Principles of Digital Forensics

Added on - 28 May 2020

  • 22

    pages

  • 1932

    words

  • 11

    views

  • 0

    downloads

Showing pages 1 to 6 of 22 pages
PRINCIPLES OF DIGITALFORENSICS
Table of Contents1.Introduction.......................................................................................................................................22.Case.....................................................................................................................................................23.Analysis of Forensic Tools.................................................................................................................24.Investigation Procedure....................................................................................................................45.Findings..............................................................................................................................................86.Conclusion........................................................................................................................................187.References........................................................................................................................................191
1.IntroductionDigital forensics is used for investigating the digital devices like hard disk image, pen driveimage and computer memory dump. Investigation gives lot of useful results that can be used asevidences in the court of law. Analytical skills , Computer science knowledge, Good knowledgeabout the cyber security and cyber security laws of the land, Good management andorganizational skills, effective communication skills are needed for a good digital forensicofficer. A crime case study will be investigated in this report. The digital forensic tools that canbe used for investigating the hard disk will be studied. Suitable tools will be used for theinvestigation. Investigation results will be shared with evidences. Suitable conclusions will bemade based on the investigation results.2.CaseMiss Chew got murdered. Police arrested Kim and Kim confessed the crime and said thekilling assignment came from Liew. Kims computer seized and the hard disk images were sentfor forensic investigation. Lot of tools can be used for investigating the hard disk images.Specific tools are used in this case and results are obtained("7 Best Computer Forensics Tools",2018).3.Analysis of Forensic ToolsWith premise on analyzing disk images & breaking into suspicious or incriminating evidencesthat may have been deleted or hidden, Digital Forensics Tools are used for Viewing ImageContents in Windows. The case investigation will witness learning on the use of diverseadvanced disk analysis tools including Forensic Tool Kit (FTK) and ProDiscover Basic withpractical, real-life experiments. During the analysis process, the investigator will through thesetools be expected to search for information pertinent to the case being compiled. Forensic Toolkit is an AcessData program specifically for digitally based investigations. On the other hand,ProDiscover Basic is an advanced reporting tool and is a perfect option for generating reports2
and creating disk images. Unlike the FTK, ProDiscover is limited in the aspect of showing mostdeleted files or hidden partitions.The FTK free versions are a more reasonable option considering the robust version is moreexpensive. However, the more robust one allows for password recovery, encryption protectionand analysis of Windows and MAC OS.3
4.Investigation ProcedureThe Analyzing Disk Image File is done in Pro Discover Basic1. Open Pro Discover basic.2. At login screen in OS(Windows 8) utilize word.3. Dispatch Pro Discover basic software from work area. The screen will open requesting dataregarding another or existing undertaking. Meanwhile, this is another venture, and will round outdata for number name. At that point click the option named Open (Lynch & Duval, 2011).4
4. The new undertaking will then be opened. Now, nothing is there to examine since the ventureand is void.5.To include 'Georges Drive Image.001' to the undertaking for the purpose of examination,explore to 1.Action 2.Add 3.Image File.6.Open 'Y:\ Investigative Drive', and select the Georges Drive Image.001. At that pointclick Open. The drive has now been added to the venture. Tap on Pictures which wassettled underneath Content Opinion in left route menu. The circle picture is provided(Houck & Siegel, 2011).6. For taking a gander at the substance of Georges Drive Image, grow '+' image on one side ofImages until achieving C:. Substance of circle show up in correct side examination window. Youcan click into every envelope to see substance("Best computer forensic tools. Top forensic datarecovery apps", 2018).5
desklib-logo
You’re reading a preview
card-image

To View Complete Document

Become a Desklib Library Member.
Subscribe to our plans

Unlock This Document