Loading...

Messages

Proposals

Stuck in your homework and missing deadline? Get urgent help in $10/Page with 24 hours deadline

Get Urgent Writing Help In Your Essays, Assignments, Homeworks, Dissertation, Thesis Or Coursework & Achieve A+ Grades.

Privacy Guaranteed - 100% Plagiarism Free Writing - Free Turnitin Report - Professional And Experienced Writers - 24/7 Online Support

Patrick the human resources manager at acme company

23/11/2021 Client: muhammad11 Deadline: 2 Day

Final Project Milestone One: Draft Of Report

To complete this assignment, review the prompt and grading rubric in the Milestone One Guidelines and Rubric document. When you have finished your work, submit the assignment here for grading and instructor feedback.

ISE 640 Final Project Forensic Notes

Use the information in this document to help you complete your final project.

Drew Patrick, a director-level employee, is stealing intellectual property from a manufacturing company. The company is heavily involved in high-end development of widgets. Drew has access to corporate secrets and files. He is planning on leaving the company, taking the intellectual property with him, and going to work for a competitor. There is suspicion of him doing this, so human resources (HR) notified the information technology (IT) department to monitor Drew’s past history. An internal investigation is launched due to Drew’s abnormal behavior. The IT department confirms that they have found large files and emails. Forensics identified unauthorized access, transmission, and storage of intellectual property by Drew. Evidence found will be used to support legal civil and criminal proceedings.

Scenario ACME Construction Company designs, manufactures, and sells large construction vehicles that can cost upwards of a million dollars. They spent hundreds of thousands of hours redesigning their premier excavator. Every piece that goes into the excavator is individually designed to maximize the longevity of the equipment. Known for attention to detail, high-quality work, and industry innovation, this painstaking work is what sets ACME Construction company apart and is attributed for the excellent reputation they enjoy. This, in turn, allows them to charge a premium on their exceptionally well-built products.

Drew Patrick is a senior manager directly involved with the overall development of ACME’s excavators. His role provides him with access to design documentation, schematics, support documents, and any other technical references maintained in the company’s research and development (R&D) database. The R&D database is maintained by ACME’s information technology (IT) department, which is supported by a security operations center (SOC). The SOC uses Snort as a core component of their security information and event management (SIEM) system to keep tabs on network traffic, authentication requests, file access, and log file analysis.

The SIEM alerted SOC personnel of potential peer-to-peer (P2P) traffic originating from the internet protocol (IP) address associated with Drew’s computer. However, analysis of Active Directory logs indicated that Drew was not logged into his account at the time the files were transferred via the P2P application. ACME enforces two-factor authentication and does not allow for computer sharing. The SOC personnel began an incident report based on the identification of P2P traffic, which violates company policy. As per company policy, the SOC personnel gave human resources (HR) and the legal team the incident report. The legal team asked for further investigation. Upon further inspection of the P2P activity, several file transfers were discovered. The files transferred match the names of files in the R&D database containing intellectual property developed by Drew’s development team. Additionally, the files were transferred to IP addresses that are not owned or controlled by ACME Corporation.

Analysis of the server access logs indicated that Drew had been logging into the R&D database for several weeks prior to the external file transfers taking place. Network logs from the Intrusion Prevention Systems (IPSs) indicated that the files of interest had been transferred to Drew’s desktop computer prior to the external transfer. ACME has a strict policy against maintaining intellectual property anywhere other than the designated servers. File access logs on the R&D servers confirmed that the account belonging to Drew had copied the files in question.

At this point, fearing a loss of intellectual property, in addition to numerous policy violations, ACME called in the digital forensic team to take over the investigation. The forensics team proceeded to capture the log files from relevant computer systems and created a forensically sound copy of the hard disk drive on Drew’s computer. The log files investigated included the corporate mail, domain name server (DNS), and dynamic host configuration protocol (DHCP) servers, as well as physical access logs. Additionally, packet capture logs from the firewalls and intrusion detection system (IDS) were gathered and analyzed. This detailed investigation revealed that file transfers of intellectual property were indeed done from Drew’s computer, however, Drew’s account was not logged in at the time of the transfer. The only account active on the suspect computer was an anonymous account that had been created on 9/17/2016 at 9:57 p.m.

The following notes were provided by the Forensic Team:

Forensic Team Investigation Notes Notes from the investigative team about the forensic findings of the hard drive image obtained from Drew Patrick’s hard drive:

 Chain of custody document was begun with the sizing of the Western Digital Hard Drive 500 GB with serial number NB497356F from Drew Patrick’s computer.  Hard drive was duplicated using forensic toolkit (FTK) software to preserve the original hard drive image. A hash was created for the original and the copied image to prove both images were the same.  The operating system of the image was Windows-based. The operating system used a new technology file system (NTFS) file structure.  The hard drive was analyzed using Autopsy and Windows Forensic Toolchest. The sort and index functions were used to isolate the files needed for further analysis. These files include types SQL, Excel, email, chat, and HTML. Slack space was also analyzed.

Files and Findings EMAIL (Microsoft Outlook): Numerous emails were found that contained references to proprietary information. Some emails were to non-ACME Corporation email accounts, and they promised information pertaining to equipment design. Follow-up emails were found that asked for assurance of a promised managerial position.

CHAT (AOL Instant Messenger): Several chat conversations were recovered containing information about possession of proprietary documents.

SQL (Microsoft Database): SQL database files revealed proprietary information and connection logs to a remote SQL server. Two additional SQL database files were encrypted and were not successfully unencrypted.

EXCEL (Microsoft Excel): Numerous Excel files were located on the hard drive. These files contained parts list and parts specifications concerning proprietary construction equipment. These files had csv and xls extensions.

HTML: Recovered internet web browser cache revealed that the dark web was searched for proprietary information brokers. An email address was created to correspond in the dark web for buyer transactions called constructionseller@darkweb.com. Internet cache also revealed that YouTube was searched for the subjects “selling intellectual property” and “selling on the dark web.” Recovered internet browser history revealed pictures and illustrations on encrypting SQL database files. Internet browser history also revealed searches concerning how to exploit the vulnerabilities of an SQL database.

SLACK SPACE (hidden data and temporary files): Hidden information in the slack space was revealed to contain temporary internet files on searches for “advertising stolen data” and “hacking sql servers.” These files, once revealed, were in plain text and read using Notepad.

ISE 640 Milestone One Guidelines and Rubric

Overview: The milestone assignments in this course directly support you in the completion of your final project, a forensic investigative report. Consider the feedback you have received in class discussions, along with notes you have made in your non-graded investigative journal, to complete this milestone assignment.

This is Milestone One, a draft of Final Project One: Report. The final product will be submitted in Module Nine.

Please note that your non-graded investigative journal will be submitted with this milestone to ensure completion. Make sure that you are adding to your investigative journal as you complete each module.

Prompt: For the summative assessment, you will be taking on the role of a cybersecurity practitioner. You will need to act as a domain expert communicating to a non-expert stakeholder. For this milestone, you will be providing a summary of the scenario from the forensic notes document. You will also be explaining the relevant procedures needed to maintain evidentiary integrity: legal concerns, processes and procedures, and chain of custody. Lastly, you will be explaining details of the investigation, such as resources needed, methods, and findings. Ensure you review the full scenario in the main project document as well as the forensic notes document before drafting your report.

Specifically, the following critical elements must be addressed:

I. Executive Summary: Set the stage for your report, providing a brief overview of the situation and the stakeholders who are involved.

II. Legal Concerns: Describe the problem(s) and objectives you are working with the company’s attorneys to solve.

III. Relevant Procedures: In this section, you will outline the steps that (hypothetically) you will have to take prior to or as you investigate in order to maintain evidentiary integrity. Use your experiences from other situations you are engaging in within the lab environment to inform your responses.

A. Processes and Procedures: Describe processes or procedures necessary for handling a criminal situation by an internal employee.

B. Chain of Custody: Explain how to maintain the chain of custody as you investigate the various aspects of the incident. Support your response with specific examples.

IV. Details of Investigation: Based on your experiences in the labs, there will be specific resources, methods, and tools necessary to support the investigation in the scenario.

A. Resources Needs: Explain what resources (team knowledge, skills, and abilities) are necessary for gathering the evidence for this forensic investigation. Provide examples based on your experiences from the labs.

B. Methods: Describe the specific forensic method or approach you used to effectively leverage your available resources.

C. Findings: Describe the specific findings and the forensic tactics and technologies you employed to reach them.

V. Investigative Journal Notes: Submit your investigative journal that outlines most of the basics from each of the modules upon which you based your notes.

Rubric

Guidelines for Submission: Your assignment should adhere to the following formatting requirements: Write 4 to 5 double-spaced pages using 12-point Times New Roman font and one-inch margins. You should use current APA style guidelines for your citations and reference list. Be sure to attach both Milestone One and investigative journal files.

Homework is Completed By:

Writer Writer Name Amount Client Comments & Rating
Instant Homework Helper

ONLINE

Instant Homework Helper

$36

She helped me in last minute in a very reasonable price. She is a lifesaver, I got A+ grade in my homework, I will surely hire her again for my next assignments, Thumbs Up!

Order & Get This Solution Within 3 Hours in $25/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 3 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 6 Hours in $20/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 6 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 12 Hours in $15/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 12 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

6 writers have sent their proposals to do this homework:

Finance Homework Help
Unique Academic Solutions
Chartered Accountant
Accounting & Finance Master
High Quality Assignments
Isabella K.
Writer Writer Name Offer Chat
Finance Homework Help

ONLINE

Finance Homework Help

I can assist you in plagiarism free writing as I have already done several related projects of writing. I have a master qualification with 5 years’ experience in; Essay Writing, Case Study Writing, Report Writing.

$43 Chat With Writer
Unique Academic Solutions

ONLINE

Unique Academic Solutions

After reading your project details, I feel myself as the best option for you to fulfill this project with 100 percent perfection.

$40 Chat With Writer
Chartered Accountant

ONLINE

Chartered Accountant

I am an experienced researcher here with master education. After reading your posting, I feel, you need an expert research writer to complete your project.Thank You

$48 Chat With Writer
Accounting & Finance Master

ONLINE

Accounting & Finance Master

I am a professional and experienced writer and I have written research reports, proposals, essays, thesis and dissertations on a variety of topics.

$49 Chat With Writer
High Quality Assignments

ONLINE

High Quality Assignments

I am an experienced researcher here with master education. After reading your posting, I feel, you need an expert research writer to complete your project.Thank You

$26 Chat With Writer
Isabella K.

ONLINE

Isabella K.

After reading your project details, I feel myself as the best option for you to fulfill this project with 100 percent perfection.

$50 Chat With Writer

Let our expert academic writers to help you in achieving a+ grades in your homework, assignment, quiz or exam.

Similar Homework Questions

The Economics of Discrimination - Nursing and the Aging Family - Dna replication worksheet true or false answers - Db n420 - Acecqa educators and providers library - Vce chinese second language advanced - Ed masry law firm - Certificate iv in security operations - Pseudocode and python - Assignment 1 lenscrafters case study - Compass rallye 634 specification - Mood of everyday use - The st martin's guide to teaching writing pdf - Annual Updates - But this rough magic i here abjure - New heritage doll company simulation - Job Description and Justification - Insights Into Criminal Behavior - Develop an introduction with a thesis statement for the Final Paper. - Corporations and associations law principles and issues - Project - Air pwr b eol - Death has an appointment in samarra sufi legend - Crane technical paper 410 - Chemical reaction that produces gas - This is writing - Choosing a store location - 1,Discussion: The Application of Data to Problem-Solving and 2, Discussion: Where in the World Is Evidence-Based Practice? - Queensland building and construction commission act 1991 schedule 1b - Find the molar solubility of srco in pure water - Term ppr - Need answer for Discussion question 300 words each with 2 peer responses. - Gypframe rb1 resilient bar - 1st the worst rhyme - LIGHTING THE WAY AT THE MANOR HOUSE HOTEL - St james church alnwick - Halo effect pmp peter principle - Stevenage district riding club - Aromatic ammonia punishment - How to analyse case study in strategic management - Gotham company purchased a new machine - David easton authoritative allocation of values - Chi square test excel - St andrews avenue timperley - Mbs direct umuc - 521 Professor reply - Kiss me darling one more time lyrics - Advantages of case study in psychology - Reaction of amide with lialh4 - Mass communication living in a media world 7th edition - Enron the smartest guys in the room summary - Practical Connection Assignment - Understanding your college experience strategies for success 2nd edition - Shoo fly don't bother me - Week 5 Discission -Motivation - Ben and jerry's competitors - Rmit study support scholarship - 5-2 Final Project Milestone Three: Analysis of Ethics - Critical factors in project stakeholder management - Istqb test manager exam - Francine rivers net worth - Emc vplex cli guide - Factory x pty ltd - The opportunity cost of college worksheet - I need 1000 Words on Instruction The planner is designed. - Anti-parallel diode clipping circuit - Sociology (SSS100) - Syne hills care home - Enriched grains are cereal grains that - The mean value of land and buildings per acre - 0.655 to one decimal place - 2p permit holders excepted meaning - Plymouth university extenuating circumstances - Skin cancer investigation answers - Weekly tax timetable australia - Clinical field experience verification form - Introduction and Bibliography - Chevron lubricants sri lanka - How many different tests (i.e., scripts) did your intense scan perform? - Technicial writing - Audience Analysis- 5 paragraph only!!! - Fault block mountains examples - Themes in god's bits of wood - Capstone Research Companion - Christian Faith And Life - Health spa business plan - Paper chromatography of food dyes lab answers - Cons for kneeling during the national anthem - A $60,000 outlay for a new machine with a usable life of 15 years is called - Compute the electrical conductivity of a cylindrical silicon specimen - Use of mobile phones in education - AstroloGy bAbA 7340613399 OnLinE reaL VashIKaraN sPecIaLIsT IN Sambalpur - Headphones and earbuds paper docx - John frederick nims love poem analysis - +971561686603 Abortion pills in Dubai/Abu Dhabi-mifepristone & misoprostol in DUBAI - Open ended family focused questions - Biggest challenges facing organizations in the next 20 years powerpoint - How to draw a roller coaster track - Transmitted light in spectrophotometry - Week 1 Quiz - Succeeding in early world history mcgraw hill textbook answers