CHAPTER 1 Understanding the Digital Forensics Profession and Investigations Hands-On Project 1-2 In this project, you work
Fantastic news! We've Found the answer you've been seeking!
Question:
|
|
|
|
|
- Start Autopsy for Windows, if you exited it at the end of the previous project. If the previous project is open, click Case, Close Case from the menu. Click the Create New Case icon. In the New Case Information window, enter C1Prj02 in the Case Name text box, and click Browse next to the Base Directory text box. Navigate to and click your work folder, and then click Next.
- In the Additional Information window, type C1Prj02 in the Case Number text box and your name in the Examiner text box, and then click Finish.
- In the Select Data Source window, click the Select data source type list arrow, and click Disk Image or VM file. Click the Browse button next to the Browse for an image file text box, navigate to and click your work folder and the C1Prj02.001 file, and then click Open. Click Next.
- In the Configure Ingest Modules window, click Select All. Click Next and then Finish.
- Click the Keyword Search button at the far upper right, type confidential in the text box, and then click Search.
- In the Result Viewer pane, a new tab named Keyword search 1 opens. Click each file to view its contents in the Content Viewer pane.
- Ctrl+click to select the files in the Keyword search 1 tab. Right-click this selection, point to Tag File, and click Tag and Comment. In the Create Tag dialog box, click the New Tag Name button, type Recovered Office Documents in the Tag Name text box, and then click OK.
- Click Generate Report at the top. In the Generate Report window, click the Results - Excel option button in the Report Modules section, and then click Next.
- In the Configure Artifacts Report window, click the Tagged Results button, click the Recovered Office Documents check box, and then click Finish.
- In the Report Generation Progress Complete window, click the Results - Excel pathname to open the Excel report. This Excel file should have several tabs of information about the files you tagged for this project.
|
|
|
|
- Start Autopsy for Windows, and click the Create New Case icon. In the New Case Information window, enter C1Prj03 in the Case Name text box, and click Browse next to the Base Directory text box. Navigate to and click your work folder, and then click Next.
- In the Additional Information window, type C1Prj03 in the Case Number text box and your name in the Examiner text box, and then click Finish.
- In the Select Data Source window, click the Select data source type list arrow, and click Disk Image or VM file. Click the Browse button next to the Browse for an image file text box, navigate to your work folder and click the C1Prj03.E01 file, and then click Open. Click Next.
- In the Configure Ingest Modules window, click Select All. Click Next and then Finish.
- In the Tree Viewer pane, expand Views, File Types, By Extension, and Images.
- In the Result Viewer pane, scroll to the right, if necessary, until the Modified Time column is in view. Sort the column by clicking the Modified Time header.
- Scroll down until you find the first file with a starting month of April 2006, and then click the file to view it in the Content Viewer. Press the down arrow on the keyboard to view all files created or modified in April 2006.
- Ctrl+click every file that has a photo of a boat or part of a boat. Right-click this selection, point to Tag File and then Quick Tag, and click Follow Up.
|
|
|
- In the Result Viewer pane, click the Thumbnail tab to view the tagged photos.
- To create a report, click Generate Report at the top. In the Generate Report window, click the Results - HTML option button in the Report Modules section, and then click Next.
- In the Configure Artifacts Report window, click the Tagged Results button, click the Follow Up check box, and then click Finish.
- In the Report Generation Progress window, click the Results - HTML pathname to view the report. When viewing the report, click the links to examine the tagged files. When youre finished, click Close in the Report Generation Progress window.
- Exit Autopsy, and write a short memo to summarize your findings.
- Start Autopsy for Windows. Click the Create New Case icon. In the New Case Information window, enter C1Prj04 in the Case Name text box, and click Browse next to the Base Directory text box. Navigate to and click your work folder, and then click Next.
- In the Additional Information window, type C1Prj04 in the Case Number text box and your name in the Examiner text box, and then click Finish.
- In the Select Data Source window, click the Select data source type list arrow, and click Disk Image or VM file. Click the Browse button next to the Browse for an image file text box, navigate to your work folder and click the C1Prj04.E01 file, and then click Open. Click Next.
- In the Configure Ingest Modules window, click Select All. Click Next and then Finish.
- In the Tree Viewer pane, expand Views, File Types, and By Extension. Under By Extension are several subfolders representing file types, as youve seen in previous projects. Next to each file type subfolder is a number enclosed in parentheses, which shows the number of files of this type Autopsy found. Click subfolders with numbers greater than zero to view the files.
- In the Result Viewer pane, scroll to the right, if necessary until the Flags(Meta) column is in view. Sort the column by clicking the Flags(Meta) header, which displays all allocated files to the top of the list.
|
|
|
|
- Scroll to the left until the Name column is visible. If there are allocated files, they will be at the top of this list. Ctrl+click each allocated file, right-click this selection, and then click Extract File(s).
- In the Save dialog box, click Save to save the files automatically in Autopsys case subfolder: Work\Chap01\Projects\C1Prj04\Export.
- Write a brief memo that lists all the files you exported. Leave Autopsy running for the next project.
- Start Autopsy for Windows and click the Open Recent Case icon, if necessary.
- In the Tree Viewer pane, expand Views, File Types, Deleted Files, and All.
- In the Result Viewer pane, Ctrl+click all files in the All subfolder. Right-click this selection, point to Tag File and then Quick Tag, and click Follow Up.
- Click Generate Report at the top. In the Generate Report window, click the Results - Excel option button in the Report Modules section, and then click Next.
- In the Configure Artifacts Report window, click the Tagged Results button, click the Follow Up check box, and then click Finish.
- In the Report Generation Progress Complete window, click the Results - Excel pathname to open the Excel report. When youre finished, click Close in the Report Generation Progress window.
|
|
- ANTONIO
- HUGH EVANS
|
|
|
|
- In the Select Data Source window, click the Select data source type list arrow, and click Disk Image or VM file. Click the Browse button next to the Browse for an image file text box, navigate to your work folder and click the C1Prj06.E01 file, and then click Open. Click Next.
- In the Configure Ingest Modules window, click Select All. Click Next and then Finish.
- Click the Keyword Lists button at the far upper right, and then click Manage List.
- In the Global Keyword Search Settings dialog box, click the New List button. In the New Keyword List dialog box, type ListSearch1 in the New keyword list text box, and then click OK.
- In the Keyword Lists section, click ListSearch1, as shown in Figure 1-22, and then click the New keywords button under the Keyword Options heading.
|
|
|
|
Case Project 1-2 Jonathan Simpson owns a construction company. One day a subcontractor calls him, saying that he needs a replacement check for the job he completed at 1437 West Maple Avenue. Jonathan looks up the job on his accounting program and agrees to reissue the check for $12,750. The subcontractor says that the original check was for only $10,750. Jonathan looks around the office but cant find the company checkbook or ledger. Only one other person has access to the accounting program. Jonathan calls you to investigate. How would you proceed? Write a one-page report detailing the steps Jonathan needs to take to gather the necessary evidence and protect his company. |
Case Project 1-3 You are the digital forensics investigator for a law firm. The firm acquired a new client, a young woman who was fired from her job for inappropriate files discovered on her computer. She swears she never accessed the files. What questions should you ask and how should you proceed? Write a one- to two-page report describing the computer the client used, who else had access to it, and any other relevant facts that should be investigated. |
Posted Date: