Digital Forensics Project: Evidence Analysis, Linux, and Steganography

Verified

Added on  2021/04/17

|30
|1914
|52
Practical Assignment
AI Summary
This digital forensics assignment encompasses several hands-on projects using tools like ProDiscover Basic and OSForensics to analyze digital evidence. The projects involve creating forensic images of USB drives, recovering deleted files, searching for keywords, and calculating hash values to ensure data integrity. The assignment also explores data acquisition using Linux live CDs and the dd command, demonstrating how to create bit-by-bit backups of storage media. Furthermore, the project delves into steganography, explaining how to hide information within other files. The student demonstrates the ability to perform investigations, generate reports, and understand key concepts in digital forensics such as evidence handling, data recovery, and the use of forensic tools. The assignment showcases the practical application of forensic techniques, including the importance of hashing and the identification of hidden data, making it a comprehensive exploration of digital forensics principles.
Document Page
Task 1:
Hands-On Project 1-1:
Step 1 - 3: Creating a new project in ProDiscover Basic with project name as C1Prj01,
project number, and a brief description about the project.
Step 4: Adding the image File to our C1Prj01 Project. This is done by expanding the Add
item in the Action Menu.
1 | P a g e
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
2 | P a g e
Document Page
Step 5: Selecting the C1Prj01.eve image to be added to C1Prj01.
Step 6: Viewing the contact of C1Prj01.eve by Expanding the Content View for the
C1Prj01.eve image.
Step 7: Viewing the Content of the Files in C1Prj01.eve image with associated programs.
3 | P a g e
Document Page
Step 8: Generating C1Prj01 Evidence Report
4 | P a g e
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
Report:
From the Tasks Carried out, an image of the USB Drive was backed up bit-by-bit and
analysed. Files where found that indicate an incidence of suicide due to tough financial times
as shown by suicide1.txt located in the C1Prj01.eve image. Deleted files were also visible
though our focus was on those whose deleted status is NO.
5 | P a g e
Document Page
Hands-On Project 1-2
Step 1: Creating a new project C1Prj02 with a project number and a brief description of what it is about.
Step 2: Adding the image File to our C1Prj02 Project. This is done by expanding the Add item in the
Action Menu.
6 | P a g e
Document Page
7 | P a g e
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
Step 3: Viewing the contact of C1Prj02.eve by Expanding the Content View for the C1Prj02.eve image.
Step 4: Searching for the keyword “book,” by clicking the Search Menu Button to open
the Search dialog box.
8 | P a g e
Document Page
Step 5: Viewing Cluster Search Results after the “Book” Search
9 | P a g e
Document Page
10 | P a g e
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
Hands-On Project 1-3
Step 1: Creating a new project C1Prj03 with a project number and a brief description of what it is about.
Step 2-3: Adding C1Prj03.dd, Navigating to Content and Sorting by “Deleted”
11 | P a g e
Document Page
12 | P a g e
chevron_up_icon
1 out of 30
circle_padding
hide_on_mobile
zoom_out_icon
[object Object]