Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

Can you please help with the last step ( number 1 0 ) in writing a lab report? Module 5 Lab Part 2 OSForensics Password

Can you please help with the last step (number 10) in writing a lab report?
Module 5 Lab Part 2 OSForensics Password Recovery
1. Start OSForensics, if prompted to allow program to make changes to your computer, click YES. In the OSForensics message box, click Continue Using the Trial Version.
2. The Mount Drive Image button will need to be added to the left navigation pane. To accomplish this, select the Customize Workflow button which is located to the left in the navigation pane. You may need to click the down arrow at the bottom of the pane to see more items. From the Customize Workflow menu, check the Mount Drive Image option, under the Workflow menu column. Click OK. This will place the Mount Drive Image option into the left navigation pane.
3. Select the Mount Drive Image in the left navigation window, you may need to use the up/down arrows to find the item. This will present the Mount Virtual Disk window. Click Mount New button and provide path to image. The drive image named InCh05 is located on your Desktop/Lab Data/Module 5 folder. Once you select it click open, click next, click next again, then mount, and finally click exit.
4. Click the Manage Case button in the navigation bar on the left. From the Manage Case window, select new case. Provide a Case name. Click OK. This returns the Manage Case window.Under Add to Case, Select device. Click image file and provide path to image using the same path as you did in step 3 above. Click Ok. This will return you to the Manage Case window.
5. In the navigation bar on the left, click Passwords. In the pane on the right, click the Password and Keys tab. Click Scan button. (Your image file should be listed in the drive to be scan area). Select items and click add to case. Provide a descriptive name such as Passwords & Keys and click OK.
6. Now select the Window logins password tab. Click Scan button. (Your image file should be listed in the drive to be scan area). Select items and do a right click and select add list of all results to case. Provide a descriptive name such as Windows Login Passwords and click OK.
7. Now select User Activity from the left navigation pane. From the User activity window, select scan. Take a screenshot of the results and include them in your report for the lab.
8. In the navigation bar on the left, click Manage Case. In the Manage Case pane on the right, click generate report button. Leave the selected defaults in place and click OK. When you get the window to view in Edge, click OK.
9. From the report window, under the Evidence Artifacts section, select logins/Passwords which will present two items on the right. Select each of these items and take a screenshot of the results. You will have two screenshots from the report
10. Exit OSForensics.Turn in the screenshots (3) from steps 7 and 9 and submit them with your lab report.
I have to screenshots. thanks

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Machine Learning And Knowledge Discovery In Databases European Conference Ecml Pkdd 2022 Grenoble France September 19 23 2022 Proceedings Part 4 Lnai 13716

Authors: Massih-Reza Amini ,Stephane Canu ,Asja Fischer ,Tias Guns ,Petra Kralj Novak ,Grigorios Tsoumakas

1st Edition

3031264118, 978-3031264115

More Books

Students also viewed these Databases questions

Question

What does a firms liquidity measure?

Answered: 1 week ago