Case is individual work Case 3 deadline is June 3 by 11:00 pm Cases Grade 20...
Fantastic news! We've Found the answer you've been seeking!
Question:
Transcribed Image Text:
Case is individual work Case 3 deadline is June 3 by 11:00 pm Cases Grade 20 20 20 20 20 100 Case 1 Case 2 Case 3 Case 4 Case 5 Total Rubrics Case 2 - Total 20 points 20.0 pts Excellent Submission- Word Document 1. Steps you have done with screenshots 2. Autopsy Report 3. In-depth explanation and analyze the USB drive data Download Autopsy Forensic Tool (Free download) http://sleuthkit.org/autopsy/ Task 1 10.0 pts Good Analyzing Your Digital Evidence using Autopsy Forensic Tool 0.0 pts Poor When you analyze digital evidence, your job is to recover the data. If users have deleted or overwritten files on a disk, the disk contains deleted files and file fragments in addition to existing files. Remember that as files are deleted, the space they occupied becomes free space-meaning it can be used for new files that are saved or files that expand as data is added to them. The files that were deleted are still on the disk until a new file is saved to the same physical location, overwriting the original file. In the meantime, those files can still be retrieved. Forensics tools such as Autopsy can retrieve deleted files for use as evidence. Task 1 1- Download Autopsy Forensic tool (It is a free tool to download, also available on computer labs) a. http://sleuthkit.org/autopsy/ b. Follow the steps in "Autopsy tool how to use" to complete the report and investigation (the .dd file is available on canvas) OR You can access to Autopsy Forensic Tool available on weblabs: https://weblabs.psu.edu/ Task 1 Submission-For every step make a screenshot and create a report for submission (5 points) Task 2 Discuss the following after Completing the Case in your report The files on George's USB drive indicate that he was conducting a side business on his company computer. Now that you have retrieved and analyzed the evidence, you need to find the answers to the following questions to write the final report: How did George's manager acquire the disk? Did George perform the work on a laptop, which is his own property? If so, did he conduct business transactions on his break or during his lunch hour? At what times of the day was George using the non-work-related files? How did you retrieve this information? Which company policies apply? Are there any other items that need to be considered? When you write your report, state what you did and what you found. The report you generated in Autopsy gives you an account of the steps you took. As part of your final report, depending on guidance from management or legal counsel, include the Autopsy report file to document your work. In any computing investigation, you should be able to repeat the steps you took and produce the same results. This capability is referred to as repeatable findings; without it, your work product has no value as evidence. Task 2 Discuss the following after Completing the Case in your report The files on George's USB drive indicate that he was conducting a side business on his company computer. Now that you have retrieved and analyzed the evidence, you need to find the answers to the following questions to write the final report: How did George's manager acquire the disk? Did George perform the work on a laptop, which is his own property? If so, did he conduct business transactions on his break or during his lunch hour? At what times of the day was George using the non-work-related files? How did you retrieve this information? Which company policies apply? Are there any other items that need to be considered? When you write your report, state what you did and what you found. The report you generated in Autopsy gives you an account of the steps you took. As part of your final report, depending on guidance from management or legal counsel, include the Autopsy report file to document your work. In any computing investigation, you should be able to repeat the steps you took and produce the same results. This capability is referred to as repeatable findings; without it, your work product has no value as evidence. Keep a written journal of everything you do. Your notes can be used in court, so be mindful of what you write or e-mail, even to a fellow investigator. Often these journals start out as handwritten notes, but you can transcribe them to electronic format periodically. Basic report writing involves answering the six Ws: who, what, when, where, why, and how. In addition to these basic facts, you must also explain computer and network processes. Typically, your reader is a senior personnel manager, a lawyer, or occasionally a judge who might have little computer knowledge. Identify your reader and write the report for that person. Provide explanations for processes and how systems and their components work. Your organization might have templates to use when writing reports. Depending on your organization's needs and requirements, your report must describe the findings from your analysis. The report generated by Autopsy lists your examination and data recovery findings. Other digital forensics tools generate a log file of all actions taken during your examination and analysis. Integrating a digital forensics log report from these other tools can enhance your final report. When describing the findings, consider writing your narrative first and then placing the log output at the end of the report, with references to it in the main narrative. In the Montgomery 72015 case, you want to show what evidence exists that George had his own business registering domain names and list the names of his clients and his income from this business. You also want to show letters he wrote to clients about their accounts. The time and date stamps on the files are during work hours, so you should include this information, too. Eventually, you hand the evidence file to your supervisor or to Steve, George's manager, who then decides on a course of action. Critiquing the Case in your report After you close the case and make your final report, you need to meet with your department or a group of fellow investigators and critique the case in an effort to improve your work. Ask yourself assessment questions such as the following: How could you improve your performance in the case? Did you expect the results you found? Did the case develop in ways you did not expect? Was the documentation as thorough as it could have been? What feedback has been received from the requesting source? Did you discover any new problems? If so, what are they? Did you use new techniques during the case or during research? Task 2 Submission- Complete task 2 (15 points) Case is individual work Case 3 deadline is June 3 by 11:00 pm Cases Grade 20 20 20 20 20 100 Case 1 Case 2 Case 3 Case 4 Case 5 Total Rubrics Case 2 - Total 20 points 20.0 pts Excellent Submission- Word Document 1. Steps you have done with screenshots 2. Autopsy Report 3. In-depth explanation and analyze the USB drive data Download Autopsy Forensic Tool (Free download) http://sleuthkit.org/autopsy/ Task 1 10.0 pts Good Analyzing Your Digital Evidence using Autopsy Forensic Tool 0.0 pts Poor When you analyze digital evidence, your job is to recover the data. If users have deleted or overwritten files on a disk, the disk contains deleted files and file fragments in addition to existing files. Remember that as files are deleted, the space they occupied becomes free space-meaning it can be used for new files that are saved or files that expand as data is added to them. The files that were deleted are still on the disk until a new file is saved to the same physical location, overwriting the original file. In the meantime, those files can still be retrieved. Forensics tools such as Autopsy can retrieve deleted files for use as evidence. Task 1 1- Download Autopsy Forensic tool (It is a free tool to download, also available on computer labs) a. http://sleuthkit.org/autopsy/ b. Follow the steps in "Autopsy tool how to use" to complete the report and investigation (the .dd file is available on canvas) OR You can access to Autopsy Forensic Tool available on weblabs: https://weblabs.psu.edu/ Task 1 Submission-For every step make a screenshot and create a report for submission (5 points) Task 2 Discuss the following after Completing the Case in your report The files on George's USB drive indicate that he was conducting a side business on his company computer. Now that you have retrieved and analyzed the evidence, you need to find the answers to the following questions to write the final report: How did George's manager acquire the disk? Did George perform the work on a laptop, which is his own property? If so, did he conduct business transactions on his break or during his lunch hour? At what times of the day was George using the non-work-related files? How did you retrieve this information? Which company policies apply? Are there any other items that need to be considered? When you write your report, state what you did and what you found. The report you generated in Autopsy gives you an account of the steps you took. As part of your final report, depending on guidance from management or legal counsel, include the Autopsy report file to document your work. In any computing investigation, you should be able to repeat the steps you took and produce the same results. This capability is referred to as repeatable findings; without it, your work product has no value as evidence. Task 2 Discuss the following after Completing the Case in your report The files on George's USB drive indicate that he was conducting a side business on his company computer. Now that you have retrieved and analyzed the evidence, you need to find the answers to the following questions to write the final report: How did George's manager acquire the disk? Did George perform the work on a laptop, which is his own property? If so, did he conduct business transactions on his break or during his lunch hour? At what times of the day was George using the non-work-related files? How did you retrieve this information? Which company policies apply? Are there any other items that need to be considered? When you write your report, state what you did and what you found. The report you generated in Autopsy gives you an account of the steps you took. As part of your final report, depending on guidance from management or legal counsel, include the Autopsy report file to document your work. In any computing investigation, you should be able to repeat the steps you took and produce the same results. This capability is referred to as repeatable findings; without it, your work product has no value as evidence. Keep a written journal of everything you do. Your notes can be used in court, so be mindful of what you write or e-mail, even to a fellow investigator. Often these journals start out as handwritten notes, but you can transcribe them to electronic format periodically. Basic report writing involves answering the six Ws: who, what, when, where, why, and how. In addition to these basic facts, you must also explain computer and network processes. Typically, your reader is a senior personnel manager, a lawyer, or occasionally a judge who might have little computer knowledge. Identify your reader and write the report for that person. Provide explanations for processes and how systems and their components work. Your organization might have templates to use when writing reports. Depending on your organization's needs and requirements, your report must describe the findings from your analysis. The report generated by Autopsy lists your examination and data recovery findings. Other digital forensics tools generate a log file of all actions taken during your examination and analysis. Integrating a digital forensics log report from these other tools can enhance your final report. When describing the findings, consider writing your narrative first and then placing the log output at the end of the report, with references to it in the main narrative. In the Montgomery 72015 case, you want to show what evidence exists that George had his own business registering domain names and list the names of his clients and his income from this business. You also want to show letters he wrote to clients about their accounts. The time and date stamps on the files are during work hours, so you should include this information, too. Eventually, you hand the evidence file to your supervisor or to Steve, George's manager, who then decides on a course of action. Critiquing the Case in your report After you close the case and make your final report, you need to meet with your department or a group of fellow investigators and critique the case in an effort to improve your work. Ask yourself assessment questions such as the following: How could you improve your performance in the case? Did you expect the results you found? Did the case develop in ways you did not expect? Was the documentation as thorough as it could have been? What feedback has been received from the requesting source? Did you discover any new problems? If so, what are they? Did you use new techniques during the case or during research? Task 2 Submission- Complete task 2 (15 points)
Expert Answer:
Related Book For
Income Tax Fundamentals 2013
ISBN: 9781285586618
31st Edition
Authors: Gerald E. Whittenburg, Martha Altus Buller, Steven L Gill
Posted Date:
Students also viewed these algorithms questions
-
Python and most Python libraries are free to download or use, though many users use Python through a paid service. Paid services help IT organizations manage the risks associated with the use of...
-
Image transcription text Module 5 Discussion A' Instructions: This discussion will be completed in two parts, and will give you an opportunity to reect upon this week's content and to interact with...
-
The total sales (all credit) of a firm are 6,40,000. It has a gross profit margin of 15 per cent and a current ratio of 2.5. The firm's current liabilities are 96,000; inventories 48,000 and cash...
-
Listed below are heights (in.) of fathers and their first sons. The data are from a journal kept by Francis Galton. (See Data Set 5 "Family Heights" in Appendix B.) Use a 0.05 significance level to...
-
A piston/cylinder arrangement has a load on the piston so it maintains constant pressure. It contains 1 kg of steam at 500 kPa, 50% quality. Heat from a reservoir at 700C brings the steam to 600C....
-
Identify the key elements of effective project cost management.
-
Steve and Linda Hom live in Bartlesville, Oklahoma. Two years ago, they visited Thailand. Linda, a professional chef, was impressed with the cooking methods and the spices used in the Thai food....
-
As a result of the Great Depression,the U.S.government established many new regulations targeted at helping workers and consumers.One new piece of legislation was the minimum wage law,which sets a...
-
Discuss the issues on the forecasting system being used by a company. Recommend how to improve the forecasting method. Develop a forecast for each month of the next year and justify the forecast and...
-
Refer to Figure 20-13. What are the coordinates of Msat? Use the units of Aym for both values. Magnetization (X 106 A m-) 0 2.0 1.5 1.0 0.5 0 0 Magnetizing field H (X 104 A m-) 2 3 4 [100] [110]...
-
For show by the method described in this chapter that the following pairs of FAs are equivalent: FA b (1 FA b +
-
In the preparation of the 20X6 consolidated balance sheet, computer equipment will be a. Debited for $1,000. b. Debited for $15,000. c. Credited for $24,000. d. Debited for $40,000. On January 1,...
-
If 1 Canadian dollar can be exchanged for 90 cents of U.S. currency, what fraction should be used to compute the indirect quotation of the exchange rate expressed in Canadian dollars? a. 1.10/1 b....
-
An entity denominated a sale of goods in a currency other than its functional currency. The sale resulted in a receivable fixed in terms of the amount of foreign currency to be received. The exchange...
-
Fareast Group is a conglomerate with presence in various continents. Return on investment (ROI) has been the Group managers favorite tool used in measuring divisional performance. In the past two...
-
Privitera and Freeman (2012) constructed a scale to measure or estimate the daily fat intake of participants; the scale was called the estimated daily intake scale for fat (EDIS-F). To validate the...
-
Clifford Johnson has a limited partnership investment and a rental condominium. Clifford actively manages the rental condominium. During 2012, his share of the loss from the limited partnership was...
-
Sophie is a single taxpayer. For the first payroll period in October 2012, she is paid wages of $3,250 monthly. Sophie claims three allowances on her Form W-4. a. Use the percentage method to...
-
Bea Jones (age 32) moved from Texas to Florida in December 2011. She lives at 654 Ocean Way, Gulfport, FL 33707. Bea's Social Security number is 466-78-7359 and she is single. Her earnings and income...
-
Trust Management System: A university would like to develop a system for students to evaluate their peers performance in some group projects. Students ratings in various categories will affect a...
-
Building trust in potential students to join music classes by a music teacher a. Explain the above scenario. b. Draw a class diagram for it. c. Document a detailed and significant use case. d. Create...
-
Building trust in parents by hostel authorities to state that hostel is safe for students to live a. Explain the above scenario. b. Draw a class diagram for it. c. Document a detailed and significant...
Study smarter with the SolutionInn App