Question Description
EnCase Investigations Transcript
Screen 1
Dominic Santini is the CEO of the ZeroBit Corporation. He has received a call claiming that proprietary information about a ZeroBit product has surfaced in a competitor's sales brochure. He suspects a leak and wants to meet with you to discuss a possible investigation.
Screen 2
Mr. Santini welcomes you to his office, saying:
"Thanks for stoppin' by at such short notice. Have a seat. Lemme tell ya more about what's been goin' on. One of our marketing managers came back from a convention last week with a brochure for a competitor's product having the exact same specs as our product. No way that's coincidence! So, do you know our guy Peterson? I have a feeling he might be the one who's been talking to those other guys, maybe saying some things he shouldn't be saying."
Screen 3
"There's been a lot of absenteeism in Peterson's department lately—from the boss on down. When employees in the department do show up, they stay late into the evening. Now I'm not ready to launch a full-blown offensive here, but I think it'd be worth our time to check into what our friend Peterson has been doin' in his free time!"
Screen 4
"If we go to court, our success will depend on the proper handling of people, property, and evidence, so give me a safety and investigation plan first. By the time we wrap this thing up, I'll need a report to share with the Board. Gimme plenty of detail—what you found out and exactly how and where you found it."
Santini makes it clear that you are more or less on your own with this case. It's a sensitive investigation that will require maximum discretion!
Prior to conducting any investigation, participants must take certain steps to ensure the safety of the operating environment. Safety considerations fall into three general categories: people, property and environment, and evidence handling. They can range from weather-related issues to verbal or physical threats from the subjects under investigation. Investigations may occur off hours or at night, which raises the possibility that the investigator might be mistaken for a criminal. A forensic investigator constructs a safety and investigation plan specific to each investigation, and this plan will address all foreseeable situations that could jeopardize the investigation or its participants.
Once a safety and investigation plan has been developed, the investigation can begin. This project will focus on Guidance Software's EnCase. EnCase is the most widely used commercial digital forensic tool available today. It is an integrated tool used in many types of computer and server investigations. EnCase is extensible with advanced scripting capability and a growing number of third-party modules. It is critical for today's digital forensic investigators to be familiar with its processing and analytic capabilities. This project will utilize EnCase in a typical investigation scenario in which it generates forensic examination reports from a few different situations. (As you proceed through this course, you will encounter references to a wide variety of digital forensics tools—far beyond Encase. We have provided a list of these tools to help you access them when you need them.)
The final assignment in this project will include a safety and investigation plan, as well as reports that employ the EnCase report template (PDF format). to answer the questions noted in the steps. The bookmark and report features of EnCase are emphasized. The result will be reports that include case overviews and explanations of the processing and analysis experience.
Mr. Santini's first request was for a safety plan. Are you ready to get started?
Step 1: Explain Cryptography Basics
It is important to lay a foundation for the work that the temp IT workers in the scenario are expected to do. The building blocks of the foundation should be a familiarity with the processes of encryption and decryption, and the meaning of keys. You will need to explain the differences between asymmetric and symmetric key cryptography and the significance of public key infrastructure. It is also important to include a description of encrypted data in terms of randomness and entropy.
"Basic Cryptography" will be the first section of your job aid. It should include two parts:
- A description of the basic elements of cryptography including the following:
- the roles of encryption and decryption in public and private keys
- the differences between asymmetric and symmetric key cryptography
- public key infrastructure
- the nature of encrypted data regarding randomness and entropy
- An explanation of the possible significance of this information for the agency; that is, how does an examiner know whether encrypted data is present? What are the examiner's options for dealing with encrypted data?
Prepare a 2-page document organized in bulleted form (APA format). Refer to in-class readings and outside resources for your content. Remember that your audience is composed of temp workers or new hires—that is, nonexperts. Review your summary carefully for accuracy and completeness. You will include it in the job aid to be delivered in Step 6.
In the next step, you turn to the question of whether the suspect's disks and file systems have been encrypted by demonstrating an analysis of partitions.
Step 2: Examine Evidence Partitions
Demonstration and hands-on training are always most effective, so you turn to the former in Step 2. Digital forensic investigators need to understand how to examine evidence partitions. In a case that you are working on currently, the suspect's computer contains four disk partitions. A disk partition is a portion of a whole disk with its ownfile system. Access the virtual lab to examine evidence partitions in order to determine whether files on each partition are encrypted, defragmented, securely deleted, or none of these. If they have been encrypted, what process was used: NTFS encrypted file systems, BitLocker, PGP, etc.?
After conducting your analysis, you demonstrate how you would document your findings in a formal forensic report. Include descriptions of destruction strategiessuch as wiping, overwriting, corruption, and degaussing. Make sure these strategies are explained in terms that IT temps, recent hires, and other nonexperts can understand in a consistent way. This will be the first section of your investigative report.
Share this section of the report with a colleague (your instructor) for review and feedback before continuing to the next step, where you will search for hidden data in files. Make sure to incorporate any suggested changes. This will be the first section of the sample investigative report to be included in the job aid submitted in the final step.
Step 3: Search for Hidden Data
In the previous step, you demonstrated the examination of partitions for encryption, compression, and wiping. In this step you access the virtual lab to show trainees how to search for hidden data in .jpg files. As you prepare to demonstrate the process, you remind them that the tools you are using are only some examples of the many steganography, forensic tools, and anti-forensic tools that can be used. Multiple tools exist to address any problem, and learning how to select and use the appropriate ones is a valuable skill.
After demonstrating the search, you show trainees how to describe findings as you would in a formal forensic report, making sure the findings are in terms that nonexperts can understand. Take special care to indicate the nature of the data, how you found it (including the tools used), and where it is hidden.
Review your document carefully for accuracy and completeness. It is the second section of your sample investigative report. You will include it in the job aid to be delivered at the end of this project.
Next, you will show trainees how to search for suspicious software on a suspect's computer.
Step 4: Identify Suspicious Software
In the previous step, you showed trainees some tools and techniques for finding hidden data. In this step you access the virtual lab to demonstrate how to find and identify malware on a computer. Your team has extracted three processes from a memory image. It is unclear whether any or all of these processes are malware, so you show trainees how to upload them to an online service that offers multiple virus and malware scanning tools. After the service has scanned the processes, you explain precisely how to describe the results as you would in a formal forensic report.
Was there malware? Which process(es) was/were contaminated? What type(s) of malware was/were evident? Again, be sure the results are in terms that a trainee or nonexpert can understand. Review your work carefully for accuracy and completeness. This will be the third section of the sample investigative report to be included in the job aid submitted in the final step of this project.
Step 5: Summarize Password and Interception Attacks
You have completed your demonstration of strategies for uncovering hidden or encrypted data, and for diagnosing contamination. There is one more subject that you want to address with the trainees, but it is difficult to demonstrate, so you will gather information and include it in the job aid. It is complex, so you are expecting many questions. The subject is password and interception attacks.
You will need to describe the various classes of password attacks, including brute-force and dictionary attacks. You also want to explain the methods and benefits of offline password cracking. Finally, you want to explain how Windows authentication exchanges work, and how such exchanges may be sniffed and cracked to enable access to protected data.
As you did in Step 1, prepare a 2-page job aid organized in bulleted form (APA format). Refer to in-class readings and outside resources for your content. Proper research and support of your explanations is an important aspect of this assignment. This part of your job aid should be 1 to 2 pages, and APA format should be used.
Remember that trainees and other nonexperts are your target audience. Review your summary carefully for accuracy and completeness. You will include it in the job aid to be delivered when you have completed all the step of this project.
You're finally ready to assemble the job aid and send it to your supervisor for review!
Step 6: Submit Final Assignment (Job Aid)
Your final assignment is a job aid that consists of explanatory material and sample investigative reports. Each investigative report documents the steps and data resulting from a particular analysis.
Requirements for the Job Aid (final assignment)
The job aid should include four sections:
- Explanatory material
- Part I
- Basic cryptography
- Part II
- Password cracking
- Interception attacks
- Part I
- Investigative report, part I
- Analysis of four small partitions extracted from a suspect's hard drive. Your analysis will assess the nature of each partition—specifically, whether each partition is encrypted, compressed, wiped, or none.
- Investigative report, part II
- Analysis of three files extracted from a suspect's hard drive. Your analysis will identify any information hidden in the files, how you found the hidden data, and where it was hidden.
- Investigative report, part III
- Analysis of three executable processes extracted from a snapshot of a suspect's computer memory. Your analysis will use open source tools to identify known malware in any of the processes.
Our website has a team of professional writers who can help you write any of your homework. They will write your papers from scratch. We also have a team of editors just to make sure all papers are of HIGH QUALITY & PLAGIARISM FREE. To make an Order you only need to click Ask A Question and we will direct you to our Order Page at WriteDemy. Then fill Our Order Form with all your assignment instructions. Select your deadline and pay for your paper. You will get it few hours before your set deadline.
Fill in all the assignment paper details that are required in the order form with the standard information being the page count, deadline, academic level and type of paper. It is advisable to have this information at hand so that you can quickly fill in the necessary information needed in the form for the essay writer to be immediately assigned to your writing project. Make payment for the custom essay order to enable us to assign a suitable writer to your order. Payments are made through Paypal on a secured billing page. Finally, sit back and relax.
About Writedemy
We are a professional paper writing website. If you have searched a question and bumped into our website just know you are in the right place to get help in your coursework. We offer HIGH QUALITY & PLAGIARISM FREE Papers.
How It Works
To make an Order you only need to click on “Place Order” and we will direct you to our Order Page. Fill Our Order Form with all your assignment instructions. Select your deadline and pay for your paper. You will get it few hours before your set deadline.
Are there Discounts?
All new clients are eligible for 20% off in their first Order. Our payment method is safe and secure.