Loading...

Messages

Proposals

Stuck in your homework and missing deadline? Get urgent help in $10/Page with 24 hours deadline

Get Urgent Writing Help In Your Essays, Assignments, Homeworks, Dissertation, Thesis Or Coursework & Achieve A+ Grades.

Privacy Guaranteed - 100% Plagiarism Free Writing - Free Turnitin Report - Professional And Experienced Writers - 24/7 Online Support

Encase recover folders

08/01/2021 Client: saad24vbs Deadline: 10 Days

Advanced Computer Forensics


Windows EnCase Forensics Lab

Exercise 1: Starting a New Case

Question 1: What is the file system of this raw Image?


(Hint: 1. Check “report” from the bottom pane OR


2. choose “Disk View…” from the top drop-down disk manual, image1.png


then click the first sector (in red), the volume boot, image2.png


and read the text in the bottom pane.)


FAT 12


Question 2: What is the first character (in Hex) of the filename of a deleted file (check week 6 lecture recording)?


EB


Question 3: What type of files can be added using EnCase’s “Add Evidence Files”


Legacy evidence files , current evidence files , safeback files , vmware files , logical files , current logical , virtual files


Exercise 2: Using Encase


Set the Time Zone

Question 4: Where does the Time Zone information reside in a Windows system? (Hint: See EnCase 7 User guide, page 122 or watch Processing Evidence Part 1 from http://www.encaseondemand.com/EnCasev7Essentials/tabid/2617/index.aspx).


It stored in registry in the path : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\TimeZoneInformation key


Question 5: How do you modify Time Zone Settings, show a screen shot below.


image3.jpg


Now that you have the evidence added and the time zone set, you can analyze the evidence.

Timeline View

Question 6: Why is Timeline View useful for your investigation?


Help us to get a better information which help us in the investigation .


Gallery View

Question 7: In the Raw Image, how many pictures are shown in Gallery View?


Three images


Question 8: Read the EnCase manual to find out how Recover-Folders recover deleted folders for FAT and NTFS file systems respectively?


FAT : searches through the unallocated clusters of a specific FAT partition for the “dot, double-dot” signature of a deleted folder; when the signature matches, EnCase can rebuild the files and folders that were within that deleted folder.


NTFS: EnCase can recover NTFS files and folders from Unallocated Clusters and continue to parse through the current Master File Table (MFT) records for files without parent folders. This is particularly useful when a drive has been reformatted or the MFT is corrupted. Lost files that are recovered are placed in the gray Recovered Folders virtual folder in the root of the NTFS partition. To recover folders on an NTFS partition, right-click on the volume and select Recover Folders


Question 9: What information is listed for each file type?


File name , file extension , header signature and unique tag .


Question 10: What can an investigator do if the header of a file is unknown in your current setting of the EnCase?


Changing the settings of encase or try to open the file with any software


Question 11: What different terms you see in the Signature Analysis column?


Alias , unknown , match and bad signature


Question 12: Do you find any signature mismatch? List them.


No


Question 13: Are there any graphics files on the WinLabRaw image whose file extensions have been changed? List them.


Yes there are


(3) file3.xls


(4) files.csv


(5) tt-logo.gif


(7)file6.


(8) file7.zip


Question 14: If a file’s extension has been changed to a non-graphics file type (such as changing jpg to txt), will it be displayed in the Gallery view? If not, what could you do to fix this?


It won’t display but we need to signature analysis regarding to type .


Question 15: What are the types of files that will not have a hash generated?


The deleted files


Question 16: What are the three most common uses for hashes analysis?


secure files , very helpful in investigation , we can compare the hashes to know if we have the right file .


Compound Files

Question 17: Did anything happen? Do you find any important information? If so, what kind of information you got?


The files expanded and we can see all the folders and the files inside each folder


Question 18: What interesting information do you see from emails?


I can find different folders like deleted items , inbox , sent item and folders


Question 19: Read EnCase Forenscis V7 User Guide (page 208), briefly describe what are these features.


These features are very helpful in investigation with this features we can focus on a specific subject which we want and help us in email investigation


Question 20: Under the Records view, you should also see Thumbnails under WinLabRaw Image, what are thumbnails? List three of them.


Thumbnails are the files which we flagged and we interesting to focus on it in the investigation


Question 21: What kind of information do you see in the record for Internet?


We can find information regarding to internet browser like cookies history and bookmark


Question 22: How does “search unallocated space for internet artifacts” affect your search results in the record?


This search will look for all files that have relation with the internet on the entire hard disk even in the unallocated space


Question 23: What are the results? List 2 files that contain the term “search” in their contents.


The results are all the files which have the word search in their titles and contents


Search[1]


Search contractors


Questions 24: What are the other search options besides “Search entry slack”?


Skip contents for known files , undelete entries before searching and use initialized size


Question 25: What do you see from Search Hits? List two files from the search hits.


Search hits are more or same number as items for computer keyword , I found three hits


Raytheon.htm


Monster.htm


Serach.htm


Action 26: Include a screenshot of the bookmarks you created in the Bookmarks tab.


image4.jpg


Action 27: Show the tagged Files in the Table view.


image5.jpg


Question 28: What is the “One-click tagging” feature (see EnCase User Guide, page 234)?


Add each pic we click on it to the important files which we interesting on investigate them


Action 29: Finally, go back Process Evidence… from the Add Evidence menu. Selected the WinlabEnCase image, expend Modules, and choose one function from Modules and include your results below.


image6.jpg


image7.jpg


PAGE


1


Advanced Computer Forensics - EnCase

Homework is Completed By:

Writer Writer Name Amount Client Comments & Rating
Instant Homework Helper

ONLINE

Instant Homework Helper

$36

She helped me in last minute in a very reasonable price. She is a lifesaver, I got A+ grade in my homework, I will surely hire her again for my next assignments, Thumbs Up!

Order & Get This Solution Within 3 Hours in $25/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 3 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 6 Hours in $20/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 6 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 12 Hours in $15/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 12 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

6 writers have sent their proposals to do this homework:

Top Essay Tutor
University Coursework Help
Helping Hand
Writer Writer Name Offer Chat
Top Essay Tutor

ONLINE

Top Essay Tutor

I have more than 12 years of experience in managing online classes, exams, and quizzes on different websites like; Connect, McGraw-Hill, and Blackboard. I always provide a guarantee to my clients for their grades.

$105 Chat With Writer
University Coursework Help

ONLINE

University Coursework Help

Hi dear, I am ready to do your homework in a reasonable price.

$102 Chat With Writer
Helping Hand

ONLINE

Helping Hand

I am an Academic writer with 10 years of experience. As an Academic writer, my aim is to generate unique content without Plagiarism as per the client’s requirements.

$100 Chat With Writer

Let our expert academic writers to help you in achieving a+ grades in your homework, assignment, quiz or exam.

Similar Homework Questions

University of hull midwifery - Assignment - SCIENCE Discussion(NO PLAGIARISM, A++ WORK, QUALITY, ON TIME) - How many chromosomes does a drosophila gamete have - What are the pros and cons of the flu vaccine - Java program - Write a journal about Muslim countries - Labor relations and collective bargaining case study - Christian Faith And Life - Mississippi burning film techniques - Crane capacity calculation formula - Writing prompts to kill a mockingbird - The __________ on packages were intended to improve inventory control for businesses. - Scholarship Thank you letter - Us airline industry case study - Walt disney strengths - Where is total cell style in excel - Brazill brothers line card - Week 5 eco breif assignment - South audley street london - An asset used in a four year project falls - The signal by vsevolod garshin - David rafalovsky bank of america - Malcolm x ballot or the bullet speech analysis - Special purpose acquisition companies an introduction - Ph of 10 8 m naoh - How do you round your answer to two decimal places - Essential Guide to NURS FPX 4055 & 4065 Key Assessments - Dnv rules for planning and execution of marine operations 2000 - How to increase profits in capsim - What is ftk imager used for - Revex s20 coaxial switch price - Criminal justice wedding cake diagram - Userinfo getusertype in salesforce - A glossary of literary terms ebook - ECON 2200 MOD 3 DB - Born haber cycle definition - 3/67 elizabeth street malvern - Novoferm novomatic 553 remote - Leadership 5 - Sections of a quantitative research report - Is nick carraway gay - Czx - Case Study BSN - Difference between transparent and translucent - Jason stockwood net worth - Super's archway model - Ray vanderbilt crime by design - 16 slice ct scanner comparison - Into thin air read aloud - Business partnership proposal email - Articulate the PR-Ideologies - A firm can rapidly build its presence in the target foreign market through acquisitions. - Exercise 10 13 revising depreciation lo c2 - Advanced Portfolio Diversification - Walden university code of conduct - Built with science nutrition calculator - Ap lit and more 2019 frankenstein answers - Dmps3 300 c crestron - Supportive and interpersonal psychotherapies - Synchro check relay works - Electric field mapping lab answers - The great gatsby argumentative essay - Small Group Communication - Po box 3321 newstead qld - Vehicle identification number color weight and horsepower best exemplify - Falling down customer is always right - The epic hero beowulf worksheet answers - War - Ergogenic Aids - Improvement Plan - Quantitative research on bedside shift report - Consecutive odd and even integers - Kingdom heirs when the story of my life is told - Fingame - Understanding gender - Map co x tpr - Job analysis and design case study - Human resource - RESPONSES - Volcano goddess crossword clue - Statistical methods, and specific tools used in quality measurement and improvement - Alignment of IT Strategy and Business Strategy- Case - Human resource essay - Commentary Peer Review Worksheet - Define formed elements and list the major categories - English 2 - Richard huish student advantage - Uea medicine course structure - Pros and cons of andragogy - Bill gates character traits - Good vocabulary words to use in a story - Who warned, “advertisements contain the only truth to be relied on in a newspaper?” - What does iap mean in spss - Physical changes and aging - Monsanto syngenta mega merger would drive more deals real m&a - Disorders of testis, scrotum, and epididymis. - Relationship between pressure and volume - July 27 2003 kelowna ufo - Word search puzzle 173 baseball