Digital Forensics and Practices

Verified

Added on  2023/06/07

|34
|4777
|156
AI Summary
This project aims to recover an authorized image of a USB data storage device and investigate the evidence related to a case of sexual assault. The article discusses the tools used for analysis, the hearsay rule, and the witnesses' statements. The subject is digital forensics and practices, and the course code, name, and college/university are not mentioned.

Contribute Materials

Your contribution can guide someone’s learning journey. Share your documents today.
Document Page
Digital Forensics and Practices

Secure Best Marks with AI Grader

Need help grading? Try our AI Grader for instant feedback on your assignments.
Document Page
Table of Contents
1 Introduction.......................................................................................................................2
1.1 Project Objective in light of Evidences....................................................................2
1.2 Actualities...................................................................................................................2
1.3 Issues...........................................................................................................................2
1.4 Presumptions..............................................................................................................3
1.5 Tolerability and Witnesses........................................................................................3
2 Analysis Tool.....................................................................................................................3
3 Evidence.............................................................................................................................4
3.1 Hearsay (HS)..............................................................................................................4
4 Investigation......................................................................................................................7
4.1 Creating a case file using Autopsy tool....................................................................7
4.2 Initial Survey............................................................................................................12
4.3 Documentation Phase..............................................................................................19
4.4 Search for evidence..................................................................................................25
5 Witnesses Report.............................................................................................................30
6 References........................................................................................................................31
1
Document Page
1 Introduction
The principle target of this project is to recover an authorised picture of the USB
information storing device. Farayi is associated with offering fake International Student
Identity Cards to individuals who are not qualified for assert the rebates this card brings. A
covert sting activity was setup to get Farayi in the demonstration of offering his fake
merchandise. Farayi endeavored to offer a fake ISIC card to a covert officer who was a piece
of the sting task. Subsequent to being captured and addressed at the neighbourhood police
headquarters, Farayi gave a USB information stick to be additionally analysed. Under
addressing Farayi has expressed that all the confirmation that can be found is on this USB
information stick. This USB stockpiling gadget has been prepared by a measurable imaging
specialist and the criminological picture has been gotten. So I need to recuperate the
criminological picture of the USB information stockpiling gadget. At that point the replicated
Data in USB will be resolved. The examination will be completed to verify that the concealed
information in USB, the reasons and actualities behind the burglary.
1.1 Project Objective in light of Evidences
The update addresses the potential issues of agreeableness of the affirmations nearby
the competency of witnesses. It moreover studies the verification's quality and the
methodology which could be considered with the response of the charges (Advances in
Digital Forensics 9, 2016).
1.2 Actualities
The pointed the finger at (Lauris Gulbis) is rebuked for attempting sexually pestered
assault on his significant other (Agar Gulbis).
Agar has scarves of devours on her chests, using a lit light.
There are various affirmations to show that the charged, Lauris has made all the harm
Agar.
There are moreover observes who support Agar.
The sentiments had not been uncovered to the Law Society of Scotland.
1.3 Issues
The vital choice communicates that a mate could be charged for attacking their
spouses, despite when the couple live separately.
The companion who is condemned the assault can be put into criminal fundamental.
2
Document Page
1.4 Presumptions
According to the Scotland Act of 2009, sexual offenses are enhanced by the Scots
law, which helps with the consent and gives assertion that from the setback physical
resistance isn't required, for the offense to be given.
Lauris can be condemned as an attack censured.
Henceforth, as shown by this Act, Agar could have protested right in 2015 and the
issue could have not extended using any and all means (Altheide and Carvey, 2011).
1.5 Tolerability and Witnesses
The witnesses are recorded underneath:
Sergeant Elspeth Sawyer, Police Scotland Domestic Violence Unit, Glasgow
Mary Moran
Ronnie Atkins
Darren McPhee, proprietor of "Darren's Dodgems
Mrs Inese Rubenis (Agar's Mother)
Under Criminal Justice (Scotland) Act 2016, the going with will be recorded:
Arresting time and place.
Nature of the offense.
Arresting reason
By whom the individual was educated concerning rights
Name
Date of Birth
Place of Birth
Nationality
Person's Address
Reply by the Arrested Person.
Time and place of the place transported to.
In guardianship Authorisation from Criminal Justice (Scotland) Act 2016, Lauris at first is
'Not Officially Accused' and will be sent for a game plan of tests, in light of the uncertainty.
2 Analysis Tool
The use of analysis contains a couple of major tools for retrieving the forensic image of the
USB data storage device.
3

Secure Best Marks with AI Grader

Need help grading? Try our AI Grader for instant feedback on your assignments.
Document Page
1) Autopsy
2) Win hex
3) WinMD5
3 Evidence
3.1 Hearsay (HS)
HS control: The confirmation of protest is reasonable good as shown by s 66 for the
Evidence Act. Since, for the affirmation of the charged or the assault complainant. It is an
exceptional verification for the HS run the show. Exactly when the dissent is, new in the
memory, it is adequate. In perspective of the Evidence Act, the High Court considered the
'new' hours and days as opposed to numerous months (Graham v The Queen at 608 [4]). The
challenges that are obvious aren't allowable until the point that the moment that it has some
restored complainant's legitimacy as per s 108(3). Kara Shead, 'Responding To Historical
Child Sexual Abuse: A Prosecution Perspective on Current Challenges and Future Directions'
(2014) 26 Current Issues in Criminal Justice (Gogolin et al., 2013).
On twentieth March 2018, the reports gave from the Psychiatrist, Diana Donaldson,
MD, ChB, PhD, FRCPsych, suggest that an expert ace has broke down Mrs Agra Gulbis. The
counsel communicates that there are unprecedented post-upsetting constraining issues that are
making Agar dependably try to suicide. Mrs Gulbis was admitted to Gartnavel Royal
Hospital as a mental patient on 26th February 2018, from Gartnavel General Hospital. Her
mental flourishing decayed completely on 25th February after a visit by her near to
neighbour. As shown by the examination of Agar today, the court is represented about her
current condition and it is to an awesome degree possible that this will perilously
manufacture her absurd inclinations, paying little regard to whether she needs to give exhibit
with the upside of uncommon measures. Likewise, Mrs Agar Gulbis is a patient in the
specialist's office named as, Gartnavel Royal, under the Mental Health (Care and Treatment)
strategies in light of the (Scotland) Act 2003 (Pollitt and Shenoi, 2010).
As indicated by 25th February 2018, the announcement of Dr Edna Evans, MD, ChB,
FRCP, the Consultant Physician of Agar from the recuperating office, Gartnavel General
Hospital Glasgow, communicates that, on twentieth February 2018 at 9.00am Agra Gulbis is
insisted to have had intercourse in the past 12 hours, in light of the way that the semen
insights of her loved one were found in her vagina. This exhibits Lauris is a reprimanded. On
the other hand there were wounds on the lower arms and shoulders of Agar Gulbis. These
4
Document Page
injuries are caused in light of compelled sexual undertaking. Also, Agar's left 50% of the
head was injured, due to being dependably struck as far as possible instrument. In fact, even
devour scars to one side chest is found, which is around 2 inches square. This harm might be
caused some place in the scope of two and a long time from now, with an inquiry like a lit
light. The harm doesn't seem, by all accounts, to be accidental (Ray and Shenoi, 2011).
The assertion of Pat Boyd, BSc, PhD, Police Scotland Forensic Scientist's give insights
with respect to 28th February 2018 show the results against Lauris. For example the DNA
test, fingerprints, hair segments and the blood developments found on the bronze table light.
Mary Moran's presentation express that she despised Friday evening times in context of
Lauris' yelling, which she could hear through the divider between the two rooms. She didn't
get much lay on any Friday night till it was 3.00 am of Saturday. In any case, things went to a
true blue head on the nineteenth of February – that was a Friday. She couldn't discover the
chance to rest. There was yelling and unrest from the moment Lauris entered home from the
bar. Eventually, Mary heard Lauris say that, when considered ot her secretary, Agar isn't
extraordinary and he sounded more scornful than furious and it was notwithstanding
annoying. I enquired about Agar through telephone, anyway she found no response. Just after
15 minutes she got a call from Agar, which was to an extraordinary degree hard to hear. In
any case, Mary appreciated that Lauris was snoozing and it was all awesome by and by, yet
in the meantime Agar was crying furiously and she was startled and said "To be sure,
thankful". She by then collected her boldness to go round to Agra's home to see she was
alright and discovered the police there (Sammons, 2015).
From Mary's help the police got various letters from a little agency. Among a couple
of letters, there was a letter from Lauris to Agar, which communicated, "The more I hit you,
the more you see sense. It's a turn on, as well". The cop swung the letter to Lauris and asked,
its significance, to which Lauris answered, "Exactly what it says". This shows Lauris agrees
that he tormented Agar. By then, the light was found, which the affirmation for Agar’s scars
was.
The statement of Sergeant Elspeth Sawyer, Police Scotland Domestic Violence Unit,
Glasgow express that he had connected with Agra Gulbis, in the mid-year of 2015, when
Agar Gulbis went to the police home office whining that the upbraided had persuasively
evacuated her bits of dress to get to her chest and she had then been singed there with a light.
Agar didn't offer chance to see her chest and declined to finish any examination by the police
ace, in light of the way that the criticized was his better half. She in like way declined to help
any charges against his significant other saying something like, "I can't. She additionally
5
Document Page
verified not to have any pals or family who could enable her and help her. Agar was
recognized to have each one of the indications of a battered lady: old wounds about her body;
dull glasses more likely than not covering an injured eye. She was just 5 feet tall, and
unequipped of managing her conditions. The officer couldn't do anything, as she was not
supporting the cops. So the centers noted at from Agar's declaration were demolished after a
few months, when she didn't turn up.
Again on twentieth February 2018, the cop were educated about the event in Agra
Gulbis' home, where she was found hurt. The criticized Lauris was flushed and sat on a seat.
As demonstrated by the presentation of Constable Hobbins, Lauris was rebuked for s 48 for
the new Criminal Justice (Scotland) Act 2016 (the 2016 Act), for having a barbecue stamping
iron in his pocket of the criticized coat. Further, Lauris communicated that, "I have to control
the bitch, don't I?", he said. By at that point, consequent to ending for a moment and a laugh
he communicated, "What do you think, you fat bitch. He declined to answer to any request
from the cop. In perspective of s 32 (4) and (5) of the 2016 Act he was tended to. He pointed
the finger at Agar for assaulting him and to shield himself he hurt Agar. Lauris in like manner
communicated that he has got his name on the flame broil bar and Agar once in a while seize
the opportunity to get scorched, in places which are not clear to the overall public. He bladed
her that, she isn't the little irreproachable. In this manner, he had expended her every so often
and show her who the director is. Lauris doesn't find anything inaccurately in this.
The affirmation of Mrs Inese Rubenis shows that her young lady was not perky in her
marriage, as she saw her daughter Agar being bleak straightforwardly in the wake of
delivering Bo.
According to the presentation of Darren McPhee, proprietor of "Darren's Dodgems"
He hypothesized that there were kids who were messing close and attempting to hamper
speed limiters on the cars. He didn't know why they weren't in school. Agra Gulbis was there
with her daughter and were getting an accuse out of one another. Unexpectedly, one of the
raucous children ran direct into Agra's auto. The auto was going so rapidly that it got out the
floor and wound up half over Agra's auto. The edge of the windscreen had hit Agra fittingly
on the left half of her face and when Darren discovered her she was wedged in, and
attempting to promise herself and her daughter. The children fled and I was to an
extraordinary degree stressed, regardless of how it wasn't my blame. Darren took Agra and
the little young lady into my band and gave them tea and juice. Her head wasn't exhausting
yet she was decently stupified. Darren could see she was better so he gave her a pack of
cemented peas to put on it. She said that she didn't have to see a specialist. She was hurt in
6

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
her shoulder. Agar was not prepared to move her best down or anything. She was somewhat
humiliated and I might not have any desire to drive it. Things were enough horrendous. Later
she felt much better soon. Darren gave her and the little one a lift home after around a hour to
loosen up and was chipper that she might not have any desire to take it any further,
notwithstanding how it wasn't my blame.
Nevertheless, the key inspiration driving is sentence the faulted with criminal primers
and exhibit him culpable in the court. Each one of the confirmations are against Lauris and
Even the declaration of Agar after the last event is cross checked and evaluated, to repel the
criminal. Furthermore, the affirmations against Lauris are non-exculpatory.
The Scotland law has change its scot law for supporting the sexual offenses against
women.
4 Investigating Stage
The data recovery may be useful to examine in an extensive variety of ways. The
couple of Data stay present even after the Data eradication or USB repartitioning (Gogolin et
al., 2013). Likewise, there exists various options for guilty parties with particular know how
to cover Data, generally using a USB boss, stenography, and encryption et cetera. Finding,
recovery and revamping of hid Data can be a greatly dull and dismal process, anyway now
and then it may make demonstrate that will part the case. In order to totally perceive how and
why Data remain on a plate, one should get some answers concerning securing Data in the
USB. The USB port is the unit of settled size described when record system is made (for the
most part 512 bits). More prepared hard USBs might contain certain 'wasted' storage space
ostensibly tracks, as astutely each track is parcelled into equal the initial investment with
number of divisions. It is possible now and then to cover Data in the space between the
regions on the greater outside tracks. It is called as division opening. A couple of Data
recovery organizations may have the ability to discover and recoup Data that is concealed in
this opening. Eradicated records and slack space. When the working system makes report to
the USB, it administers particular number of portions. Amount of regions assigned depends
on confinements of the working system along with the setup decisions taken by the structure
supervisor. Zones apportioned and the region on the plate will be recorded in a table of
registry, to access it later on. Right when a record is deleted, the space at first administered to
it is basically separated as unallocated. The honest to goodness Data remains in the USB
drive (Larson, 2014).
7
Document Page
4.1 Use of Autopsy tool to Create Case file
Case Information are shown below.
Information for I:\bottle usb dd\bodd:
Physical Evidentiary Item (Source) Information:
[Device Info]
Source Type: Physical
[Drive Geometry]
Cylinders: 249
Tracks per Cylinder: 255
Sectors per Track: 63
Bytes per Sector: 512
Sector Count: 4,014,080
[Physical Drive Information]
Drive Model: General UDisk USB Device
Drive Serial Number:
Drive Interface Type: USB
Removable drive: True
Source data size: 1960 MB
Sector count: 4014080
[Computed Hashes]
MD5 checksum: b6df6dd242d94182f9fa4b1afc508a26
SHA1 checksum: db3da51e7795a00faf6f82e4e5098487c755b667
Image Information:
Acquisition started: Thu Feb 16 09:40:33 2017
Acquisition finished: Thu Feb 16 09:42:29 2017
Segment list:
I:\bottle usb dd\bodd.001
I:\bottle usb dd\bodd.002
Image Verification Results:
Verification started: Thu Feb 16 09:42:31 2017
Verification finished: Thu Feb 16 09:42:38 2017
MD5 checksum: b6df6dd242d94182f9fa4b1afc508a26 : verified
8
Document Page
SHA1 checksum: db3da51e7795a00faf6f82e4e5098487c755b667 : verified
Client must require the case record for opening the given DD picture document. The
beneath provided screen captures and demonstrates new case manifestations. To begin with,
type case name i.e., DMU-CSC066 and program the base catalog. At that point, press on
Next catch for entering the discretionary data.
Then, choose the information sources for including the information hotspots for the made
case record. Along these lines, select the unallocated space picture record and tap the
following catch to continue the including the information sources. It is demonstrated as
follows (Pollitt and Shenoi, 2010).
9

Secure Best Marks with AI Grader

Need help grading? Try our AI Grader for instant feedback on your assignments.
Document Page
For selecting the DD image file, the data source path must be browsed as illustrated below.
Next, the DD image file is configured for ingesting the modules. Then, press Next button as
illustrated below.
10
Document Page
At last, the data sources are added and the Autopsy tool will analyze the DD image file, then
press Ok option.
The below illustrated figure is utilized for displaying the successfully analysed DD image
file.
11
Document Page
Be that as it may, the DD picture record does not have the MD5 hash number. Along these
lines, it needs to recognize by utilizing the WinMD5 device. To start with, client needs to
download the introduce the WinMD5 device. After, open the apparatus. At that point, peruse
the DD picture document. This procedure is demonstrated as follows.
Further, the WinMS5 tool gives the values of MD5 hash to the given DD image file, as
illustrated below.
12

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
4.2 First Survey
In this section, the underlying overview of the proof will be we will played out. Firstly,
the client is required to make the catchphrases keyword for finding the pertinent advanced
confirmation on the DD picture document. The keyword of the watchwords are demonstrated
as follows (Ray and Shenoi, 2011).
13
Document Page
On Autopsy Creating the Keyword List
Click the keyword list for creating the keyword list and then select Manage lists as
illustrated below, which will represent the below information.
Here, the new list is clicked for entering the keywords list, which is exposed in the following
image.
14
Document Page
After entering the new keyword, even type the new watchwords for entering the defence of
made catchphrase list. Then, pick the substring match and press, Ok option.
15

Secure Best Marks with AI Grader

Need help grading? Try our AI Grader for instant feedback on your assignments.
Document Page
At last, the keywords list is created successfully with keywords justification as illustrated
below.
At that point, look through the data on picture records by utilizing the watchword list. Here,
the ISIC on watchword seek will be looked, which will be represent in the ISIC related data.
16
Document Page
Next, the ingest modules must be run by tapping on the device. Then, as illustrated below
pick the run ingest modules.
On Keyword look, for running the ingest modules, choose the design ingest modules as
catchphrase inquiry and then snap Finish for running the ingest modules, as illustrated below.
17
Document Page
Then look for the DD pictures data with the help of catchphrase look such as, Unallocated.
This step is illustrated in the below figure, which represents the accompanying data.
Here, the DD picture document data will be used. Pick the information sources. It is
demonstrated as follows.
Next, right click on the information sources and then select, Properties. This will show the
data related to the information sources.
18

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
The initial survey’s last stage refers to identifying each of the relevant files whether
connected with the investigation or not. This step is illustrated in the below figure.
19
Document Page
4.3 The Phase of Documentation
In this section, right documentation is guaranteed which is either stored or utilized.
Along these lines, check the right record identified with word reports and pictures. The
provided picture contains 3 three word archives, where the initial word document record
comprises of 20480 records and 15 is the Internal ID, which is demonstrated as follows.
20
Document Page
58368 file is the size of the second word document and 20 denotes the internal ID, as
represented below.
21

Secure Best Marks with AI Grader

Need help grading? Try our AI Grader for instant feedback on your assignments.
Document Page
At most 11477 files are present in the third word document and 9 refers to the internal ID, as
illustrated below.
22
Document Page
The given DD image file contains 6 images, which are analysed in the below figure.
23
Document Page
24

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
25
Document Page
4.4 Evidence Searching
In this section, we decrypt and then identify the important advanced proof. In this way, take a
gander at console list results. It is demonstrated as follows.
26
Document Page
Tap the ISIC pictures record is demonstrates the accompanying picture (Sammons, 2015).
This scan is utilized to appear to be totally important to an examination concerning fake ISIC
cards. Next, we will include the bookmark. For including the bookmark, right click on the
outcomes and further choose the label records for tapping the book check.
27

Secure Best Marks with AI Grader

Need help grading? Try our AI Grader for instant feedback on your assignments.
Document Page
Likewise, the counterfeit ISIC cards must be examined as illustrated below.
With the help of keyword search, search the ISIC counterfeit cards, as illustrated below.
28
Document Page
Open in the external viewer, so as to open the image files.
This step is illustrated in the below figure.
29
Document Page
Next, again check the file to generate new keyword list, as it is beneficial in the digital
investigation. The below figure illustrates the creation of keyword list.
This keyword list is presented in the below figure.
30

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
Later, on the keyword search identify a keyword such as sheetal, which denotes a customer.
This step is illustrated in the below figure.
At last, each proof is placed in the USB drive and researched documents are replicated or
transferred into the USB drive via, PC. Along these lines, this PC needs to explore and it
31
Document Page
might uncover the bunches of more valuable proof. It is utilized to give the capacity to
reproduce the exercises that made these records exist.
5 Witnesses Report
There is a strong confirmation against Lauris, which is particular and there is most
likely that the introduced witnesses have expressed any false proclamation. The witnesses
have expressed reality and they have no conceivable advantage, to tell a lie. To help the
announcement of alternate witnesses, the announcement of Sergeant Elspeth Sawyer, Police
Scotland Domestic Violence Unit, from Glasgow, assumes a noticeable part. Notwithstanding
the way that, a portion of the witnesses like the mother of Agar, Mrs Inese Rubenis and
Ronnie Atkins have issue to talk English, yet this won't bar them– if vital, a go between may
be dispensed to help with correspondence. The witness Ronnie Atkins is excessively youthful
and at the season of episode shew was excessively youthful. Indeed, even this won't hurt the
announcement of the witness.
Lauris is held liable from his own particular letter which was found by the police from
the Gulbis' home, which expresses, "The more I hit you, the more you see sense. It's a turn
on, as well". There are more possibilities that, Lauris is held liable. Notwithstanding whether
it was consensual for a couple to do as they wish for fulfilling their sexual needs. The
announcement given by Mary Moran bolsters Agar and not Lauris. Subsequently, the
consensual needs to fulfill their requirements can be disposed of.
In any case, Agar has denied that, the sex between them was not consensual and therefore it
will be considered as Rape as indicated by the Scotland law Act 2009.
32
Document Page
6 References
Advances in Digital Forensics 9. (2016). Springer-Verlag New York Inc.
Altheide, C. and Carvey, H. (2011). Digital Forensics with Open Source Tools. [s.l.]:
Elsevier professional.
Goel, S. (2010). Digital forensics and cyber crime. Berlin: Springer.
Gogolin, G., Ciaramitaro, B., Emerick, G., Otting, J. and Pavlov, V. (2013). Digital forensics
explained. Boca Raton: CRC Press, Taylor & Francis Group.
Gogolin, G., Ciaramitaro, B., Emerick, G., Otting, J. and Pavlov, V. (2013). Digital forensics
explained. Boca Raton: CRC Press, Taylor & Francis Group.
Larson, S. (2014). The Basics of Digital Forensics: The Primer for Getting Started in Digital
Forensics. Journal of Digital Forensics, Security and Law.
Pollitt, M. and Shenoi, S. (2010). Advances in digital forensics. New York:
Springer/International Federation for Information Processing.
Pollitt, M. and Shenoi, S. (2010). Advances in digital forensics. New York:
Springer/International Federation for Information Processing.
Ray, I. and Shenoi, S. (2011). Advances in digital forensics IV. New York: Springer.
Ray, I. and Shenoi, S. (2011). Advances in digital forensics IV. New York: Springer.
Sammons, J. (2015). The basics of digital forensics. Amsterdam: Syngress Media.
Sammons, J. (2015). The basics of digital forensics. Amsterdam: Syngress Media.
33
1 out of 34
circle_padding
hide_on_mobile
zoom_out_icon
[object Object]

Your All-in-One AI-Powered Toolkit for Academic Success.

Available 24*7 on WhatsApp / Email

[object Object]