IT 357 George Mason University Forensic Science and Cybercrime Educational Project please see attachments. i have attached all documents needed for assignment. if you have any question please let me know. How to get started:
1. Review Lecture 5 report writing guidelines
2. Review the assignment and expectations
3. Make sure FTK and Imager (the versions that are posted on Blackboard) or Autopsy
(https://www.sleuthkit.org/autopsy/) are installed
4. Download project image and hash values from blackboard
5. Open the image with FTK Imager verify it to make sure the hash values match what was given
6. Open the image in FTK/Autopsy to start your analysis
7. Document each step!!
Hints/reminders for the project:
1. Your report should document each step in your analysis and explain what you did, what you
found, how, where, what the technical aspects mean
2. Dont interpret the file content that is out of the scope of your job!
3. You cant say a specific person did something make sure you differentiate between PEOPLE
and USERNAMES
4. Stick to the facts
5. Write in first person
6. Include LOTS of screenshots but these go in the appendix, not the body of your report!
7. Dont forget to include the basics in your report who are you? Your authority? What case is
this? Background?
Need help?
?
?
?
?
HELP! Folder on blackboard
Labs 2 and 3
Lecture 5, 6, and 7
Ask!
Individual Project: Forensic Examination
Scenario:
You are a computer forensic examiner working for the Department of Homeland Security (DHS). DHS has been investigating the possible threat of an attack within the U.S. by members of the
Chechen mujahideen.
Your team has been conducting surveillance of suspected terrorist Anwar Tsarni, a Chechen native, currently working as a graduate teaching assistant at George Mason University. Anwar Tsarni
is a known associate of accused Boston Marathon bombers Dzhokhar Tsarnaev and Tamerlan Tsarnaev has traveled to a region with a known Chechen terrorist training camp in the past year.
After a six-month investigation including surveillance and wiretaps of the suspect, a search was conducted of an office located at: 10900 University Blvd. Manassas, VA 20110
You will be investigating a forensic image of a flash drive found during this search. Investigators suspect it may have critical evidence on it that will lead them to break up a terrorist cell and
thwart an attempted attack on the U.S. Your job is to conduct a forensic analysis of the disk and write a forensic report of your findings.
Tools:
? You may use any FORENSIC tools available to you.
o At the very least you should use:
?
FTK Imager (to verify the image and hash values)
?
FTK Toolkit (to conduct the majority of your investigation) or Autopsy (https://www.sleuthkit.org/autopsy/)
?
ExifPro (to examine JPEG files)
You must use the template provided and include the information listed. DO NOT LEAVE PLACEHOLDER TEXT, REPLACE WITH YOUR ACTUAL INFORMATION.
You will include the best evidence items and full analysis from the following categories in your report. Only include the number of items listed. Do not include more.
?
?
?
?
?
?
?
Documents (3 items)
PDF (2 items)
Graphics (3 items, minimum 1 must be jpg)
Deleted Files (3 items that are not discussed in other categories)
HTML or Web-based Files (3 items)
OLE Subitems (1 item)
All other relevant background information, image verification, etc listed in the template
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
What to Look For:
? You may want to extract these files to analyze the technical information and metadata closer.
? Remember to look for metadata that may provide you with additional information.
? Remember, you are looking for evidence to help break up a terrorist cell and prevent an attack. You may want to look for evidence of parties involved, locations, types of
attack, etc. You may also want to establish a timeline this may be crucial if an attack is imminent.
The Report:
? Your report will be approximately 5-10 pages OF TEXT (not including your screenshots, lists of evidence, content of evidence files, etc.)
? You should give a detailed (step by step) explanation of what you did, what you found, and how and where you found it.
? You may use screen shots and file content as an appendix.
o Do not include screenshots in the body of your report!!
o Do not include the content of the evidence files in the body of your report!!
o Crop your screenshots so only relevant information is showing
I shouldnt be able to see your desktop or other open files.
? Follow the Forensic Report Guidelines you have been given during lecture.
o Do not try to analyze the content of files.
o Stick to the FACTS!
o Your report should explain the technical aspects (e.x. what is a link file, why is this important, explain it so a non-technical person can understand.)
o Just giving a list of evidence with no explanation of how you found it and what it means (as far as the technical aspect) is insufficient. Dont just say you found it using
FTK explain!
o Analyze the metadata!
o You have more than enough evidence on the disk to EASILY write this much text. If you are having a hard time, you probably missed a significant amount of evidence.
Formatting:
?
?
?
?
?
?
?
?
?
Use the template provided
Include a title page
Text should be single spaced, 0 spacing before & after
Font should be set to Arial or Calibri
Font should be set to 12 point
Margins should be set to 1 inch
Paragraphs should be set to Justify (not left, right, or center aligned)
You should include headings and subheadings
Your report should be in complete sentences, free of grammatical/spelling errors, easy to read, and professional.
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
? If you use any outside sources, you must cite them using APA citations
? Your report must have a red watermark on every page stating: THIS IS AN EDUCATIONAL PROJECT. Any project that does not have this will be a zero.
o Page Layout Watermark Custom Watermark Text Watermark
o Change the text to THIS IS AN EDUCATIONAL PROJECT
o Change the color to RED, transparency to 75%
? Your file must be less than 10MB to be submitted to SafeAssign.
o Compress your graphics by using the Compress Pictures option in Word.
o Choose the smallest file size possible.
Hints:
? Remember: your report should read like a story. A list of evidence is not sufficient for a report
you need to explain how/where you found the evidence.
? You are not a terrorism analyst, so do not try to interpret the evidence
present the facts as you find them. Remember
you cant say a specific person did something.
? This is an individual project. The GMU honor code will be strictly enforced. You will submit your assignment through SafeAssign on blackboard. Only work submitted
through SafeAssign will be accepted.
Checklist:
***Also review the rubric for the project
Content:
?
I included the case background, my name, who I work for, etc.
?
I verified the hash value before anything else.
?
I included the given hashes and calculated hashed.
?
My report only includes FACTS, no opinions or interpretations.
?
I did not analyze the file content.
?
My report includes the file names of evidence items.
?
My report includes the file paths of evidence items.
?
My report includes the MAC dates and times of evidence items.
?
My report explains if the evidence is a file, deleted file, etc. and explains what this means.
?
Someone could read my report and follow my steps exactly step by step. (I explain what I did.)
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
?
Any technical term includes an explanation of what it is, in laymans terms. (I explain what everything means.)
?
All evidence mentioned in the report is in the appendix.
?
I dont say a specific person did something. (Usernames are differentiated from a persons name.)
?
All evidence is documented in the report.
?
I do not have any inaccurate information in my report.
Formatting:
?
I included my watermark.
?
I compressed my graphics and my project is less than 10MB.
?
I followed formatting guidelines for font, line spacing, etc.
?
I do not have screenshots in the body of my report.
?
I do not have file content in the body of my report.
?
My appendix has labels for each evidence item.
?
I spell checked and proofread my report.
?
My report is well formatted and easy to read.
?
I use headings and subheadings.
?
I do not have long paragraphs.
?
Only one evidence item is discussed per paragraph.
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
Rubric:
Criterion
Case Background
Expected
Case background addressed including:
·
Satisfactory
? Missing 1-2 items
Insufficient
? Not addressed or
? Missing 2 or more items
Investigator information including:
o name
o who the investigator works for
? Case information
? Authority to investigate based on search
warrants authorization
? How, when, and where the evidence was
obtained
? What type of evidence is being analyzed
? How did you process the evidence or get the
image file
4-5
Hash Value
? Hash value properly calculated, and
? Proper steps to calculate the hash value are
explained, and
? Both the hash calculated by the student and
the hash value given with the evidence are
shown in the report, and
? Explains the importance of calculating this
and what it shows
2-3
? Hash value properly calculated, and
? Student explains proper steps to calculate,
and
? Shows both the hash calculated by the
student and the given hash value, and
? Does not explain the importance
0-1
? Hash not properly calculated, or
? Does not show both calculated and given
hash values, or
? Does not explain steps, or
? Does not explain the importance, or
? Not addressed
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
4-5
Required
Evidence
Included
Includes the proper number of relevant examples for
all categories:
? Some examples included are not relevant, or
? Missing 1-3 items
0-1
? Majority of examples are not relevant, or
? Missing more than 3 examples
?
?
?
?
Documents (3 items)
PDF (2 items)
Graphics (3 items, minimum 1 must be jpg)
Deleted Files (3 items that are not discussed in
other categories)
? HTML or Web-based Files (3 items)
? OLE Subitems (1 item)
15-20
Explanation
2-3
Report explains:
? Step by step what was done, includes
software and versions, and
? What was found, and
? How it was found (more than saying I found
this using FTK must explain in detail), and
? All technical details are explained in terms a
jury/non-technical person would understand,
and
? Why the technical information is important
or why it is relevant to the case, and
? Information is accurate and only includes
facts
10-14
? Explains what was done, what was found,
and how it was found, and
? Does not explain technical information, or
? Includes lists of data that is not explained, or
? Includes all elements but it is not written so a
non-technical person would understand
0-9
? Does not explain the technical details in
terms a jury would understand, or
? Does not explain step by step what was done,
or
? Gives a general explanation but is not specific
for each evidence item
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
15-20
Content
? All evidence items addressed and fully
discussed, and
? All metadata is addressed for each evidence
item including file names, file paths, MAC
times, file status (deleted or file), and
? Report does not address any file content
(except in appendix), and
? No file content is analyzed, and
? No interpretations or opinions, and
? Report does not say a specific person did
something, and
? If relevant, report differentiates between a
person and username/email if mentioned,
and
? If relevant, documents are not translated but
mention sending to a translation specialist for
review, and
? Explains using Imager to verify image, FTK to
conduct analysis and ExifPro to examine
images (other tools can be used only if they
are verified forensic tools), and
? 5+ pages of text not including any content of
evidence files or screenshots, and
? Information is accurate and only includes
facts
15-20
10-14
? Metadata and other information is included,
but not fully explained, or
? Missing some metadata or information that
should be included
10-14
0-9
?
?
?
?
?
?
File content is addressed, or
File content is analyzed or summarized, or
Included interpretations or opinions, or
Lack of proper explanation, or
Less than 5 pages of text, or
Missing evidence items and/or proper
analysis of metadata, or
? Inaccurate information
0-9
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
Grammar and
Formatting
? Template provided is used, and
? Report follows formatting guidelines, and
? Report includes multiple headings and
subheadings and is easy to read (should be
able to quickly scan through the report and
identify evidence items. Should not include
long running paragraphs.), and
? Report is specific and does not include vague
language (e.x. many, several), and
? No grammatical errors, spelling errors, or
typos, and
? Formatting guidelines are followed including
font, line spacing, and justified text, and
? Report is written in first person, and
? Reads like a professional report
11-15
Appendix
? No screenshots or file content in the body of
the report only in the appendix
? Appendix is labeled properly to correlate to
evidence items in the report
? All evidence items mentioned in the report
appear in the appendix
? No discussion of the file content in the
appendix
11-15
? Formatting guidelines not followed, or
? Minor grammatical errors, spelling errors, or
typos, or
? Includes vague language, or
? Missing headings/subheadings where
needed, or
? Long running paragraphs, or
? Placeholder text left anywhere in report
?
?
?
?
?
?
?
?
6-10
? Appendix is not properly labeled but all other
items are adequate
? Missing 2-3 evidence items that appear in the
report.
6-10
Template provided not used, or
Vague language, or
Missing headings, or
Multiple grammatical errors, spelling errors,
or typos or
Improper formatting or
Not written in first person, or
Abundance of placeholder text left in the
report, or
Not written to read like a professional report
0-5
? Evidence items do not appear in the appendix
or missing some evidence items that appear
in the report or
? Screenshots in the body of the report or
? File content is discussed in the appendix
0-5
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
Lecture 5
Report Wri.ng
IT 357/CRIM
304 304
IT 357/CRIM
MM
archant
enally, 2015
2013
© A
©nne
Anne
archant && R Rebecca
ebecca JJ. . TTenally,
What is a Computer Forensic Report?
From Incident Response & Computer Forensics; Mandia, et al, 2003
A standard way to document:
Why you reviewed a computer system
How you reviewed the computer data
How you arrived at your conclusions
Clearly explain your conclusions
Support your conclusions
2 Types of forensic reports
Report only the facts (used by law enforcement examiners)
Report the facts and opinions (an Expert Report)
Goals of a Forensic Report
From Incident Response & Computer Forensics; Mandia, et al, 2003
Accurately describe the details of an incident
Be understandable to decision-?makers
Be able to withstand a barrage of legal scru.ny
Be unambiguous and not open to misinterpreta.on
Be easily references (using paragraph numbers for the report and
Bates numbers for a[ached documents)
Contain all informa.on required to explain your conclusions
O?er valid conclusions, opinions, or recommenda.ons when
needed
Repor.ng The Forensic Report
Will
become the basis for any legal complaints
Will become a legal document and entered into
evidence
Will be read by EVERYONE
Will be used in legal proceedings as a basis for
tes.mony, discovery, and
can also be used to impeach your tes.mony
N.B.: Impeach: To challenge the honesty or veracity of
as in, defense counselor impeached the witnesss
tes.mony by contradic.ng it with the witnesss own report.
Repor.ng The Forensic Report
Therefore, care should be taken to only include
the facts before the examiner
Care should also be taken to avoid:
Misstatements
Reliance on facts not available
Sloppiness
A sloppy report will be construed to be the work product of a
sloppy examiner
Statements that are opinions, or have no basis in fact
Statements that can be interpreted in a number of ways
Overly broad statements that can be challenged
(Slide used with permission of Lam Nguyen)
Repor.ng The Forensic Report
Example:
The link ?les prove that the defendant undoubtedly
viewed ?le A on March 1st, 2006 at approximately
2:44 am.
Whats wrong with this statement?
(Slide used with permission of Lam Nguyen)
The examiner is not the trier of
fact, and thus, does not use words
that make determina.ons.
Repor.ng The Forensic Report
Repor.ng The Forensic This
Report
word is overly broad and there is
Example:
no reason for adjec.ves in a report
based on fact.
The link ?les prove that the defendant undoubtedly
viewed ?le A on March 1st, 2006 at approximately 2:44
am.
Approximately,
indicates
doubt.
Whats
wrong
with
this It statement?
either happened at 2:44 am or it did
not.
(Slide used with permission of Lam Nguyen)
Explains to the reader why link ?les
ar…
Purchase answer to see full
attachment
part one For this assignment you are to to watch: Shattered Glass Write a two…
Standard Project - WebServers. Instruction attached. Need all requirements, you do not have to make…
Read classmates post and respond with 100 words:The International Categorization of Diseases, Tenth Revision, Clinical…
Most Americans have at least 1 issue that is most important to them. Economic issues…
For this assignment, you are the court intake processor at a federal court where you…
Use a standard outline format to lay out how you are going to write your…