Need help with your Discussion

Get a timely done, PLAGIARISM-FREE paper
from our highly-qualified writers!

glass
pen
clip
papers
heaphones

Pace University Live Acquisition Tool to Capture Evidence Project

Pace University Live Acquisition Tool to Capture Evidence Project

Pace University Live Acquisition Tool to Capture Evidence Project

Question Description

  • Using a live acquisition tool to capture evidence.
  • Analyzing Virtual Memory Using Forensic Toolkit.
  • Analyzing Windows Registry

You have used AccessData’s Forensic Toolkit (FTK) Imager to image storage devices, analyze several files. In addition, FTK Imager is provided a portable version that will fit on a small USB storage device (https://accessdata.com/product-download#past-versions, download FTK Imager Version 4.3.1.1 into your USB driver). Then, a forensic investigator can acquire the contents of virtual memory and the Windows registry that may be related to any computer crimes committed on that machine. As we may know, the virtual memory holds data temporarily when the operating system processes instructions.

Procedures:

You should install FTK Imager Lite (not anymore work, so we use FTK Imager Version 4.3.1.1 as a portable tool) on a USB Flash drive and use it to capture the Windows registry files while extracting all the files of FTK Imager Lite (FTK Imager Version 4.3.1.1) into a USB flash drive.

To start the software, double-click the FTK Imager.exe file.

Because virtual memory is temporary (volatile), examination of this evidence may be possible only before the computer is turned off to move it to a forensic lab.

You should process a virtual memory capture performed on a live computer.

Procedures:

Copy the memdump.zip file wherever you want to save, and extract all (like a RAM folder).

To start FTK tool by right-clicking the FTK icon in your USB drive (e.g., Run as administration).

In the search tab (ctrl+F after highlighting the hexadecimal windows at the right bottom), type bank, and click the blue add button. In the search tab, type search, and click the blue add button. Where both bank and search are found together, click the blue view cumulative results button, select all hits, check apply to all and click OK.

  • Screen shot of search results while indicating John Smith used Bing in Internet Explorer to search for bank locations.
  • Screen shot of http://www.yellowpages.com to find the Suntrust Bank Plantation location
  • What is the size of the memdump.mem file?
  • How many evidence items were processed by FTK?
  • How many hits are found searching using the word password ?
  • How many files are found searching the file extension .doc ?
  • How many Cumulative Result Hits are found using both password and .doc ?

The Windows registry is a central repository for all information such as users, passwords, connected devices, and physical hardware. Those data in the registry can be searched for evidence using Access Data’s Registry Viewer. Although it does not display user information in a readable format, every item listed in the registry represents a 128-bit name called a globally unique ID (GUID) that contains useful information such as the last login or last storage device accessed.

Procedures:

First, you should install AccessData Registry Viewer with rv-registry_viewer-1.5.4.exe file on BB.

Right-click the AcessData Registry Viewer icon to start.

Click File tab and click open, navigate where we you saved in 1) lab, and click Registry folder.

Click the SAM file, and click open, click the + symbol next to the SAM to expand it.

  • Screen shot of the Administrator account including the Last Logon Time
  • Screen shot of the Guest account indicating the SID number 501.
  • What is the SID associated with John Smith user name?
  • What was the last time John Smith logged into the computer?
  • Besides Andrews, which other user has never logged into the computer?
  • Screen shot of the attached storage devices implying that a forensic investigator should look for additional storage devices.
  • How many USB storage devices have been connected to this computer?
  • How many internal hard drives have been attached to this computer?

Close the Registry Viewer dialog box while clicking the file tab.

Click the file tab, select open, and double-click the System registry hive to load it into the registry viewer.

Have a similar assignment? "Place an order for your assignment and have exceptional work written by our team of experts, guaranteeing you A results."

Order Solution Now

Our Service Charter


1. Professional & Expert Writers: Eminence Papers only hires the best. Our writers are specially selected and recruited, after which they undergo further training to perfect their skills for specialization purposes. Moreover, our writers are holders of masters and Ph.D. degrees. They have impressive academic records, besides being native English speakers.

2. Top Quality Papers: Our customers are always guaranteed of papers that exceed their expectations. All our writers have +5 years of experience. This implies that all papers are written by individuals who are experts in their fields. In addition, the quality team reviews all the papers before sending them to the customers.

3. Plagiarism-Free Papers: All papers provided by Eminence Papers are written from scratch. Appropriate referencing and citation of key information are followed. Plagiarism checkers are used by the Quality assurance team and our editors just to double-check that there are no instances of plagiarism.

4. Timely Delivery: Time wasted is equivalent to a failed dedication and commitment. Eminence Papers are known for the timely delivery of any pending customer orders. Customers are well informed of the progress of their papers to ensure they keep track of what the writer is providing before the final draft is sent for grading.

5. Affordable Prices: Our prices are fairly structured to fit in all groups. Any customer willing to place their assignments with us can do so at very affordable prices. In addition, our customers enjoy regular discounts and bonuses.

6. 24/7 Customer Support: At Eminence Papers, we have put in place a team of experts who answer all customer inquiries promptly. The best part is the ever-availability of the team. Customers can make inquiries anytime.

We Can Write It for You! Enjoy 20% OFF on This Order. Use Code SAVE20

Stuck with your Assignment?

Enjoy 20% OFF Today
Use code SAVE20