Time: This activity should take you approximately 60 minutes to complete.
In this activity, we will use the GUI-based open-source forensic analysis tool, Autopsy, to analyze a Windows image. You may have downloaded and installed Windows Autopsy for Unit 4 activities.
Autopsy downloadAutopsy User GuideDownload and unzip the image, WinLabEnCase.E01 and validate both md5 and sha1hash values.
WinLabEnCase.E01 download (zip file) MD5 = dcd36624bdacf017bf8f913ea1340e8fSHA1 468b3a258133639cfa5dc06afba8887803074b87ACME Industry develops custom software for the aviation industry. Its main competitors are companies like Raytheon and Boeing, as well as a few smaller contractors.
Pat Smith has worked for ACME Industry for five years. Pat’s supervisor has noted that after being passed over several times for a promotion, Pat has become quite disgruntled. The company fears that Pat may be offering proprietary company information to a competitor in exchange for a job.
An EnCase image of Pat’s computer’s hard drive has been generated. Your job is to examine the image and extract all pertinent information to support or disprove the statement of Pat may be offering proprietary company information to a competitor in exchange for a job.
Note: Once you have created the case, you can reopen it at any time in Autopsy using "Open Existing Case," and choosing Desktop\Financial Case\ACME Case.aut.
If you are interested, you can also try other Autopsy features and examine other artifacts that are not covered in “Check Your Work”.
You can also try other features that Autopsy supports such as:
View Images/VideosTimelineTag and bookmark for reportingGenerate Report.You can examine many other artifacts for this exercise. For example:
Documents and Settings\psmith\Local Settings\History\History.IE5\index.datRecycledDocuments and Settings\psmith\ntuser.datWINDOWS\system32\spool\PRINTERS.Enjoy the fun of forensic investigation!
转载于:https://www.cnblogs.com/sec875/articles/10015752.html
相关资源:JAVA上百实例源码以及开源项目