Question: AUTOMATED DATA COLLECTION USING - KAPE ( WIN 1 0 ) Performing disk forensics using KAPE. Step 0 : Fire the Windows 1 0 VM

AUTOMATED DATA COLLECTION USING- KAPE (WIN10)
Performing disk forensics using KAPE.
Step0: Fire the Windows10 VM up
Step1: Download KAPE
From your Win10 VM, open Edge up
Download Kape.zip
Unzip Kape.zip in the folder C:\user\XXX
Run the command-line and cd to kape: cd \ C:\user\XXX
Display the KAPE folder and make sure kape.exe is there: dir
Collect and process the following artifacts from a live system (your Win10 VM) and save them in the C:\tmp folder (remember to create a subfolder under the tmp folder for each artifact)
- GroupPolicy
- RegistryHivesUser
- WindowsTimeline
Answer the following questions:
Question 1
Include the top of screenshots (see slide#36 for an example) here for GroupPolicy
Question 2
Include the top of screenshots (see slide#36 for an example) here for RegistryHivesUser
Question 3
Include the top of screenshots (see slide#36 for an example) here for WindowsTimeline
Analyze the artifacts of WindowsTimeline and RegistryHivesUser using Timeline Explorer. Open the CSV files and answer the following questions:
Question 4
WindowsTimeline
- When was the coiadmin user account created?
ex.2016-03-02 at 10:16:42
- When was the last time the coiadmin user account was modified?
,, and
ex.2016-03-02 at 10:16:42/or 2016(date and time order is from low to high)
- When was the coistudent user account created?
ex.2016-03-02 at 10:16:42
- When was the last time the coistudent user account was accessed?
,, and
ex.2016-03-02 at 10:16:42/or 2016(date and time order is from low to high)
Question 5
RegistryHivesUser:
- When was the \config\DEFAULT created?
ex.2016-03-02 at 10:16:42/ or 2016
- When was the last time the \config\DEFAULT was modified?
ex.2016-03-02 at 10:16:42/or 2016

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!