Loading...

Messages

Proposals

Stuck in your homework and missing deadline? Get urgent help in $10/Page with 24 hours deadline

Get Urgent Writing Help In Your Essays, Assignments, Homeworks, Dissertation, Thesis Or Coursework & Achieve A+ Grades.

Privacy Guaranteed - 100% Plagiarism Free Writing - Free Turnitin Report - Professional And Experienced Writers - 24/7 Online Support

Encase recover folders

08/01/2021 Client: saad24vbs Deadline: 10 Days

Advanced Computer Forensics


Windows EnCase Forensics Lab

Exercise 1: Starting a New Case

Question 1: What is the file system of this raw Image?


(Hint: 1. Check “report” from the bottom pane OR


2. choose “Disk View…” from the top drop-down disk manual, image1.png


then click the first sector (in red), the volume boot, image2.png


and read the text in the bottom pane.)


FAT 12


Question 2: What is the first character (in Hex) of the filename of a deleted file (check week 6 lecture recording)?


EB


Question 3: What type of files can be added using EnCase’s “Add Evidence Files”


Legacy evidence files , current evidence files , safeback files , vmware files , logical files , current logical , virtual files


Exercise 2: Using Encase


Set the Time Zone

Question 4: Where does the Time Zone information reside in a Windows system? (Hint: See EnCase 7 User guide, page 122 or watch Processing Evidence Part 1 from http://www.encaseondemand.com/EnCasev7Essentials/tabid/2617/index.aspx).


It stored in registry in the path : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\TimeZoneInformation key


Question 5: How do you modify Time Zone Settings, show a screen shot below.


image3.jpg


Now that you have the evidence added and the time zone set, you can analyze the evidence.

Timeline View

Question 6: Why is Timeline View useful for your investigation?


Help us to get a better information which help us in the investigation .


Gallery View

Question 7: In the Raw Image, how many pictures are shown in Gallery View?


Three images


Question 8: Read the EnCase manual to find out how Recover-Folders recover deleted folders for FAT and NTFS file systems respectively?


FAT : searches through the unallocated clusters of a specific FAT partition for the “dot, double-dot” signature of a deleted folder; when the signature matches, EnCase can rebuild the files and folders that were within that deleted folder.


NTFS: EnCase can recover NTFS files and folders from Unallocated Clusters and continue to parse through the current Master File Table (MFT) records for files without parent folders. This is particularly useful when a drive has been reformatted or the MFT is corrupted. Lost files that are recovered are placed in the gray Recovered Folders virtual folder in the root of the NTFS partition. To recover folders on an NTFS partition, right-click on the volume and select Recover Folders


Question 9: What information is listed for each file type?


File name , file extension , header signature and unique tag .


Question 10: What can an investigator do if the header of a file is unknown in your current setting of the EnCase?


Changing the settings of encase or try to open the file with any software


Question 11: What different terms you see in the Signature Analysis column?


Alias , unknown , match and bad signature


Question 12: Do you find any signature mismatch? List them.


No


Question 13: Are there any graphics files on the WinLabRaw image whose file extensions have been changed? List them.


Yes there are


(3) file3.xls


(4) files.csv


(5) tt-logo.gif


(7)file6.


(8) file7.zip


Question 14: If a file’s extension has been changed to a non-graphics file type (such as changing jpg to txt), will it be displayed in the Gallery view? If not, what could you do to fix this?


It won’t display but we need to signature analysis regarding to type .


Question 15: What are the types of files that will not have a hash generated?


The deleted files


Question 16: What are the three most common uses for hashes analysis?


secure files , very helpful in investigation , we can compare the hashes to know if we have the right file .


Compound Files

Question 17: Did anything happen? Do you find any important information? If so, what kind of information you got?


The files expanded and we can see all the folders and the files inside each folder


Question 18: What interesting information do you see from emails?


I can find different folders like deleted items , inbox , sent item and folders


Question 19: Read EnCase Forenscis V7 User Guide (page 208), briefly describe what are these features.


These features are very helpful in investigation with this features we can focus on a specific subject which we want and help us in email investigation


Question 20: Under the Records view, you should also see Thumbnails under WinLabRaw Image, what are thumbnails? List three of them.


Thumbnails are the files which we flagged and we interesting to focus on it in the investigation


Question 21: What kind of information do you see in the record for Internet?


We can find information regarding to internet browser like cookies history and bookmark


Question 22: How does “search unallocated space for internet artifacts” affect your search results in the record?


This search will look for all files that have relation with the internet on the entire hard disk even in the unallocated space


Question 23: What are the results? List 2 files that contain the term “search” in their contents.


The results are all the files which have the word search in their titles and contents


Search[1]


Search contractors


Questions 24: What are the other search options besides “Search entry slack”?


Skip contents for known files , undelete entries before searching and use initialized size


Question 25: What do you see from Search Hits? List two files from the search hits.


Search hits are more or same number as items for computer keyword , I found three hits


Raytheon.htm


Monster.htm


Serach.htm


Action 26: Include a screenshot of the bookmarks you created in the Bookmarks tab.


image4.jpg


Action 27: Show the tagged Files in the Table view.


image5.jpg


Question 28: What is the “One-click tagging” feature (see EnCase User Guide, page 234)?


Add each pic we click on it to the important files which we interesting on investigate them


Action 29: Finally, go back Process Evidence… from the Add Evidence menu. Selected the WinlabEnCase image, expend Modules, and choose one function from Modules and include your results below.


image6.jpg


image7.jpg


PAGE


1


Advanced Computer Forensics - EnCase

Homework is Completed By:

Writer Writer Name Amount Client Comments & Rating
Instant Homework Helper

ONLINE

Instant Homework Helper

$36

She helped me in last minute in a very reasonable price. She is a lifesaver, I got A+ grade in my homework, I will surely hire her again for my next assignments, Thumbs Up!

Order & Get This Solution Within 3 Hours in $25/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 3 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 6 Hours in $20/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 6 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 12 Hours in $15/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 12 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

6 writers have sent their proposals to do this homework:

Top Essay Tutor
University Coursework Help
Helping Hand
Writer Writer Name Offer Chat
Top Essay Tutor

ONLINE

Top Essay Tutor

I have more than 12 years of experience in managing online classes, exams, and quizzes on different websites like; Connect, McGraw-Hill, and Blackboard. I always provide a guarantee to my clients for their grades.

$105 Chat With Writer
University Coursework Help

ONLINE

University Coursework Help

Hi dear, I am ready to do your homework in a reasonable price.

$102 Chat With Writer
Helping Hand

ONLINE

Helping Hand

I am an Academic writer with 10 years of experience. As an Academic writer, my aim is to generate unique content without Plagiarism as per the client’s requirements.

$100 Chat With Writer

Let our expert academic writers to help you in achieving a+ grades in your homework, assignment, quiz or exam.

Similar Homework Questions

Star in a box - John cabot nationality italian - Olet psychology of crime - Cuda fortran programming guide - F for th phonological process - Polarization index of motor - Q & Q D7 - Alice walker essay beauty - Cardinal newman pe kit - Hedgehog rescue whitley bay - Six bird hunters in full camouflage - All money market instruments are short term debt - Jim hallam land rover defender specialists - Write a note on managerial reporting - Anatomy and physiology chapter 11 nervous system - Open source mobile operating system - Bible verses that seem restrictive - Intermediate Accounting - 03.05 marginal cost analysis data - Ng μl to nm - Measurement theory in accounting - Cardiac drugs for nurses - IP 5 - Statistic - QEP Activity 4 - Us bank cocoa beach fl - MKGT201 - Powerpoint presentation on stress management in the workplace - Help 2 - Impact of digital india - PAPER - Www thesmallbusinessgame co uk - Ib math sl formula booklet 2019 - On january 1 you sold short one round lot - Access chapter 3 grader project - Cert 4 in roman numerals - Family focused functional assessment questionnaire - Https zephoria com top 15 valuable facebook statistics - The company's facility for assembling cameras is located in - Propylene production process flow diagram - Big data analytics case studies ppt - Careskills academy care certificate - HISTORY-ECONOMIC THOUGHT 125 (001) (Fall 2020) - Independent groups design advantages - How to calculate sa to volume ratio - A new approach to monitoring exercise training - Financial markets and institutions frederic s mishkin stanley eakins - Medical surgical case studies, nursing diagnoses and interventions - A bookcase contains 3 statistics books - Why did miss ellie leave the andy griffith show - Best site for affordable book editing UK - The future tense in italian - Stilbene dibromide stereoisomers - Second negative constructive speech example - Arup family health clinic - Hemming co reported the following current year - Human development class Discussion - Law - GLOB (U4_RPL) - Sheet pile wall design - Tax Question - Spacegass - Managers use standard beverage costs to establish - Jb extended warranty price - Navigating Organizational Change - Linuxzoo net - Nursing diagnosis related to heart failure - Lawson street medical practice - Advantages and disadvantages of whiteboards - Royal bank usd to cad exchange rate - Business report example hsc - Summarize machiavelli's beliefs about what makes a great leader - Anchor bolt template definition - Nurs495Journal - List of brass instruments - University of hull nebosh - Ati basic concept - Uhcw nhs uk bloodtests - Free leadership legacy assessment test - What does ruca mean in spanish - 802.11 s mesh networking - Research paper and ppt - International units to ml - 28 hillock street coorparoo - Technology - Trend micro hosted email security 2.0 - Module 07 Quiz - Pico question examples heart disease - Hartley grove halls southampton - Sarah palin is a cunt - Rms voltage of half wave rectifier - Edexcel gcse mathematics linear 1ma0 coordinates answers - Flames and dangling wire analysis - The repeated use of the "o" sound in "a host, of golden daffodils" is called - 104.7 kg in stone - What is api testing guru99 - Which of the following normal distributions has the widest spread? - PSY 3 - Loctite products list pdf - Cloud computing