Loading...

Messages

Proposals

Stuck in your homework and missing deadline? Get urgent help in $10/Page with 24 hours deadline

Get Urgent Writing Help In Your Essays, Assignments, Homeworks, Dissertation, Thesis Or Coursework & Achieve A+ Grades.

Privacy Guaranteed - 100% Plagiarism Free Writing - Free Turnitin Report - Professional And Experienced Writers - 24/7 Online Support

Encase recover folders

08/01/2021 Client: saad24vbs Deadline: 10 Days

Advanced Computer Forensics


Windows EnCase Forensics Lab

Exercise 1: Starting a New Case

Question 1: What is the file system of this raw Image?


(Hint: 1. Check “report” from the bottom pane OR


2. choose “Disk View…” from the top drop-down disk manual, image1.png


then click the first sector (in red), the volume boot, image2.png


and read the text in the bottom pane.)


FAT 12


Question 2: What is the first character (in Hex) of the filename of a deleted file (check week 6 lecture recording)?


EB


Question 3: What type of files can be added using EnCase’s “Add Evidence Files”


Legacy evidence files , current evidence files , safeback files , vmware files , logical files , current logical , virtual files


Exercise 2: Using Encase


Set the Time Zone

Question 4: Where does the Time Zone information reside in a Windows system? (Hint: See EnCase 7 User guide, page 122 or watch Processing Evidence Part 1 from http://www.encaseondemand.com/EnCasev7Essentials/tabid/2617/index.aspx).


It stored in registry in the path : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\TimeZoneInformation key


Question 5: How do you modify Time Zone Settings, show a screen shot below.


image3.jpg


Now that you have the evidence added and the time zone set, you can analyze the evidence.

Timeline View

Question 6: Why is Timeline View useful for your investigation?


Help us to get a better information which help us in the investigation .


Gallery View

Question 7: In the Raw Image, how many pictures are shown in Gallery View?


Three images


Question 8: Read the EnCase manual to find out how Recover-Folders recover deleted folders for FAT and NTFS file systems respectively?


FAT : searches through the unallocated clusters of a specific FAT partition for the “dot, double-dot” signature of a deleted folder; when the signature matches, EnCase can rebuild the files and folders that were within that deleted folder.


NTFS: EnCase can recover NTFS files and folders from Unallocated Clusters and continue to parse through the current Master File Table (MFT) records for files without parent folders. This is particularly useful when a drive has been reformatted or the MFT is corrupted. Lost files that are recovered are placed in the gray Recovered Folders virtual folder in the root of the NTFS partition. To recover folders on an NTFS partition, right-click on the volume and select Recover Folders


Question 9: What information is listed for each file type?


File name , file extension , header signature and unique tag .


Question 10: What can an investigator do if the header of a file is unknown in your current setting of the EnCase?


Changing the settings of encase or try to open the file with any software


Question 11: What different terms you see in the Signature Analysis column?


Alias , unknown , match and bad signature


Question 12: Do you find any signature mismatch? List them.


No


Question 13: Are there any graphics files on the WinLabRaw image whose file extensions have been changed? List them.


Yes there are


(3) file3.xls


(4) files.csv


(5) tt-logo.gif


(7)file6.


(8) file7.zip


Question 14: If a file’s extension has been changed to a non-graphics file type (such as changing jpg to txt), will it be displayed in the Gallery view? If not, what could you do to fix this?


It won’t display but we need to signature analysis regarding to type .


Question 15: What are the types of files that will not have a hash generated?


The deleted files


Question 16: What are the three most common uses for hashes analysis?


secure files , very helpful in investigation , we can compare the hashes to know if we have the right file .


Compound Files

Question 17: Did anything happen? Do you find any important information? If so, what kind of information you got?


The files expanded and we can see all the folders and the files inside each folder


Question 18: What interesting information do you see from emails?


I can find different folders like deleted items , inbox , sent item and folders


Question 19: Read EnCase Forenscis V7 User Guide (page 208), briefly describe what are these features.


These features are very helpful in investigation with this features we can focus on a specific subject which we want and help us in email investigation


Question 20: Under the Records view, you should also see Thumbnails under WinLabRaw Image, what are thumbnails? List three of them.


Thumbnails are the files which we flagged and we interesting to focus on it in the investigation


Question 21: What kind of information do you see in the record for Internet?


We can find information regarding to internet browser like cookies history and bookmark


Question 22: How does “search unallocated space for internet artifacts” affect your search results in the record?


This search will look for all files that have relation with the internet on the entire hard disk even in the unallocated space


Question 23: What are the results? List 2 files that contain the term “search” in their contents.


The results are all the files which have the word search in their titles and contents


Search[1]


Search contractors


Questions 24: What are the other search options besides “Search entry slack”?


Skip contents for known files , undelete entries before searching and use initialized size


Question 25: What do you see from Search Hits? List two files from the search hits.


Search hits are more or same number as items for computer keyword , I found three hits


Raytheon.htm


Monster.htm


Serach.htm


Action 26: Include a screenshot of the bookmarks you created in the Bookmarks tab.


image4.jpg


Action 27: Show the tagged Files in the Table view.


image5.jpg


Question 28: What is the “One-click tagging” feature (see EnCase User Guide, page 234)?


Add each pic we click on it to the important files which we interesting on investigate them


Action 29: Finally, go back Process Evidence… from the Add Evidence menu. Selected the WinlabEnCase image, expend Modules, and choose one function from Modules and include your results below.


image6.jpg


image7.jpg


PAGE


1


Advanced Computer Forensics - EnCase

Homework is Completed By:

Writer Writer Name Amount Client Comments & Rating
Instant Homework Helper

ONLINE

Instant Homework Helper

$36

She helped me in last minute in a very reasonable price. She is a lifesaver, I got A+ grade in my homework, I will surely hire her again for my next assignments, Thumbs Up!

Order & Get This Solution Within 3 Hours in $25/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 3 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 6 Hours in $20/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 6 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 12 Hours in $15/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 12 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

6 writers have sent their proposals to do this homework:

Top Essay Tutor
University Coursework Help
Helping Hand
Writer Writer Name Offer Chat
Top Essay Tutor

ONLINE

Top Essay Tutor

I have more than 12 years of experience in managing online classes, exams, and quizzes on different websites like; Connect, McGraw-Hill, and Blackboard. I always provide a guarantee to my clients for their grades.

$105 Chat With Writer
University Coursework Help

ONLINE

University Coursework Help

Hi dear, I am ready to do your homework in a reasonable price.

$102 Chat With Writer
Helping Hand

ONLINE

Helping Hand

I am an Academic writer with 10 years of experience. As an Academic writer, my aim is to generate unique content without Plagiarism as per the client’s requirements.

$100 Chat With Writer

Let our expert academic writers to help you in achieving a+ grades in your homework, assignment, quiz or exam.

Similar Homework Questions

Tsunami 2 diesel technical reference - Swot analysis mayo clinic - Tensile coupon test specimen - Walmart capstone simulation level 3 - Anu finance economics and statistics - Culture diverse society - Rowlands castle st johns cec primary school - Information Ethics - Prayer of the faithful adelaide - Root-Cause Analysis and Safety Improvement Plan - 2 pm military time - GBI Procurement Process - It takes courage poem summary - 1.3 1.3 lab answers - Ucl accommodation what to bring - Students should not have phones in school - Estimate at completion formulas - Richard huish student advantage - Deep learning yann lecun nature - Taylor distributors of indiana fort wayne - Malcolm x coming to an awareness of language essay - Wk 3, IOP 470: DQ - Blood pressure measurement in pregnancy - Experiment 3 flame tests and electron configuration answer key - The sarbanes oxley act does all of the following except - Alam company is a manufacturing firm - The dynaco manufacturing company produces - System calls in os ppt - Law of contracts homework answers - Stress concentration factor v notch - Secretive contracts briefly crossword clue - Prejudice against immigrants was known as ___ - The tempest vocabulary list - Essays in ethical theory - WEEK 1 - Forten company statement of cash flows - Ucd timetable 2016 17 - Iso 17025 document control procedure - Caesar cipher decoder c++ - What is hoodooing in to kill a mockingbird - Class ring stone colors - I need a case study on how would the nurse actualize Parse's theory of Human Becoming - 8 2 2 project 3 multimedia presentation submission - Deliverable 5 - Interpreting Key Performance Indicators/ Excel File, Summary, Data Visuals, Dashboards, ScoreCard - 3 parts of hamilton's financial plan - Matrix year 12 english - Lone man building cathedral in spain - Northern renaissance art vs italian renaissance art - Bfc fried chicken mackay - Homework 6.39 - John f antioco net worth - Beginner Google Analytics Questions - Example of variable acceleration - Sace bonus points 2017 - How to write an editorial example - 9781260906301 - Hildegard von bingen opera - 0 10v dimming multiple fixtures - Brisbane city council south regional business centre - Grocery shop program in python - Effects of drugs on pulsation rate of lumbriculus variegatus - Need to create infographic for the element thallium - Conch republic electronics part 1 answers - "A" WORK PLAGIARISM FREE - Bank accepted bills australia - 34.5 divided by 40 - How to draw a cube on paper - The father of statistical quality control - Medicare provider analysis and review - Personal respones - What is common mode gain - The force f required to compress a spring - Originally carol ann duffy questions - Analyzing a poem i wandered lonely as a cloud answers - Rational emotive therapy ppt - Are ash trees fast growing - Roll a d6 lyrics - Pelicula de cesar chavez - DR SAM 0609702423 ABORTION CLINIC IN SOSHANGUVE - The following costs were incurred in april - 52a birksgate drive urrbrae - Flexible budget example in healthcare - 2 CPO RESPONSES - Example http www youtube com watch v qk6sbxwc4vs - Leadership and management term paper - English word stock list - Effects of not doing homework - James and the giant peach glow worm - Calculate the molarity of the vinegar sample - Synchronous machine problems and solutions - Human Service Dicussion Questions - Considering Hypotheses and Research Question - MEMORY - Ucl student support and wellbeing - Characternym - Organize and complete daily work activities doc - Frito lay assessment test answers - Samsung printer app windows 10 - Final Strategic Plan - Fast fluid power caldicot