Loading...

Messages

Proposals

Stuck in your homework and missing deadline? Get urgent help in $10/Page with 24 hours deadline

Get Urgent Writing Help In Your Essays, Assignments, Homeworks, Dissertation, Thesis Or Coursework & Achieve A+ Grades.

Privacy Guaranteed - 100% Plagiarism Free Writing - Free Turnitin Report - Professional And Experienced Writers - 24/7 Online Support

Encase recover folders

08/01/2021 Client: saad24vbs Deadline: 10 Days

Advanced Computer Forensics


Windows EnCase Forensics Lab

Exercise 1: Starting a New Case

Question 1: What is the file system of this raw Image?


(Hint: 1. Check “report” from the bottom pane OR


2. choose “Disk View…” from the top drop-down disk manual, image1.png


then click the first sector (in red), the volume boot, image2.png


and read the text in the bottom pane.)


FAT 12


Question 2: What is the first character (in Hex) of the filename of a deleted file (check week 6 lecture recording)?


EB


Question 3: What type of files can be added using EnCase’s “Add Evidence Files”


Legacy evidence files , current evidence files , safeback files , vmware files , logical files , current logical , virtual files


Exercise 2: Using Encase


Set the Time Zone

Question 4: Where does the Time Zone information reside in a Windows system? (Hint: See EnCase 7 User guide, page 122 or watch Processing Evidence Part 1 from http://www.encaseondemand.com/EnCasev7Essentials/tabid/2617/index.aspx).


It stored in registry in the path : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\TimeZoneInformation key


Question 5: How do you modify Time Zone Settings, show a screen shot below.


image3.jpg


Now that you have the evidence added and the time zone set, you can analyze the evidence.

Timeline View

Question 6: Why is Timeline View useful for your investigation?


Help us to get a better information which help us in the investigation .


Gallery View

Question 7: In the Raw Image, how many pictures are shown in Gallery View?


Three images


Question 8: Read the EnCase manual to find out how Recover-Folders recover deleted folders for FAT and NTFS file systems respectively?


FAT : searches through the unallocated clusters of a specific FAT partition for the “dot, double-dot” signature of a deleted folder; when the signature matches, EnCase can rebuild the files and folders that were within that deleted folder.


NTFS: EnCase can recover NTFS files and folders from Unallocated Clusters and continue to parse through the current Master File Table (MFT) records for files without parent folders. This is particularly useful when a drive has been reformatted or the MFT is corrupted. Lost files that are recovered are placed in the gray Recovered Folders virtual folder in the root of the NTFS partition. To recover folders on an NTFS partition, right-click on the volume and select Recover Folders


Question 9: What information is listed for each file type?


File name , file extension , header signature and unique tag .


Question 10: What can an investigator do if the header of a file is unknown in your current setting of the EnCase?


Changing the settings of encase or try to open the file with any software


Question 11: What different terms you see in the Signature Analysis column?


Alias , unknown , match and bad signature


Question 12: Do you find any signature mismatch? List them.


No


Question 13: Are there any graphics files on the WinLabRaw image whose file extensions have been changed? List them.


Yes there are


(3) file3.xls


(4) files.csv


(5) tt-logo.gif


(7)file6.


(8) file7.zip


Question 14: If a file’s extension has been changed to a non-graphics file type (such as changing jpg to txt), will it be displayed in the Gallery view? If not, what could you do to fix this?


It won’t display but we need to signature analysis regarding to type .


Question 15: What are the types of files that will not have a hash generated?


The deleted files


Question 16: What are the three most common uses for hashes analysis?


secure files , very helpful in investigation , we can compare the hashes to know if we have the right file .


Compound Files

Question 17: Did anything happen? Do you find any important information? If so, what kind of information you got?


The files expanded and we can see all the folders and the files inside each folder


Question 18: What interesting information do you see from emails?


I can find different folders like deleted items , inbox , sent item and folders


Question 19: Read EnCase Forenscis V7 User Guide (page 208), briefly describe what are these features.


These features are very helpful in investigation with this features we can focus on a specific subject which we want and help us in email investigation


Question 20: Under the Records view, you should also see Thumbnails under WinLabRaw Image, what are thumbnails? List three of them.


Thumbnails are the files which we flagged and we interesting to focus on it in the investigation


Question 21: What kind of information do you see in the record for Internet?


We can find information regarding to internet browser like cookies history and bookmark


Question 22: How does “search unallocated space for internet artifacts” affect your search results in the record?


This search will look for all files that have relation with the internet on the entire hard disk even in the unallocated space


Question 23: What are the results? List 2 files that contain the term “search” in their contents.


The results are all the files which have the word search in their titles and contents


Search[1]


Search contractors


Questions 24: What are the other search options besides “Search entry slack”?


Skip contents for known files , undelete entries before searching and use initialized size


Question 25: What do you see from Search Hits? List two files from the search hits.


Search hits are more or same number as items for computer keyword , I found three hits


Raytheon.htm


Monster.htm


Serach.htm


Action 26: Include a screenshot of the bookmarks you created in the Bookmarks tab.


image4.jpg


Action 27: Show the tagged Files in the Table view.


image5.jpg


Question 28: What is the “One-click tagging” feature (see EnCase User Guide, page 234)?


Add each pic we click on it to the important files which we interesting on investigate them


Action 29: Finally, go back Process Evidence… from the Add Evidence menu. Selected the WinlabEnCase image, expend Modules, and choose one function from Modules and include your results below.


image6.jpg


image7.jpg


PAGE


1


Advanced Computer Forensics - EnCase

Homework is Completed By:

Writer Writer Name Amount Client Comments & Rating
Instant Homework Helper

ONLINE

Instant Homework Helper

$36

She helped me in last minute in a very reasonable price. She is a lifesaver, I got A+ grade in my homework, I will surely hire her again for my next assignments, Thumbs Up!

Order & Get This Solution Within 3 Hours in $25/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 3 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 6 Hours in $20/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 6 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 12 Hours in $15/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 12 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

6 writers have sent their proposals to do this homework:

Top Essay Tutor
University Coursework Help
Helping Hand
Writer Writer Name Offer Chat
Top Essay Tutor

ONLINE

Top Essay Tutor

I have more than 12 years of experience in managing online classes, exams, and quizzes on different websites like; Connect, McGraw-Hill, and Blackboard. I always provide a guarantee to my clients for their grades.

$105 Chat With Writer
University Coursework Help

ONLINE

University Coursework Help

Hi dear, I am ready to do your homework in a reasonable price.

$102 Chat With Writer
Helping Hand

ONLINE

Helping Hand

I am an Academic writer with 10 years of experience. As an Academic writer, my aim is to generate unique content without Plagiarism as per the client’s requirements.

$100 Chat With Writer

Let our expert academic writers to help you in achieving a+ grades in your homework, assignment, quiz or exam.

Similar Homework Questions

What temperature does pewter melt at - Need help with chemistry homework - Women in Leadership Roles - Developmental analysis paper coun 502 - Cold applied tape coating steel pipe - Journal entry 32 on course - Purdue owl semicolon exercises - Marlborough & district canine society - Erica branch ridley cause of death - Comcast notice of claim of copyright infringement reddit - Buoyancy of floating cylinders - A case of pheochromocytoma case study answers - Allison thiel world surf league - Difference between claim of fact value and policy - Better world books charity rating - PAAS and IAAS - Porphyrin is a pigment in blood protoplasm - Leader vs Manager - Refrigeration oil cross reference - Cause and effect of voting rights act - Access 2016 in practice - ch 1 independent project 1-5 - Nmc feedback log template - Disadvantages of selective breeding - Order 2227248: Interview IEP collaborative school team - Man made materials plastic - Chinese ribbon dance music download - Student exploration collision theory gizmo answer key - Leviticus 20 27 autopsy of jane doe - Alh3 lewis dot structure - Energy transfers and transformations worksheet answers - Locus of control meaning - Nexiq device tester error 275 - MILITARY DIME PROCESS - Qaunatative math homework - Xerox uniprise project - New tech bus leaders - Shell helix ultra 5w 40 datasheet - In job evaluation, a benchmark job is - The best things in life are free lyrics ray henderson - Enterprise Architecture - Thread 1 & 2 (160 words each) - Anz visa card services - English 111 - Week 8 - The american fur company case study - Juniper design ltd of manchester england is a company - Public relations lecture notes - Aca code of ethics cultural competence - Assignment and discussion - Compass n s e w - Irac method of critical thinking - CS 5 - Gillette fusion proglide battery change - Bundle of algorithms in java pdf - Strayer university acc 100 syllabus - No me gustan esos zapatos voy a comprar - Grand slam sports equipment - ENG 225 Introduction to Film NO PLAGIARISM PLZ - Multisegment targeting strategy example - Brief one page summary on the use of privately owned and run prisons in America - Stoichiometry and theoretical yield experiment - Morrisons swan valley 3 address - The following airborne times for united airlines flight 448 - What does netiquette mean in computer terms - Discussion Please give in 20 hours from no plagiarism APA format reference includes 300 -400 words - Headway academic skills level 2 - Commutative identity associative distributive properties - Chemistry - Such great heights apple commercial - Why study business ethics ppt - Discussion paper with 2 responses - What is the rational approach - Molar mass of nitrogen gas - Brisbane city council wages - Banning cellphones in school statistics - Texthelp read and write gold - Article Analysis 2 - Blue collar brilliance main points - Diameter of tennis ball inches - Sap fico profile summary - Uber eats background check return needs attention - Terrick terrick national park - Project - Essay - Biozone crossword puzzle answers - Esther park shadow health diagnosis - Greenwich university admissions number - North or south who killed reconstruction - NEED IN 6 HOURS or LESS - Life perpetuates itself at the cellular level - Borosilicate glass thermal expansion - Southport a and e - Suonerie per gli Amanti del Teatro: Suoni Drammatici per Artisti - 119.5 kg to lbs - Power Point Presentation - Categories of cybercrime - Gasoline thermal expansion calculator - We real cool pdf - Awc ashford edu writing tools thesis generator html - Internal and external respiration - What is the main goal of gohsep