List the information you can determine about the system

Assignment Help Other Subject
Reference no: EM131271443

In this assignment , you will be asked to forensically examine a hard drive for evidence. Your assignment is to examine the drive, gather evidence in a forensically-sound manner, and present a report of your investigation. The incident in question occurred in October, 2016. You should focus your investigation on that time window.

1. The Investigation Report - this is really the whole package

2. Physical evidence tag/label. Refer to textbook for information that should be included. If you use a template or example from the Interwebs, site your sources. ("Appendix A" to investigation report.)

3. Key Evidence listing. Should be a table of (at a minimum) files examined and their hashes. ("Appendix B" to the investigation report.)

4. Tools listing. Should be a table of (at a minimum) executables used to examine or process files, and their hashes. Definitely list a tool like "pasco". You probably don't need to include commands like "cd" or "ls". Unless you're doing a live system acquisition. ("Appendix C" to the investigation report.)

5. Your case investigation activity log (your notes). Either include scans of your notebook, or photos of the pages, or if you use electronic notes, the notes file.

A note on presenting actual evidence files. Do NOT create a printed version of the super timeline. In your report, highilight key events (e.g. software was installed, a document was deleted) and include the key timeline entry rows for the event, or the start/end of the event (software installation may produce many dozens of pages). Also Do NOT try to hexdumpthe entire hard drive and print it out.

INVESTIGATION REPORT:

The report should clearly and concisely present evidence. Avoid drawing any conclusions in the report. Start each section with a summary of the key findings for that section. List the basic steps you took to arrive at that conclusion. Make references to your notes ("see Case 001 notes, page 2"). Pictures with labels, or screenshots of tool output, are appropriate. Hashes are appropriate. Time and date labels of the steps are appropriate. Explanations such as "this file is of type XYZ and includes data about ABC" are appropriate. Pasting your command history from the terminal is too much detail. Use "Page X of YY" on every page. Label every page with the Case Number (you can make one up).

1. Title Page:

"CS 447/547: Case 0000-001, October 2016", author's name. File name.pdf.

2. Executive Summary

This should begin something like: "In the investigation of Case 0000-001, involving the examination of a suspect harddrive, I reviewed the filesystem, including X user profile(s), examined the activity of user "<username Y>", and recovered Z deleted files. The evidence included in this report includes the following:" Use your own words, or mine.

3. Physical Evidence:

List the information you can determine from the drive you received, without opening it up and exposing the platters. Not necessary for this investigation.

4. File Systems and Partitions:

List the information you can determine about the file systems contained on this drive. Demonstrate that you have not altered the evidence.

5. Computer System Information

Mount the partitions and examine their contents. List the information you can determine about the system this was running on (e.g. what OS?, what users present? what software installed? important registry key values?)

6. Deleted files

Recover key deleted files and report on them.

7. Web browsing history

In one user's home directory, there is evidence of web-browsing activity. What can you determine from it?

8. Recovered emails

In one user's home directory, there is email. What can you recover from it?

9. Appendix A: Physical evidence

10. Appendix B: Key digital evidence

11. Appendix C: Tools used during investigation

12. Appendix D: Investigator's Notes

Reference no: EM131271443

Questions Cloud

What are the core issues at stake in articulating csrs : What are the core issues at stake in articulating CSRs? What concerns do you think are most important when formulating a CSR? To what would you give priority, and why
Determine its corresponding mean square error : Find the LMMSE predictor of x[n] given x[n - 1] and x[n - 2]. Also determine its corresponding mean square error.
What are private saving and public saving : Suppose that in a closed economy GDP is equal to 15,000, government purchases are equal to 3,000, consumption equals 10,500, and taxes equal 3,500. What are private saving and public saving?
Images of managing change-director-navigator-caretaker : Which of the six images of managing change; director, navigator, caretaker, coach, interpreter, or nurturer do you believe is the most effective and why?
List the information you can determine about the system : You will be asked to forensically examine a hard drive for evidence. Your assignment is to examine the drive, gather evidence in a forensically-sound manner, and present a report of your investigation. The incident in question occurred in October,..
Coefficients for market income : There you will see data on Gini coefficients for market income, gross income (before taxes) and disposable income (post taxes and transfers). There is more data for "Income definition until 2011" so you may prefer to use that.
Description of your in-person mock interview experience : After completing you're in-person mock interview, write a 1 to 2-page, single-spaced paper describing your experience. Be sure to include: Description of your in-person mock interview experience. Who did you interview with
Why not a non stationary random process : Give a simple example of each of the following. If it is not possible to specify such an example, clearly state, in one or two sentences
Getting projects back on schedule : What does crashing a schedule entail? Specifically, what is the point of crashing and what rules must be followed to crash effectively? Because crashing typically requires us to throw extra resources onto a project, some experts believe that crashing..

Reviews

Write a Review

Other Subject Questions & Answers

  Q1 the acceleration of gravity on the surface of venus is

q1. the acceleration of gravity on the surface of venus is 8.9ms2. would a ball throw upward on venus return to the

  Hellenistic mystery religions

Historians have discerned many parallels between some Hellenistic mystery religions such as _______ and later Christian ideas about Jesus of Nazareth.

  Regulatory requirements-health care entrepreneurship

What role do regulatory requirements play in the entrepreneurship process in the health care field? What can health care entrepreneurs do to establish a solid ethical and legal foundation?

  Construct a story about a fictional korean

Creative and construct a story (300~500words) about a fictional (or non-fictional) Korean that is living undocumented in Los Angeles

  What are wsdl documents used for

What are WSDL documents used for Discuss one possible methodology for undertaking a performance evaluation in this organization Outline the main steps required to access a Web service with the WebService Behavior

  Hotel and restaurant management issues

The cost of labor in the housekeeping department can be highest at a full-service hotel. How would you control labor costs in a full-service hotel?

  Find the composition of the exhaust gas

100 mol/min of a purge stream from a reactor's recycle stream contains 75 mol% propane and 20 mol% hydrogen. What is the composition of the exhaust gas?

  Call for a more task oriented leader

Consider the findings from the Ohio State and Michigan studies: Good leadership requires effectiveness on two dimensions initiating structure, commonly called task orientation, and showing consideration, commonly called employee orientation. Evaluate..

  Introduce the coding standards to coding staff

1. Introduce the coding standards to coding staff. (How will you inform coders about the coding standards?) 2. Identify sample size of charts you will audit for compliance. 3. State how often you will audit charts for compliance. 4. Discuss the actio..

  What are the stages of negotiation what are the three most

1.what are the stages of negotiation? what are the three most important steps in the negotiation planning process and

  Ethical principles of psychologists and code of conduct

Briefly discuss the ethical issues that apply, referencing either (or both) the Behavior Analyst Certification Board Guidelines for Responsible Conduct and/or the APA's Ethical Principles of Psychologists and Code of Conduct.

  Designing culturally relevant instruction

Designing Culturally Relevant Instruction

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd