Loading...

Messages

Proposals

Stuck in your homework and missing deadline? Get urgent help in $10/Page with 24 hours deadline

Get Urgent Writing Help In Your Essays, Assignments, Homeworks, Dissertation, Thesis Or Coursework & Achieve A+ Grades.

Privacy Guaranteed - 100% Plagiarism Free Writing - Free Turnitin Report - Professional And Experienced Writers - 24/7 Online Support

Prodiscover

06/01/2021 Client: saad24vbs Deadline: 10 Days

Advanced Computer Forensics

Windows ProDiscover Forensics Lab

This lab is a replacement for the EnCase lab (122) for students who have been unable to access EnCase through RLES. In order to do this lab, you will need to download and install ProDiscover Basic (make sure to pick 32-bit or 64-bit depending on your version of Windows) from this URL: http://www.techpathways.com/desktopdefault.aspx?tabindex=8&tabid=14 (scroll down until you see the download links at the bottom of the page). You will also need to download a copy of the image files for this lab, 123img.zip. These image files are distributed under the GPL and were originally created by Brian Carrier.


Instructions appear as bullet points, questions are numbered and bolded.


Instructions & Questions

Start ProDiscover Basic.


Create a new project for this laboratory. Give it a unique number and name.


Click “Add” then “Image File” and add “123img1.dd”.


Click the “Action” menu then generate “OS Info”. This adds some information about the image to the report, which you can view at any time during your examination by clicking on “View” then “Report”.


What is the file system of this image file?


What is the volume name?


Go to “Cluster View” and click on the image.


How many clusters are used on this image file?


Go to “Content View” and click on the image.


List all the Deleted files recovered by ProDiscover in a table – and calculate the MD5 hash value for each deleted file.


Is there anything special about any of the files?


ProDiscover will use the time zone setting of your examiner workstation if no time zone is set for the evidence. When you acquire a computer as evidence it is important to make note of the computer’s time and time zone, especially if you need to correlate evidence from different time zones (never assume the time or time zone on a computer is correct.)


Where does the Time Zone information reside in a Windows system?


Set the timezone by clicking on File, then Preferences. The timezone should be US Central Time in this particular case (the image file has been extracted from a computer in that timezone although it is not an image of the system partition so there is no way to find the computer's actual timezone from the image itself).


What is the latest file creation time on the image?


Which files are resident files? Hint: you can right-click on a file and say “Show Cluster Numbers” to see the cluster/s in which the file is stored – you can do this for the $MFT of the disk image to see which clusters are allocated to the $MFT.


Add the second image to the case - “123img2.dd”


Go to the “Content View” and click “All Files”.


Go to the “View” menu and select “Gallery View”.


Which files display a thumbnail in Gallery View?


Are there any files with mismatching file extensions? If so, which ones? Identify their types according to their extension versus their actual type and explain how you have identified the actual type.


Disable Gallery View.


Extract all JPEG files from the image by selecting each of them. You will be prompted to add a comment about the file for the report. Record “JPEG file” and whether the file has been hidden, deleted, mislabelled or is in any other way special.


Right-click on a file and click “Copy All Selected Files”. Save them in a temporary directory on your computer.


Paste each JPEG file from your temporary directory into your submission document as an embedded image.


Do you think you have identified every JPEG file in the image? Hint: You can search for the JPEG file header by clicking on “Search”, selecting “Hex” and searching for the pattern FFD8. Do any files contain the pattern which do not appear in your temporary directory? If so, which ones?


Create a table for all files on the second image, listing each file's name and MD5 hash value.


Your answers to all questions should be stored in a LibreOffice document, Word document or PDF, and uploaded to Dropbox in the “EnCase Lab” folder as this exercise replaces the EnCase lab.

Homework is Completed By:

Writer Writer Name Amount Client Comments & Rating
Instant Homework Helper

ONLINE

Instant Homework Helper

$36

She helped me in last minute in a very reasonable price. She is a lifesaver, I got A+ grade in my homework, I will surely hire her again for my next assignments, Thumbs Up!

Order & Get This Solution Within 3 Hours in $25/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 3 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 6 Hours in $20/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 6 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 12 Hours in $15/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 12 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

6 writers have sent their proposals to do this homework:

University Coursework Help
Top Essay Tutor
Helping Hand
Writer Writer Name Offer Chat
University Coursework Help

ONLINE

University Coursework Help

Hi dear, I am ready to do your homework in a reasonable price.

$62 Chat With Writer
Top Essay Tutor

ONLINE

Top Essay Tutor

I have more than 12 years of experience in managing online classes, exams, and quizzes on different websites like; Connect, McGraw-Hill, and Blackboard. I always provide a guarantee to my clients for their grades.

$65 Chat With Writer
Helping Hand

ONLINE

Helping Hand

I am an Academic writer with 10 years of experience. As an Academic writer, my aim is to generate unique content without Plagiarism as per the client’s requirements.

$60 Chat With Writer

Let our expert academic writers to help you in achieving a+ grades in your homework, assignment, quiz or exam.

Similar Homework Questions

Predictive Methods - Burder forklift for sale - Reply 1 and 2 ,150 words each one add references and citations by 08/14/2020 - Dishonored basement vault key boyle estate - Public sector accounting objectives questions and answers - Viking documentary neil oliver - Bsuonline blackboard - Nursing care plan for fracture patient - R v katarzynski [2002] nswsc 613 - Discussion 2 Business ethics - Denmark hill to lewisham - Which of the following is not a distortion in perception - 2 bedroom basement for rent in surrey near scott road - Thomas adams school wem - Which quotation shows jacques in a positive light - Letter from birmingham jail outline - 2011 methods exam 2 - Potential rating scale appraisal problems - Coach k vs coach knight - What are 2 properties of water - Bio enzyme soil stabilization - Thermochemistry heat of reaction lab report - "Connect CIPD: Where Expertise Meets Your Level 5 Assignments" - How to compute single trade discounts - Lobbying against an issue - Ethics in Criminal Justice: - Gary tibble attorney kalamazoo mi - Sap archivelink configuration guide - Stainless steel nut and bolt torque settings - How to make a food web on powerpoint - An object of mass 1 kg travelling - Bus Cont Plan&Disas Recov Plan (ISOL-632-A04) - Phd In Information Technology - Cisco network services orchestrator - Construction of life table - Supply chain management - Direct sales association australia - Discuss the transactional model of communication - Personal communication devices and nursing - Rosicrucian home study lessons - Federated architecture in cloud systems - Steve jobs biography by nick bilton pdf - Disgronificator - Organ Leader - Written assignment - Hierarchy of cues speech therapy - Define the term cliché penn foster - P3 explain the issues related to the use of information - My manisku pte ltd - Maese industries inc has warrants outstanding - The afn equation and the financial statement forecasting - COURSE: NURS-6050N-66/NURS-6050C-66-Policy & Advocacy - Capella university marriage and family therapy - Assignments to be complete - Walmart brand equity - The natural order macbeth - Powerpoint presentation - Barton community college lsec fort riley - A head start currumbin - Krumboltz theory of career choice - Symbolic actions of eucharist - Do i have a healthy relationship quiz - Apple financial statements past 5 years - Labor Relations and Collective Bargaining - The chain rule worksheet - Discounting factoring and forfaiting - Two eigenvalues of a 3x3 matrix - Management cases peter drucker pdf - REVISE/POLISH MY ESSAY - Lab 3 diffusion and osmosis answers - Information Systems - Process Costing & cost behavior - Beyond stress strategies for blissful living pdf - Team Assignment: Organizational Performance Management Presentation - Rn capstone course chamberlain college nursing - Liberal credit policy - Australia tax table weekly - Rodding eye building regulations - Exam for Introduction to machine language and digital logic COSC 2325 - Disciplinary actions for plagiarism at penn foster - Continuum of managed health care plans - The great gatsby review questions - 75m offshore patrol vessel - What does the disaster recovery cost curve chart - Compensation management system in multinational companies - APA 01 - Harley davidson competitive advantage - Order 2497414: Formal Teacher Observation Student Teaching Video - Miller dynasty 200 help codes - A bank has three types of accounts - Clipsal lifesaver smoke alarm - International juvenile justice observatory - How do you write a ballad - Stew and braise difference - Discount factor table cima - Paranormal Essay - Sociology - Linguistic Assignment - It 210 basic security considerations - Mickleover primary learning platform - Penn foster writing process part 2 - Week 7 - Faraday's electromagnetic lab 1 answers