tools used in forensic investigations.
• Analyze digital evidence.
• Report findings.
• Assess business considerations related to computer forensic investigations.

Deliverables

Part 3:Analyzing Evidence from Mac OS X

Part 3: Analyzing Evidence from Mac OS X

Scenario

Two weeks ago, D&B Investigations was hired to conduct an incident response for a major oil company in North Dakota. The company's senior management had reason to suspect that one or more company employees were looking to commit corporate espionage. The incident response team went on-site, began monitoring the network, and isolated several suspects. They captured forensic images from the machines the suspects used. Now, your team leader has asked you to examine a forensic image captured from a suspect's computer, which runs the Mac OS X operating system. The suspect's name is John Smith, and he is one of the company's research engineers.

Tasks

• Review the information on the Mac OS X file structure provided in the chapter titled "Macintosh Forensics" in the course textbook.

• Using Paraben P2 Commander, create a case file and add the image the incident response team captured (filename: Mac OS JSmith.img).

• Sort and review the various directories within the Mac OS X image. Look for evidence or indicators that John Smith was or was not committing corporate espionage. This may include direct evidence that John Smith took corporate property, as well as indirect evidence or indicators about who the suspect is and what his activities were during work hours. You can use the software features to help you keep track of the evidence you identify, for instance, by bookmarking sections of interest and exporting files.

• Write a report in which you:

o Document your investigation methods.

o Document your findings. Explain what you found that may be relevant to the case, and provide your rationale for each item you have identified as an indicator or evidence that John Smith was or was not committing corporate espionage.

o Analyze the potential implications of these findings for the company and for a legal case.

Submission Requirements

- Format: Microsoft Word (or compatible)
- Font: 12-Point, Double-Space
- Citation Style: Follow your school's preferred style guide
- Length: 2 pages

Self-Assessment Checklist

- I have applied appropriate evidence collection and handling methods.
- I have correctly identified and analyzed evidence that is relevant to the investigation.
- I have analyzed business considerations associated with the scenario.
- I have analyzed legal considerations associated with the scenario.
- I have created a professional, well-developed report with proper documentation, grammar, spelling, and punctuation.

Reference no: EM131740429

Questions Cloud

Evaluate the ideas in relationship to curriculum development : Evaluate these ideas in relationship to curriculum development. How do you see these ideas being embedded in curriculum design?
Availability of cheap natural gas : Which industries gain and which industries lose from the availability of cheap natural gas produced from shale deposits?
Implementation of key procedures supported by calculation : Implementation of key procedures supported by Excel calculation.
Recreation found in the ibis database : Give examples of industries where target costing is prevalent. Comment on the benefits of the practice also.
Explain computer forensic investigation procedures : Explain computer forensic investigation procedures. Evaluate sources of evidence. Analyze laws related computer forensics.
Discuss your observations and analysis of the six dimensions : The desire is for the stated educational philosophy to be as close as possible to the actual curriculum design and educational practice of the school.
Describe the limitations on employment : Limitations on Employment at Will Terry was hired as an assistant manager by the Assurance Manufacturing Company. There was no specific time related to Terry's.
Discuss are there differences between males and females : Are there differences between males and females, in terms of their weight and length. Are infants always smaller/lighter than the adults
Examine the employees e-mail accounts : Workers' Privacy John Hancock Life Insurance Company instructed its employees to create passwords to protect their e-mail accounts.

Reviews

Write a Review

Computer Engineering Questions & Answers

  Design a powerpoint presentation based on the scenario

design a PowerPoint presentation based on the scenario. You have been asked to present tips on time management skills to new students at an online university. Your group will work together to organize and create a presentation with your advice.

  Define difference between a shallow copy and a deep copy

Overload the operator += for the class newString to perform the following string concatenation; suppose that s1 is "Hello" and s2 it "there". Then the statement s1 += s2; should assign "Hello there" to s1, where s1 and s2 are newString objects.

  Bourne shell and design suitable functions

Bourne shell and design suitable functions

  Write down java application to accomplish

Ask users for the past 5 years of federal taxes they have paid, save this data to an array, search for largest and the smallest amount of tax, and display it to screen.

  Prepare data flow diagrams which use only a few symbols

"It is easier to learn to prepare data flow diagrams, which use only a few symbols, than it is to learn to prepare flowcharts, which use a number of different symbols." Discuss.

  Investigate what may be a perceived threat to environment

How many devices are connected to the internet - analyzing a users web access or installed applications - information security professional

  Create a disaster plan to protect the organization

build a disaster plan for your selected organization that includes how you will recommend the company back up and protect network data. Your plan should be 1,250 to 1,500 words in length and your recommendations must be based on the RAID system of..

  Prepare a er diagram for the daycare

Create an ER diagram for the Daycare. The daycare keeps track of every family. A family can have two parents, an unlimited number of children, current address for parent 1, current address for parent

  How office applications installed on a computer

List the common interface features seen in this applications versions of each of the office applications installed on a computer.

  Ethical policy that could be used by a team

Write down a short ethical policy that could be used by a team of IT workers when they encounter spam, email viruses or wish to use the company's denial-of-service rights.

  Give an example of a program where consistency has caused

Can you give an example of a program where consistency has caused too many problems? Is there a program you have used in your own work environment where consistency has caused problems?

  Preventing the pci specifications

To prevent having the whole network subject to the PCI specifications, how would you segment the network in order to decrease the scope of compliance?

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd