Assignment1


Objective: 

This assignment will allow you to demonstrate your skills in imaging, hashing, and report writing.

 

Deliverables:

Create a folder called "<first.name>.<last.name>. Save the following into that folder. When done, ZIP it.  Make sure you watch the Report Writing videos.

  1. Your report (template here)
    1. Make sure to answer all of the questions posed in the assignment at the end of your report.
  2. Your notes (template here)
  3. Your ~/.bash_history file from your Linux VM AFTER you write the report. 
    1. Not a screenshot. Not a picture. Not copy/pasted text. The actual file.
    2. Make sure to close all terminal windows and then re-open before copying the file.
    3. Note that this is a hidden file named .bash_history inside your user's home directory.
    4. If you're using something other than Mint or Ubuntu, like Kali, and cannot find this file, contact me and I will find an alternative file

 

Examples:

 

Procedure:

 

Download and read, thoroughly, the assignment description. Follow the instructions.  

 

Files:

  1. Assignment Description 
  2. Forensic Image (125MB compressed to 135 KB)

 

SHA1 Hashes:

 

Why did I include the hashes? Because we always need to verify the integrity of forensic evidence whether you create the forensic image yourself and compare that to the original media or if you are provided a forensic image as done here.  Your report and notes should show that you validated the provided image by showing the original and checked hash.