Loading...

Messages

Proposals

Stuck in your homework and missing deadline? Get urgent help in $10/Page with 24 hours deadline

Get Urgent Writing Help In Your Essays, Assignments, Homeworks, Dissertation, Thesis Or Coursework & Achieve A+ Grades.

Privacy Guaranteed - 100% Plagiarism Free Writing - Free Turnitin Report - Professional And Experienced Writers - 24/7 Online Support

Ftk live search

17/12/2020 Client: saad24vbs Deadline: 7 Days

Advanced Computer Forensics


Windows FTK Forensics Lab

Read the ENTIRE document before starting to be sure you have all the necessary tools and files required to complete the lab. You should further explore the tools used in this lab to ensure your familiarity with alternative investigation options.


Lab Setup for using RLES vCloud


This lab is designed to function on the RLES vCloud. The interface is available by navigating to https://rlesvcloud.rit.edu/cloud/org/NAT . You have created a vApp in your previous labs. Now, you will add the vApp template, 841_Win_Forensics_Updated , from the Public Catalogs, to the same vApp following the instruction of Add Virtual Machines to a vApp without a network required (see RLES vCloud User Guide).


FTK software including FTK 1.8, Registry Viewer and FTK Imager are install in the 841_Win_Forensics_Updated VM. The EnCase evidence file, WinLabEnCase, is located in the local E:\ drive in RLES VM. Please read FTK 1.80 User Manual, posted in RLES, for FTK details.


The 841_Win_Forensics_Updated VM login


Username: Administrator


Password: netsys


NOTE: If you are not able to open the VM, please reset the VM’s mac address (right click on the VM, choose property, then click on the Hardware tab, click on the drop down arrow of mace address to reset the mac address)


PART I: Familiar with FTK Imager


Bonus Exercise 1 (5 points): Assume that you have a write-protected USB device.


Image a USB device or a floppy disk to create an image in a DD format. (Note: You are not able to use the 841_Win_Forensics_Updated VM to perform this bonus exercise. You have to use your own computer for this exercise).


Provide a snapshot from FTK Imager.


Requires: a USB device or a floppy disk


Launch FTK Imager


Click File > Create Disk Image


Click Physical Drive and Next


Select the device and select Raw (dd) Image Type


Exercise 2: View images


Click File > Add Evidence Item


Select Image file and then click Next


Browse to your WinLabEnCase.E01 image and click Finish


View the image in the Evidence Tree view


Question 1: What is the VBR file used for? How to export this file? How to export a file Hash?


Exercise 3: Convert the WinLabEnCase image to a DD image


In the Evidence Tree view, select the WinLabEnCase image


Click File > Export Disk Image


In the Create Image dialog, click Add


Select the raw image type and name it as converted.


Exercise 4: Verify images


Select the Encase Image and click File > Verify Drive/Image


Add in the converted raw image to the FTK Imager and click File > Verify Drive/Image.


Question 2: What are the results of verification? Comparing both hashes, are they same or not?


PART II: Working with FTK 1.8x


All exercises and questions in this part are designed for FTK 1.8x.


NOTE: If you choose to use FTK 4 instead of FTK 1.8x, please follow PART III.


Objective: Based on the experience you have in the previous lab, you will utilize FTK to conduct an analysis of an incident. This project will help you tie all of the pieces and techniques together, so that you have a better understanding of the whole picture of forensics investigation.


Requires: FTK and a windows’ disk image provided by your instructor.


Descriptions: In this lab you will be given a scenario and a disk image to go along with it. You will use FTK to analyze the disk image, retrieve deleted files and terms that have been purposefully hidden, and then use FTK to create a report about this incident.


Scenario: ACME Industries develops custom software for the aviation industry. Its main competitors are companies Raytheon and Boeing and a few smaller contractors.


Pat Smith has worked for ACME Industries for 5 years. His supervisor has noted that after being past over several times for a promotion, Pat has become quite disgruntled. The company fears that Pat may be offering proprietary company information to a competitor in exchange for a job.


The first investigator has created an Encase image of Pat’s computer’s hard drive. Your job is to examine it and extract all pertinent information to the investigation. You are to make no assumptions of innocence or guilt, just to gather information.


Steps involved:


1) Locate the EnCase evidence file “WinLabEnCase.E01”


2) Create a new case and add the EnCase evidence file to FTK for investigation.


3) Analyze the image.


Show the activities such as recovering deleted files; finding information that have been purposefully hidden; analyzing MAC time, signatures and Hash sets; searching keywords; gathering pertinent information from compound files such as outlook express .dbx files and registry files; examining IE history file, searching recycled files though the hidden Recycled folder and printer’s spool files located in WINDOWS\system32\spool\PRINTERS etc.


4) Generate a report


Note: All information in your report needs to be verified and repeatable in order to be admissible in court.


DETAILED PROCEDURES THAT MAY HELP YOU TO GO THROUGH THE FTK SOFTWARE


Exercise 1: Starting a New Case

Click File > “New Case” to begin a new case.


Name the case “FTK Case 1”


Enter your name as the examiner.


Enter your information as the forensic Examiner Information


Question 3: What information is required to create a new case using the FTK New Case Wizard?


In the Case Log Options window, leave all options marked. Try to understand each of the options.


In the Processes to Perform window, leave all options marked. Try to understand each of the options.


In both the Refine Case Default and the Refine Index Default windows, leave all options marked. Try to understand each of the options.


Add an Image to the exist case

In the Add Evidence to the Case window click “Add Evidence”, choose “Acquired Image of Drive”


Question 4: What are the types of evidence that can be added to a case in FTK?


Select the “WinLabEnCase.E01” file.


Set the Time Zone


When you acquire a computer as evidence it is important to make note of the computer’s time and time zone, especially if you need to correlate evidence from different time zones (never assume the time or time zone on a computer is correct.)


To set the time zone in FTK, in the Local Evidence Time Zone Selection window, choose your local time zone.


Exercise 2: Working with FTK


Click the OVERVIEW tab; note the numbers for each type of file.


Question 5: How to make the number of the Checked Items to go up? How to make the number of Flagged Thumbnails to go up?


File Signatures

A file type (JPEG, Word Document, MP3 file) can be determined by the file’s extension and by a header that precedes the data in the file. If a file’s extension has been changed, then the only way to determine its type is by looking at its header.


Question 6: Click on Bad Extension from Overview tab. Do you find any signature mismatch? What are they?


Data Carved Files:


Question 7: Check the number of Data Carved Files, what is the number?


Click on Tools > Data Carving…


Select only GIF Files to perform date carving.


Highlight all the files in the filelist and add them to the case.


Question 8: Check the number of Data Carved Files from Overview, how many files added to the case by data carving?


Question 9: What are those files found by performing data carving process? Why is this process so important?


Explore Tab


Check mark List all descendants.


Question 10: What is the file system of this Image?


Question 11: Right-click a folder and select File Properties, What information do you get?


Question 12: Select a file, and right-click on that file and select File Properties, What information do you get?


Question 13: Select Documents and Settings\psmith\Recent, what kind of files contain in this folder? Select each file in this folder, what kind of information do you get from the up-right window?


Question 14: Select Documents and Settings\psmith\Local Settings\History\History.IE5\index.dat, what kind of files contain in this file? Select each file, what kind of information do you get from the up-right window?


Question 15: Select Documents and Settings\psmith\Favorites, what are psmith’s favorite links?


Question 16: Looking into the Recycled folder, which files are currently in the recycler? Select the INFO2 file from the Recycled folder, what information do you get from that file?


Question 17: Looking into WINDOWS\System32\spool folder, what information can you get from this folder?


Windows Registry

Locate ntuser.dat from the Documents and Settings\psmith folder


Export the ntuse.dat; then launch the AccessData Registry Viewer to include this file in the Registry Viewer. (You may also right click the file and choose View in Registry Viewer


In the Registry Viewer, explore the list.


Action 18: List any interesting results


Graphics Tab

The Graphics Tab allows you to quickly see all the pictures in the case.


Check mark List all descendants.


You will now see all of the pictures contained on all of the devices in the case.


Question 19: If a file’s extension has been changed to a non-graphics file type (such as changing jpg to txt), will it be displayed in the Gallery view? Provide one example to support your statement. Does EnCase work in the same way?


Bookmarking

Bookmarks allow you to mark folders, files, or parts of a file for later reference and for inclusion in reports.


Highlight (or checkmark) three graphics in the file list; right click the graphics and select Create Bookmark.

In the Create New Bookmark menu, name the bookmark Highlighted Graphics. Then select All highlighted items (or Checked Graphics) and click OK. Go to the Bookmark Tab to verify the bookmark.


Flag five graphics to green by clicking on the red circles. Go to the Overview tab and select the Flagged Thumbnails container to verify that the graphics you just flagged are included.


Export and Copy Special


Export these five graphics to your desktop.


Use Copy Special to copy a list of the dates and times associated with the exported files to the clipboard. Then paste this data into Microsoft Excel.


Question 20: What is the major difference between Export a file and Copy Special a file?


Keywords and Searching

Searching evidence for information pertaining to a case can be one of the most crucial steps in the examination. FTK support two kind of search, indexed and live searches. An indexed search uses the index file to find a search term while a live search involves an item-by-item comparison with a search term. The index file could be generated during the creation of a case or be indexed later.


Question 21: What is the advantage to use indexed search vs. the live search?


Click the Search > Indexed Search tab. In the Search Term box, type some keywords, for example “Job”; then click Add.


Click View Cumulative Results if you add multiple keywords or click “view item results”


Expand the search results.


Select one file and find the instances of “Job” in the file.


Create a bookmark to keep a couple of important files in the bookmark called Search Bookmark.


Examining the Options and Import feature in the indexed Search


Question 22: What are these two features used for?


In the Search tab, select Live Search


Click Regular Expression and click the arrow to view the available regular expressions


Choose Edit Expressions to view the default regular expressions.


Select US Phone Number and Search.


Question 23: Do you find any files containing US Phone numbers? List two files that in the result list.


Email

Email processing is one of the most important steps in forensics investigation. FTK supports powerful email feature to help you process emails.


Question 24: Read the manual and find out what kind of email formats do FTK support?


Click on the E-Mail tab


Navigate to Deleted items.dbx, Inbox.dbx and Sent Items.dbx, check for each message and bookmark some important messages to support your final report.


Question 25: Did anything happen? Do you find any important information? If so, what kind of information you got?


Case Report

After performing a thorough forensic investigation, it is critical that you are able to publish and present your findings. FTK has a sophisticated report wizard that allows you to assemble and publish case information. The final report generated by the FTK wizard is in HTML format.


Click File > Report Wizard


Fill in the Case information which will appear on the Case Information page of the report.


Create a report to include the following:


a) all bookmarks and export all bookmarked files


b) Export full-size graphics and link them to the thumbnails


c) Include the Date and Time file Properties for the Bookmarked Files


d) Include only graphics flagged green in the Graphics View


e) Group 6 thumbnail per row


f) Include Bad Extension files in the report and export the files to the report along with its data and time property


g) Add one or more of your own file to the report that support your statement


h) Create a custom graphic for the report.


Action 26: Include two screenshots of this report in your submission.


PART III: Working with FTK 4 (Bonus)


FTK 4 is install on the Windows 7 w/FTK 7 EnCase VM that is used in your EnCase lab. Please read FTK 4 User Manual, posted in RLES, for FTK details.


FTK 4 on Windows 7 w/FTK 7 EnCase login:


Username: Student


Password: student


Bonus question 1: (10 points): Follow the procedure defined in PART II and answer all appropriate questions from PART II using FTK 4. If a question from RART II does not work in FTK 4, please leave “N/A” in your answer.


Be aware that FTK imager and Registry Viewer are not installed on the Windows 7 w/FTK 7 EnCase VM.


Bonus question 2: (10 points): What new FTK4 features did you use to investigate this case (Include detailed steps and screenshots to support your answer)?


PAGE


9


Computer Forensics - FTK


Applied Sciences

Architecture and Design

Biology

Business & Finance

Chemistry

Computer Science

Geography

Geology

Education

Engineering

English

Environmental science

Spanish

Government

History

Human Resource Management

Information Systems

Law

Literature

Mathematics

Nursing

Physics

Political Science

Psychology

Reading

Science

Social Science

Home

Blog

Archive

Contact

google+twitterfacebook

Copyright © 2019 HomeworkMarket.com

Homework is Completed By:

Writer Writer Name Amount Client Comments & Rating
Instant Homework Helper

ONLINE

Instant Homework Helper

$36

She helped me in last minute in a very reasonable price. She is a lifesaver, I got A+ grade in my homework, I will surely hire her again for my next assignments, Thumbs Up!

Order & Get This Solution Within 3 Hours in $25/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 3 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 6 Hours in $20/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 6 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 12 Hours in $15/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 12 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

6 writers have sent their proposals to do this homework:

Best Coursework Help
Homework Guru
Top Essay Tutor
University Coursework Help
Helping Hand
Writer Writer Name Offer Chat
Best Coursework Help

ONLINE

Best Coursework Help

I am an Academic writer with 10 years of experience. As an Academic writer, my aim is to generate unique content without Plagiarism as per the client’s requirements.

$100 Chat With Writer
Homework Guru

ONLINE

Homework Guru

Hi dear, I am ready to do your homework in a reasonable price and in a timely manner.

$102 Chat With Writer
Top Essay Tutor

ONLINE

Top Essay Tutor

I have more than 12 years of experience in managing online classes, exams, and quizzes on different websites like; Connect, McGraw-Hill, and Blackboard. I always provide a guarantee to my clients for their grades.

$105 Chat With Writer
University Coursework Help

ONLINE

University Coursework Help

Hi dear, I am ready to do your homework in a reasonable price.

$102 Chat With Writer
Helping Hand

ONLINE

Helping Hand

I am an Academic writer with 10 years of experience. As an Academic writer, my aim is to generate unique content without Plagiarism as per the client’s requirements.

$100 Chat With Writer

Let our expert academic writers to help you in achieving a+ grades in your homework, assignment, quiz or exam.

Similar Homework Questions

126 tuckers lane north rothbury nsw 2335 - +971561686603 Abortion pills in Dubai/Abu Dhabi-mifepristone & misoprostol in DUBAI - Family life cycle stages psychology - The eukaryotic cell cycle and cancer worksheet answers - Does pepsi own taco bell - How do incumbents respond to the threat of entry - Creswell purpose statement - Griffith uni accommodation nathan - Single double triple tetra penta hexa - Literary comparison crossword clue - Decision Making - Opening remarks for letter - Sally goddard blythe wikipedia - Raptor pseudocode - 2/23 ferguson avenue labrador - Examples of multicellular organisms - Upon arriving in london what did magwitch call himself - Royal arch chapter room layout - The execs gtfoh mp3 download - NURS-6050N-66/NURS-6050C-66-Policy & Advocacy - Costa coffee digital marketing strategy - Seven c's of communication - Accounting Case - Fear and odin in the shroud - 1769 aentr set ip address - Best bubble gum for blowing bubbles - The call by jessie pope essay - Journal 3 - Which of the following is not a tropic hormone - Innovative health - Ceramic capacitor code 103 - Survey of Partial Differential Equations - Discussion Board - Visual Studio Coding (R) - Https lc ugrad1 gcu edu - Areva vacuum circuit breaker - Advantages and disadvantages of rock armour - How to stop translating in packet tracer - Industrial regions of the world on map - English - Ansi z535 4 arc flash - Police signal codes florida - De escalation techniques powerpoint - Difference between classification and clustering ppt - How to measure cloud cover - Training and development 5? - 1.09 unit test narrative techniques and structure quizlet - The following information has been obtained for the gocker corporation - Lamarck vs darwin worksheet answers - Probability distribution ti 84 - Ryanair organisational structure chart - Significance of dante's inferno in prufrock - Blade runner rachael quotes - Hyperbole for loud noise - Gordon's 11 functional health patterns examples - Business math final exam answers - Our iceberg is melting group activities - Human service delivery system - Abstract algebra a first course by dan saracino - Alternate form reliability definition - Wechsler preschool and primary scale of intelligence - Hydraulic powered robotic arm - 2/22 arundel court hoppers crossing - How to make a wet mount onion slide - Aqa italian past papers - Composition of target market for lemonade - Eric foner give me liberty volume 2 citation - Ann taylor survival in specialty retail - Lit 102 paper - What is 24 inches long - Network pro exam answers - Puente hills toyota case study - William damon's stages of friendship - Identify 4 principles of implied consent - Helen keller documentary youtube - Planet fitness commercial big muscle - ERM - Drill size for 3/8 unc tap - Stolen rivers poem analysis - Delta air lines a the low cost carrier threat - Economic Recession - How to make a stem and leaf plot in powerpoint - Equilibrium arrow in word - Describe the relationship between health care cost and quality - Spiritual needs assessment interview questions - Flow level 126 11x11 - NEED IN 8 HOURS or LESS (NO EXCEPTION) - For Daniel Only - Eccles vets bowling league - Railmatch paint colour chart - Premarital and marital counselling ppt - Training and development #3 - A life cycle of a wolf - Heat of combustion of paraffin lab answers - What was the dow on december 31 - Assignment: Academic Success and Professional Development Plan Part 3: Strategies to Promote Academic Integrity and Professional Ethics - Imogene king theory of goal attainment ppt - Beyonce diet pepsi commercial - International conference on harmonization guidelines for good clinical practice - Disability Awareness Board