Answered step by step
Verified Expert Solution
Question
1 Approved Answer
AUTOMATED DATA COLLECTION USING - KAPE ( WIN 1 0 ) Performing disk forensics using KAPE. Step 0 : Fire the Windows 1 0 VM
AUTOMATED DATA COLLECTION USING KAPE WIN
Performing disk forensics using KAPE.
Step: Fire the Windows VM up
Step: Download KAPE
From your Win VM open Edge up
Download Kape.zip
Unzip Kape.zip in the folder C:userXXX
Run the commandline and cd to kape: cd C:userXXX
Display the KAPE folder and make sure kape.exe is there: dir
Collect and process the following artifacts from a live system your Win VM and save them in the C:tmp folder remember to create a subfolder under the tmp folder for each artifact
GroupPolicy
RegistryHivesUser
WindowsTimeline
Answer the following questions:
Question
Include the top of screenshots see slide# for an example here for GroupPolicy
Question
Include the top of screenshots see slide# for an example here for RegistryHivesUser
Question
Include the top of screenshots see slide# for an example here for WindowsTimeline
Analyze the artifacts of WindowsTimeline and RegistryHivesUser using Timeline Explorer. Open the CSV files and answer the following questions:
Question
WindowsTimeline
When was the coiadmin user account created?
ex at ::
When was the last time the coiadmin user account was modified?
and
ex at ::or date and time order is from low to high
When was the coistudent user account created?
ex at ::
When was the last time the coistudent user account was accessed?
and
ex at ::or date and time order is from low to high
Question
RegistryHivesUser:
When was the configDEFAULT created?
ex at :: or
When was the last time the configDEFAULT was modified?
ex at ::or
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started