Unit 7: Windows Forensics Analysis 7.3 Activity and Discussion Activity: Case Study

mac2022-06-30  26

ACTIVITY: CASE STUDY

Time: This activity should take you approximately 60 minutes to complete.

SOFTWARE AND DOWNLOADS

In this activity, we will use the GUI-based open-source forensic analysis tool, Autopsy, to analyze a Windows image.  You may have downloaded and installed Windows Autopsy for Unit 4 activities.

Autopsy downloadAutopsy User Guide

Download and unzip the image, WinLabEnCase.E01 and validate both md5 and sha1hash values.

WinLabEnCase.E01 download (zip file) MD5 = dcd36624bdacf017bf8f913ea1340e8fSHA1 468b3a258133639cfa5dc06afba8887803074b87

CASE SCENARIO

ACME Industry develops custom software for the aviation industry. Its main competitors are companies like Raytheon and Boeing, as well as a few smaller contractors.

Pat Smith has worked for ACME Industry for five years. Pat’s supervisor has noted that after being passed over several times for a promotion, Pat has become quite disgruntled. The company fears that Pat may be offering proprietary company information to a competitor in exchange for a job.

An EnCase image of Pat’s computer’s hard drive has been generated. Your job is to examine the image and extract all pertinent information to support or disprove the statement of Pat may be offering proprietary company information to a competitor in exchange for a job.

INSTRUCTIONS

Launch Autopsy from the Toolbox folder on the desktop and follow the instruction below to create a case and add the given image into the case.Select > Create New CaseName the case as “ACME Case”.Use the default Base Directory (Desktop) to store the case data in Desktop\ACME Case\.Enter the Case Number as “1” and enter your name as “Examiner.”Click Finish. You will see the "Add Data Source" window.Select data source type: choose Disk Image or VM File; browse and select the path to "WinLabEnCase.E01".In our case, the computer image’s time zone is North American Eastern Time Zone. Select the time zone accordingly and click Next.In the Ingest (processing) modules window, leave all modules checked; click Next and then click Finish.Examine the files in Data Sources > WinLabEnCase.E01 and categorized data under Views and Results to identify pertinent evidence.Explore the image contents to answer the Check Your Work questions.

Note: Once you have created the case, you can reopen it at any time in Autopsy using "Open Existing Case," and choosing Desktop\Financial Case\ACME Case.aut.

If you are interested, you can also try other Autopsy features and examine other artifacts that are not covered in “Check Your Work”.

You can also try other features that Autopsy supports such as:

View Images/VideosTimelineTag and bookmark for reportingGenerate Report.

You can examine many other artifacts for this exercise. For example:

Documents and Settings\psmith\Local Settings\History\History.IE5\index.datRecycledDocuments and Settings\psmith\ntuser.datWINDOWS\system32\spool\PRINTERS.

Enjoy the fun of forensic investigation!

转载于:https://www.cnblogs.com/sec875/articles/10015752.html

相关资源:JAVA上百实例源码以及开源项目
最新回复(0)