Reference no: EM134012043
Assignment Task Distribution - Legal & Report Documentation
Task 1 - Forensic Readiness and Legal-Ethical Compliance
What to Do:
Explain how digital evidence should be collected properly
Write about chain of custody and maintaining evidence integrity
Compare forensic standards:
ISO/IEC 27037
NIST or ACPO
Explain Australian legal requirements and e-discovery
Discuss:
Employee privacy
Confidential company data
Handling deleted/hidden files
Prepare:
Introduction
Conclusion
References in IEEE style
Combine all group work into final report
Tools/Resources:
Research papers
Google Scholar
MS Word
Deliverables:
Complete Task 1 write-up
Standards comparison table
Legal and ethical discussion using concepts from Business Ethics
Final formatted report
Member 2 - VM & Endpoint Forensics
Topic:
Task 2 - Endpoint and Virtual Machine Forensics
What to Do:
Create forensic image of VM using:
FTK Imager
Autopsy
Capture screenshots during imaging
Generate:
MD5 hash
SHA256 hash
Analyse VM image and identify:
Deleted files
Hidden folders
Suspicious executables
Ransomware evidence
Explain:
Timeline of attack
User activity
Impact on organisation
Tools:
FTK Imager
Autopsy
Deliverables:
VM acquisition screenshots
Hash verification
Evidence analysis
Timeline explanation
*Member 3 - Network & Memory Forensics
Topic:
Task 3 - Network Intrusion Analysis
and
Task 4 - Memory and Malware Analysis
What to Do:
Task 3:
Open PCAP file in Wireshark
Analyse network traffic using concepts related to Data Communication And Networking
Use filters to detect:
SYN flood
DNS anomalies
Suspicious HTTP/HTTPS traffic
Identify:
Data exfiltration
Possible intrusion
Command-and-control traffic
Suggest extra logs:
Firewall logs
IDS/IPS logs
DNS logs
Task 4:
Perform memory analysis using Volatility
Run plugins:
pslist
pstree
netscan
dlllist
Detect:
Hidden processes
Malware activity
Injected code
Explain importance of memory forensics
Tools:
Wireshark
Volatility
Deliverables:
Wireshark screenshots
Volatility screenshots
Network analysis
Malware findings
Member 4 - Email, Mobile Forensics & Presentation
Topic:
Task 5 - Digital Communication and Mobile Forensics
and
Task 6 - PowerPoint Presentation
What to Do:
Task 5:
Convert PST file to CSV using:
Aid4Mail
OS Forensics
Apply keyword search/filter
Analyse suspicious emails:
Sender/receiver
Subject
Timestamp
Folder location
Explain mobile forensic analysis within broader Computer Science concepts:
SMS logs
WhatsApp/app data
File transfers
Discuss metadata and e-discovery reporting
Task 6:
Prepare PowerPoint slides
Add screenshots and diagrams
Create professional design
Organise speaking order
Help team practice presentation
Tools:
Aid4Mail
OS Forensics
PowerPoint
Deliverables:
Email analysis
Mobile forensic explanation
Metadata discussion
Complete PowerPoint slides supported by relevant Computer Science Engineering presentation practices
*Note: need only Member 3 - Network & Memory Forensics Part (Report only 500-600 word)