Unit 7: Windows Forensics Analysis 7.3 Activity and Discussion Activity: Case Study

ACTIVITY: CASE STUDY

Time: This activity should take you approximately 60 minutes to complete.

SOFTWARE AND DOWNLOADS

In this activity, we will use the GUI-based open-source forensic analysis tool, Autopsy, to analyze a Windows image.  You may have downloaded and installed Windows Autopsy for Unit 4 activities.

Download and unzip the image, WinLabEnCase.E01 and validate both md5 and sha1hash values.

CASE SCENARIO

ACME Industry develops custom software for the aviation industry. Its main competitors are companies like Raytheon and Boeing, as well as a few smaller contractors.

Pat Smith has worked for ACME Industry for five years. Pat’s supervisor has noted that after being passed over several times for a promotion, Pat has become quite disgruntled. The company fears that Pat may be offering proprietary company information to a competitor in exchange for a job.

An EnCase image of Pat’s computer’s hard drive has been generated. Your job is to examine the image and extract all pertinent information to support or disprove the statement of Pat may be offering proprietary company information to a competitor in exchange for a job.

INSTRUCTIONS
  1. Launch Autopsy from the Toolbox folder on the desktop and follow the instruction below to create a case and add the given image into the case.
  2. Select > Create New Case
  3. Name the case as “ACME Case”.
  4. Use the default Base Directory (Desktop) to store the case data in Desktop\ACME Case\.
  5. Enter the Case Number as “1” and enter your name as “Examiner.”
  6. Click Finish. You will see the "Add Data Source" window.
  7. Select data source type: choose Disk Image or VM File; browse and select the path to "WinLabEnCase.E01".
  8. In our case, the computer image’s time zone is North American Eastern Time Zone. Select the time zone accordingly and click Next.
  9. In the Ingest (processing) modules window, leave all modules checked; click Next and then click Finish.
  10. Examine the files in Data Sources > WinLabEnCase.E01 and categorized data under Views and Results to identify pertinent evidence.
  11. Explore the image contents to answer the Check Your Work questions.

Note: Once you have created the case, you can reopen it at any time in Autopsy using "Open Existing Case," and choosing Desktop\Financial Case\ACME Case.aut.

If you are interested, you can also try other Autopsy features and examine other artifacts that are not covered in “Check Your Work”.

You can also try other features that Autopsy supports such as:

  • View Images/Videos
  • Timeline
  • Tag and bookmark for reporting
  • Generate Report.

You can examine many other artifacts for this exercise. For example:

  • Documents and Settings\psmith\Local Settings\History\History.IE5\index.dat
  • Recycled
  • Documents and Settings\psmith\ntuser.dat
  • WINDOWS\system32\spool\PRINTERS.

Enjoy the fun of forensic investigation!

转载于:https://www.cnblogs.com/sec875/articles/10015752.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值