Categories: Homework Aiders

IT 357 GMU Department of Homeland Security Forensic Examination Project Scenario: You are a computer forensic examiner working for the Department of Homel

IT 357 GMU Department of Homeland Security Forensic Examination Project Scenario:

You are a computer forensic examiner working for the Department of Homeland Security (DHS).DHS has been investigating the possible threat of an attack within the U.S. by members of the Chechen mujahideen.

Don't use plagiarized sources. Get Your Custom Essay on
IT 357 GMU Department of Homeland Security Forensic Examination Project Scenario: You are a computer forensic examiner working for the Department of Homel
Get an essay WRITTEN FOR YOU, Plagiarism free, and by an EXPERT! Just from $10/Page
Order Essay

Your team has been conducting surveillance of suspected terrorist Anwar Tsarni, a Chechen native, currently working as a graduate teaching assistant at George Mason University.Anwar Tsarni is a known associate of accused Boston Marathon bombers Dzhokhar Tsarnaev and Tamerlan Tsarnaev has traveled to a region with a known Chechen terrorist training camp in the past year.

After a six-month investigation including surveillance and wiretaps of the suspect, a search was conducted of an office located at: 10900 University Blvd. Manassas, VA 20110

You will be investigating a forensic image of a flash drive found during this search.Investigators suspect it may have critical evidence on it that will lead them to break up a terrorist cell and thwart an attempted attack on the U.S. Your job is to conduct a forensic analysis of the disk and write a forensic report of your findings.

Tools:

You may use any FORENSIC tools available to you.
At the very least you should use:
FTK Imager (to verify the image and hash values)
FTK Toolkit (to conduct the majority of your investigation) or Autopsy (https://www.sleuthkit.org/autopsy/)
ExifPro (to examine JPEG files)

You must use the template provided and include the information listed.DO NOT LEAVE PLACEHOLDER TEXT, REPLACE WITH YOUR ACTUAL INFORMATION.

You will include the “best” evidence items and full analysis from the following categories in your report. Only include the number of items listed.Do not include more.

Documents (3 items)
PDF (2 items)
Graphics (3 items, minimum 1 must be jpg)
Deleted Files (3 items that are not discussed in other categories)
HTML or Web-based Files (3 items)
OLE Subitems (1 item)
All other relevant background information, image verification, etc listed in the template Created By AccessData® FTK® Imager 3.1.0.1514
Case Information:
Acquired using: ADI3.1.0.1514
Case Number: IT357
Evidence Number: GMU01
Unique description: Purple/Silver 1GB flash drive
Examiner: R. Pollard
Notes: No physical damage to disk
————————————————————-Information for C:
UsersrjpollardDesktopIT357GMU:
Physical Evidentiary Item (Source) Information:
[Drive Geometry]
Bytes per Sector: 512
Sector Count: 1,966,080
Source data size: 960 MB
Sector count:
1966080
[Computed Hashes]
MD5 checksum:
15b1b636e3d07b5fe3c7a37dd9c127c5
SHA1 checksum:
8a48feef46e5801c50d4af254d675455d3f8eba7
Image Information:
Acquisition started:
Thu Jun 27 11:11:40 2019
Acquisition finished: Thu Jun 27 11:13:29 2019
Segment list:
C:UsersrjpollardDesktopIT357GMU.E01
Image Verification Results:
Verification started: Thu Jun 27 11:13:29 2019
Verification finished: Thu Jun 27 11:13:34 2019
MD5 checksum:
15b1b636e3d07b5fe3c7a37dd9c127c5 : verified
SHA1 checksum:
8a48feef46e5801c50d4af254d675455d3f8eba7 : verified
Individual Project: Forensic Examination
Scenario:
You are a computer forensic examiner working for the Department of Homeland Security (DHS). DHS has been investigating the possible threat of an attack within the U.S. by members of the
Chechen mujahideen.
Your team has been conducting surveillance of suspected terrorist Anwar Tsarni, a Chechen native, currently working as a graduate teaching assistant at George Mason University. Anwar Tsarni
is a known associate of accused Boston Marathon bombers Dzhokhar Tsarnaev and Tamerlan Tsarnaev has traveled to a region with a known Chechen terrorist training camp in the past year.
After a six-month investigation including surveillance and wiretaps of the suspect, a search was conducted of an office located at: 10900 University Blvd. Manassas, VA 20110
You will be investigating a forensic image of a flash drive found during this search. Investigators suspect it may have critical evidence on it that will lead them to break up a terrorist cell and
thwart an attempted attack on the U.S. Your job is to conduct a forensic analysis of the disk and write a forensic report of your findings.
Tools:
? You may use any FORENSIC tools available to you.
o At the very least you should use:
?
FTK Imager (to verify the image and hash values)
?
FTK Toolkit (to conduct the majority of your investigation) or Autopsy (https://www.sleuthkit.org/autopsy/)
?
ExifPro (to examine JPEG files)
You must use the template provided and include the information listed. DO NOT LEAVE PLACEHOLDER TEXT, REPLACE WITH YOUR ACTUAL INFORMATION.
You will include the “best” evidence items and full analysis from the following categories in your report. Only include the number of items listed. Do not include more.
?
?
?
?
?
?
?
Documents (3 items)
PDF (2 items)
Graphics (3 items, minimum 1 must be jpg)
Deleted Files (3 items that are not discussed in other categories)
HTML or Web-based Files (3 items)
OLE Subitems (1 item)
All other relevant background information, image verification, etc listed in the template
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
What to Look For:
? You may want to extract these files to analyze the technical information and metadata closer.
? Remember to look for metadata that may provide you with additional information.
? Remember, you are looking for evidence to help break up a terrorist cell and prevent an attack. You may want to look for evidence of parties involved, locations, types of
attack, etc. You may also want to establish a timeline – this may be crucial if an attack is imminent.
The Report:
? Your report will be approximately 5-10 pages OF TEXT (not including your screenshots, lists of evidence, content of evidence files, etc.)
? You should give a detailed (step by step) explanation of what you did, what you found, and how and where you found it.
? You may use screen shots and file content as an appendix.
o Do not include screenshots in the body of your report!!
o Do not include the content of the evidence files in the body of your report!!
o Crop your screenshots so only relevant information is showing… I shouldn’t be able to see your desktop or other open files.
? Follow the “Forensic Report Guidelines” you have been given during lecture.
o Do not try to analyze the content of files.
o Stick to the FACTS!
o Your report should explain the technical aspects (e.x. what is a link file, why is this important, explain it so a non-technical person can understand.)
o Just giving a list of evidence with no explanation of how you found it and what it means (as far as the technical aspect) is insufficient. Don’t just say you found it using
FTK – explain!
o Analyze the metadata!
o You have more than enough evidence on the disk to EASILY write this much text. If you are having a hard time, you probably missed a significant amount of evidence.
Formatting:
?
?
?
?
?
?
?
?
?
Use the template provided
Include a title page
Text should be single spaced, 0 spacing before & after
Font should be set to Arial or Calibri
Font should be set to 12 point
Margins should be set to 1 inch
Paragraphs should be set to Justify (not left, right, or center aligned)
You should include headings and subheadings
Your report should be in complete sentences, free of grammatical/spelling errors, easy to read, and professional.
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
? If you use any outside sources, you must cite them using APA citations
? Your report must have a red watermark on every page stating: “THIS IS AN EDUCATIONAL PROJECT”. Any project that does not have this will be a zero.
o Page Layout – Watermark – Custom Watermark – Text Watermark
o Change the text to “THIS IS AN EDUCATIONAL PROJECT”
o Change the color to RED, transparency to 75%
? Your file must be less than 10MB to be submitted to SafeAssign.
o Compress your graphics by using the “Compress Pictures” option in Word.
o Choose the smallest file size possible.
Hints:
? Remember: your report should read like a story. A list of evidence is not sufficient for a report… you need to explain how/where you found the evidence.
? You are not a terrorism analyst, so do not try to interpret the evidence… present the facts as you find them. Remember… you can’t say a specific person did something.
? This is an individual project. The GMU honor code will be strictly enforced. You will submit your assignment through SafeAssign on blackboard. Only work submitted
through SafeAssign will be accepted.
Checklist:
***Also review the rubric for the project
Content:
?
I included the case background, my name, who I work for, etc.
?
I verified the hash value before anything else.
?
I included the given hashes and calculated hashed.
?
My report only includes FACTS, no opinions or interpretations.
?
I did not analyze the file content.
?
My report includes the file names of evidence items.
?
My report includes the file paths of evidence items.
?
My report includes the MAC dates and times of evidence items.
?
My report explains if the evidence is a file, deleted file, etc. and explains what this means.
?
Someone could read my report and follow my steps exactly step by step. (I explain what I did.)
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
?
Any technical term includes an explanation of what it is, in layman’s terms. (I explain what everything means.)
?
All evidence mentioned in the report is in the appendix.
?
I don’t say a specific person did something. (Usernames are differentiated from a person’s name.)
?
All evidence is documented in the report.
?
I do not have any inaccurate information in my report.
Formatting:
?
I included my watermark.
?
I compressed my graphics and my project is less than 10MB.
?
I followed formatting guidelines for font, line spacing, etc.
?
I do not have screenshots in the body of my report.
?
I do not have file content in the body of my report.
?
My appendix has labels for each evidence item.
?
I spell checked and proofread my report.
?
My report is well formatted and easy to read.
?
I use headings and subheadings.
?
I do not have long paragraphs.
?
Only one evidence item is discussed per paragraph.
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
Rubric:
Criterion
Case Background
Expected
Case background addressed including:
·
Satisfactory
? Missing 1-2 items
Insufficient
? Not addressed or
? Missing 2 or more items
Investigator information including:
o name
o who the investigator works for
? Case information
? Authority to investigate based on search
warrant’s authorization
? How, when, and where the evidence was
obtained
? What type of evidence is being analyzed
? How did you process the evidence or get the
image file
4-5
Hash Value
? Hash value properly calculated, and
? Proper steps to calculate the hash value are
explained, and
? Both the hash calculated by the student and
the hash value given with the evidence are
shown in the report, and
? Explains the importance of calculating this
and what it shows
2-3
? Hash value properly calculated, and
? Student explains proper steps to calculate,
and
? Shows both the hash calculated by the
student and the given hash value, and
? Does not explain the importance
0-1
? Hash not properly calculated, or
? Does not show both calculated and given
hash values, or
? Does not explain steps, or
? Does not explain the importance, or
? Not addressed
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
4-5
Required
Evidence
Included
Includes the proper number of relevant examples for
all categories:
? Some examples included are not relevant, or
? Missing 1-3 items
0-1
? Majority of examples are not relevant, or
? Missing more than 3 examples
?
?
?
?
Documents (3 items)
PDF (2 items)
Graphics (3 items, minimum 1 must be jpg)
Deleted Files (3 items that are not discussed in
other categories)
? HTML or Web-based Files (3 items)
? OLE Subitems (1 item)
15-20
Explanation
2-3
Report explains:
? Step by step what was done, includes
software and versions, and
? What was found, and
? How it was found (more than saying “I found
this using FTK” – must explain in detail), and
? All technical details are explained in terms a
jury/non-technical person would understand,
and
? Why the technical information is important
or why it is relevant to the case, and
? Information is accurate and only includes
facts
10-14
? Explains what was done, what was found,
and how it was found, and
? Does not explain technical information, or
? Includes lists of data that is not explained, or
? Includes all elements but it is not written so a
non-technical person would understand
0-9
? Does not explain the technical details in
terms a jury would understand, or
? Does not explain step by step what was done,
or
? Gives a general explanation but is not specific
for each evidence item
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
15-20
Content
? All evidence items addressed and fully
discussed, and
? All metadata is addressed for each evidence
item including file names, file paths, MAC
times, file status (deleted or file), and
? Report does not address any file content
(except in appendix), and
? No file content is analyzed, and
? No interpretations or opinions, and
? Report does not say a specific person did
something, and
? If relevant, report differentiates between a
person and username/email if mentioned,
and
? If relevant, documents are not translated but
mention sending to a translation specialist for
review, and
? Explains using Imager to verify image, FTK to
conduct analysis and ExifPro to examine
images (other tools can be used only if they
are verified forensic tools), and
? 5+ pages of text not including any content of
evidence files or screenshots, and
? Information is accurate and only includes
facts
15-20
10-14
? Metadata and other information is included,
but not fully explained, or
? Missing some metadata or information that
should be included
10-14
0-9
?
?
?
?
?
?
File content is addressed, or
File content is analyzed or summarized, or
Included interpretations or opinions, or
Lack of proper explanation, or
Less than 5 pages of text, or
Missing evidence items and/or proper
analysis of metadata, or
? Inaccurate information
0-9
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
Grammar and
Formatting
? Template provided is used, and
? Report follows formatting guidelines, and
? Report includes multiple headings and
subheadings and is easy to read (should be
able to quickly scan through the report and
identify evidence items. Should not include
long running paragraphs.), and
? Report is specific and does not include vague
language (e.x. many, several), and
? No grammatical errors, spelling errors, or
typos, and
? Formatting guidelines are followed including
font, line spacing, and justified text, and
? Report is written in first person, and
? Reads like a professional report
11-15
Appendix
? No screenshots or file content in the body of
the report only in the appendix
? Appendix is labeled properly to correlate to
evidence items in the report
? All evidence items mentioned in the report
appear in the appendix
? No discussion of the file content in the
appendix
11-15
? Formatting guidelines not followed, or
? Minor grammatical errors, spelling errors, or
typos, or
? Includes vague language, or
? Missing headings/subheadings where
needed, or
? Long running paragraphs, or
? Placeholder text left anywhere in report
?
?
?
?
?
?
?
?
6-10
? Appendix is not properly labeled but all other
items are adequate
? Missing 2-3 evidence items that appear in the
report.
6-10
Template provided not used, or
Vague language, or
Missing headings, or
Multiple grammatical errors, spelling errors,
or typos or
Improper formatting or
Not written in first person, or
Abundance of placeholder text left in the
report, or
Not written to read like a professional report
0-5
? Evidence items do not appear in the appendix
or missing some evidence items that appear
in the report or
? Screenshots in the body of the report or
? File content is discussed in the appendix
0-5
Copyright © 2018 Rebecca J. Pollard. All rights reserved.
GMU IT 357 Forensic Report
Name
This is an educational project for a George Mason University course. Contents of this report are part of a
fictional scenario.
By submitting this assignment, I certify I have abided by all requirements
of the GMU honor code. I certify that this is entirely my own work, no
unauthorized sources have been used, and all sources used have been
properly cited.
Investigator Information
Include your name, who you work for, qualifications to conduct this analysis
Case Background
Include the background of the case, search warrant authorization, where, when, and how the
evidence was found, type of evidence, how/where evidence was obtained, how/when/who
created image and how you obtained it
Evidence Analyzed
Give details about the evidence – i.e. what type of evidence are you examining? Give an
explanation of how the evidence was acquired and steps taken. Hint: You were given the image
file, who created this, how did you obtain this?
Verification of Evidence Integrity
Explain the hash process, and what tools were used. Explain what a hash is and why it is
important. Show the hash value given with the evidence and compare it to the hash value you
calculated with the image verification. Hint: You were given an image file, do not create an image
of the image, just verify it.
Forensic Tools
Explain what tools and systems you are using to conduct the analysis, include versions of the
tools and additional information about the tools or any details to give credibility.
Overview
Give an overview explaining your approach to the forensic investigation and analysis of the
evidence.
Give an overview of the structure of the drive, number of files, folders and folder organization,
etc.
Documents
Explain the steps you have taken to get here
Explain relevance and other details
Evidence File Name #1
Give all of the details about this evidence item in a way a non-technical person would understand
Explain exactly HOW you found it using the tools (not just “I found this using FTK”)
Give the file path (full file path from the root of the EVIDENCE drive, not of your image you are
working off)
Explain information about the file properties, metadata, and any relevant technical information,
including the file type. Is it a file or a deleted file? How can you tell? How can you recover this if
it’s “deleted”?
Explain the technical significance of this (e.x. Link files are created when a file is opened in
Windows Explorer. They contain information specific to the underlying file and are a reliable
indicator that a particular file was opened. Link files were found on this computer that are
consistent with File A being opened on March 1st, 2006 at 2:44 am.)
Reference the appendix # with the content of the file.
Notes:
No file content goes here.
No screenshots go here.
No analysis of the file content.
No interpretations or opinions.
Differentiate between a username and person – don’t say a person did something.
Don’t use long paragraphs, break them up so it is easy to read.
Don’t use vague language like several or many, be specific
Write in first person
Write like this is a professional report
If you include technical information it MUST be explained.
Don’t include lists of technical info without an explanation.
Evidence File Name #2
Include relevant info listed above
Evidence File Name #3
Include relevant info listed above
PDF
Explain the steps you have taken to get here
Explain relevance and other details
Evidence File Name #1
Give all of the details about this evidence item in a way a non-technical person would understand
Explain exactly HOW you found it using the tools (not just “I found this using FTK”)
Give the file path (full file path from the root of the EVIDENCE drive, not of your image you are
working off)
Explain information about the file properties, metadata, and any relevant technical information,
including the file type. Is it a file or a deleted file? How can you tell? How can you recover this if
it’s “deleted”?
Explain the technical significance of this (e.x. Link files are created when a file is opened in
Windows Explorer. They contain information specific to the underlying file and are a reliable
indicator that a particular file was opened. Link files were found on this computer that are
consistent with File A being opened on March 1st, 2006 at 2:44 am.)
Reference the appendix # with the content of the file.
Notes:
No file content goes here.
No screenshots go here.
No analysis of the file content.
No interpretations or opinions.
Differentiate between a username and person – don’t say a person did something.
Don’t use long paragraphs, break them up so it is easy to read.
Don’t use vague language like several or many, be specific
Write in first person
Write like this is a professional report
If you include technical information it MUST be explained.
Don’t include lists of technical info without an explanation.
Evidence File Name #2
Include relevant info listed above
Graphics
Explain the steps you have taken to get here
Explain relevance and other details
Evidence File Name #1
Give all of the details about this evidence item in a way a non-technical person would understand
Explain exactly HOW you found it using the tools (not just “I found this using FTK”)
Give the file path (full file path from the root …
Purchase answer to see full
attachment

superadmin

Recent Posts

communication MA | Solution Aider

part one For this assignment you are to to watch: Shattered Glass Write a two…

4 years ago

Standard Project – WebServers | Solution Aider

Standard Project - WebServers. Instruction attached. Need all requirements, you do not have to make…

4 years ago

Discussion post 2 | Solution Aider

Read classmates post and respond with 100 words:The International Categorization of Diseases, Tenth Revision, Clinical…

4 years ago

case sttudy | Solution Aider

Most Americans have at least 1 issue that is most important to them. Economic issues…

4 years ago

Methodologies Report | Solution Aider

For this assignment, you are the court intake processor at a federal court where you…

4 years ago

outline about gender equality | Solution Aider

Use a standard outline format to lay out how you are going to write your…

4 years ago