Setting Up
|
|
Installing Mint |
Overview of Forensic Science
|
|
Overview |
|
|
|
Legal Aspects of Digital Forensics
- Civil and Criminal Procedure
- Courtroom Testimony
- Intellectual Property
- Laws
- Legal Compliance
|
|
Procedure
|
|
|
|
Report Writing
- Guest lecturer Professor Pollitt, FBI (retired), will describe the report writing process from a law enforcement viewpoint.
|
|
Report Writing
|
Seizing and Imaging
- In these three lectures I discuss important concepts related to seizing digital evidence, creating a forensic copy of the evidence, and verifying that you made an accurate copy. The associated labs involves creating a forensic copy of a flash drive using Linux.
|
|
Seizing and Imaging |
Project 1: Demonstrate an Understanding of Forensic Imaging and Verification
|
|
|
Hierarchy of Access
- Media can be accessed at varying levels, from the purely physical to the logical. The concept of hierarchy of access is explained.
|
|
Hierarchy
|
File Systems
-
In order to understand digital forensics first and foremost you must understand file systems. A file system is the organizational structure by which files are organized on a disk. There are dozens of different file systems, but will start with the simplest, the FAT file system.
|
|
File Systems
|
|
|
|
Physical Analysis
-
Physical analysis looks at the contents of the media from a raw perspective. So instead of viewing files in allocated space (logically), we can also view system space (e.g., root directory, FAT, Master File Table, etc.), and also recover unallocated and slack space.
|
|
Physical Analysis
|
|
|
|
Project 2: Demonstrate an Understanding of the FAT File System and File Recovery
|
|
|
Forensic Tool Validation
|
|
Validation
|
Drives and Partitions
- In this section we discuss drives and their geometry, and physical characteristics
|
|
Drives |
Date and Time Stamps
- Every file has multiple date and time stamps. These can be useful in a forensic examination.
|
|
Date / Time Stamps |
Forensic Tool Kit
|
|
|
FTK Imager
- FTK Imager is a small Windows-based utility that can fit on a USB that allows a forensic examiner to create a forensic image and conduct a basic preview of evidence. It's absolutely free to download and use so it might be something to include in your own toolkit. While our version of FTK 6.1 requires a VPN, FTK Imager does not (thus, why you can put it on a USB stick!).
|
|
FTK Imager |
Setting up VPN Access
- In order to run FTK you will need to setup VPN access to the FTK dongle which resides on a server at DSC.
|
|
VPN Access |
Installing and Configuring FTK
- FTK is a full-fledged commercial digital forensics application. You will use FTK for the remaining two assignments.
|
|
Install FTK |
Overview of the FTK Interface
- FTK is complicated so we'll need to review the interface and its capabilities in multiple videos. In this video walkthrough I cover the Explore, Overview, and Email tabs/functionality.
|
|
Explore, Overview, Email |
Graphics, Video, Internet, Bookmarks, and Filters
- In this video walkthrough I cover the Graphics, Video, Internet, Bookmarks, and Filters capabilities.
|
|
Graphics, Internet, Bookmarks, Filters |
Manual Carving and Indexed Search
- In this video lecture I cover how to add new evidence to your case, how to use manual carving to recover deleted files from unallocated space, and how to use the powerful indexed search to identify keywords in your case.
|
|
Carving and Indexed Search |
Creating a Report
- The purpose of a forensic examination is to identify evidence, or lack thereof, and produce a forensic report. In this video lecture I discuss how to add new evidence and bookmarks to case, and how to create a report in multiple formats.
|
|
Creating a report |
Project 3: The Forensic Tool Kit (FTK)
|
|
|
Password Recovery Toolkit
- Password Recovery Toolkit (PRTK) is an add-on product to FTK that allows an examiner to breaker all different types of passwords.
|
|
PRTK |
Registry Toolkit |
|
|
Windows Registry Analysis
- The Windows registry is a hierarchical database that stores configuration settings and options on Microsoft Windows operating systems. It contains settings for low-level operating system components and for applications. As such it contain a wealth of information regarding applications installed and used, last files opened, devices mounted, etc.
|
|
Windows Registry
|
|
|
|
Project 4: Password Recovery Tool Kit (PRTK)
|
Comments (0)
You don't have permission to comment on this page.