Beruflich Dokumente
Kultur Dokumente
Run
14SEP/FR/JUN15/1
Module Title
SECURITY AND FORENSIC TOOLS
Module Leader
Lindsey Gillies
Module Coordinator
Module Tutors
Element Description
INDIVIDUAL WRITTEN REPORT ON A
FORENSIC CASE STUDY (Individual written
report on a forensic case study)
50%
Dates
Date Issued to Students:
23 Feb 2015
Submission Place
Submission Date
16/04/2015
Blackboard
Submission Time
2.00 pm
Deliverables
A detailed report, using the submission form found in Appendix A, which identifies
each evidential artefact, provides your contemporaneous analysis notes, and which
provides a written overview of the case scenario:
Case Scenario
The scenario for the assignment is as follows:
Suspects Name:
Main Victim:
Other people in the
case/potential victims:
Circumstances
Remit
Odlaw
Wally
Wizard, Wenda and Woof.
It is suspected that Odlaw has kidnapped Wally and is holding
him hostage for ransom.
Your task is to identify the location where Wally is being held.
Deliverable
A detailed report, using the submission form found in Appendix A, which identifies
each evidential artefact, provides your contemporaneous analysis notes, and which
provides a written overview of the case scenario:
1.
2.
3.
The report should identify each artefact you have found and its
provenance.
The report should detail, for each artefact, how you found it, in
sufficient detail for someone else to follow your process.
The contemporaneous notes should be sufficiently detailed to allow
an independent examiner to repeat your examination with the same
results. Factors you need to consider are:
50%
10%
20%
A complete examination
A logical, coherent examination.
Dual verification.
Repeatability
Appropriate choice and use of tools.
4.
20%
constructed upon the evidence you have found describing the case
scenario (ie. what you think has taken place, referring back to
individual evidence items). You should also identify the important
players in this scenario, together with any contact details for them.
Submission
You should submit a document file, readable in Microsoft Word or Adobe PDF, via
BlackBoard.
Appendix A: Template to be used in reporting upon your analysis of the Forensic Image
Student Number: XXXXX
Section A: Findings
The following evidence items were found:
Evidence item number
1
2
3
4
Method of discovery
Description of item
Significance to case
Etc
Exam
commenced
Other
relevant
information
Software used,
versions and
licensing
Action
Load case & verify in EnCase
Done?
Date
Time
Notes
Action
Recover lost folders (FAT16 & 32).
Mount archives; zip, thumbs.db, etc
File signature analysis, compute hash values
Log-on passwords
use SAMInside/Ophcrack
Done?
Date
Time
Notes
Action
IM clients
Encryption, Steg ,
Link files
Print artefacts
Additional Notes:
Done?
Date
Time
Notes