Does the sender have any other unusual activities

Assignment Help Computer Engineering
Reference no: EM133680904

Homework: Investigation

Purpose

In this homework, you will examine a volatile memory dump to investigate a potential malware case. Your analysis will primarily be done with Volatility Workbench, but you may also use other utilities to look at the disk from other perspectives. In Autopsy, the evidence can be imported as an Unallocated Space image to run intake scripts. Be sure to make a note of all applications and methods you use in your examination.

Instructions

You'll need to use the following resources to complete the homework:

I. Investigation 04 Sample Evidence*

II. Volatility Workbench*

III. (Optional) Download and use the report template (See the Investigation and Forensics Challenge module for the templates)

IV. (Optional) Strings

V. (Optional) Autopsy the open-source forensic suite* (or another suite, such as EnCase or FTK.)

Accessed via the Virtual Lab.

After reading the Investigation 4 Scenario, open your forensic tool and import the sample evidence into the case. Begin a forensic report to document your examination.

Scenario

This scenario takes place circa 2010.

Company X has contacted you to perform forensics work on a recent incident that occurred. One of their employees had received an email from a fellow co-worker that pointed to a PDF file. Upon opening, the employee did not seem to notice anything. However, recently they have had unusual activity in their bank account.

Company X was able to obtain a memory image of the employee's virtual machine upon suspected infection. Company X wishes you to analyze the virtual memory and report on any suspected activities found.

Task

I. What specific indicators in the memory image indicate possible malicious activity?

II. Is there any evidence of malware execution or persistence mechanisms in the memory image?

III. Is there any evidence of privilege escalation or unauthorized access to the memory image?

IV. Is there any evidence of memory-resident malware or rootkits that could avoid traditional detection methods?

V. Was there any sensitive information, such as credentials or financial data, has been accessed or altered within the memory image?

VI. Are there any unusual processes or applications running in the virtual machine's memory during the suspected infection?

VII. Does the sender have any other unusual activities?

VIII. What were the processes that were running on the employees computer?

Reference no: EM133680904

Questions Cloud

What kind of presidency is faithful servant presidency : What kind of presidency is a faithful servant presidency? What kind of presidency is a faithful servant presidency?
How quantum cryptography differ from classical cryptography : How does quantum cryptography differ from classical cryptography, and what are the implications for secure communication?
Write on base of the movie paper tigers-alexander street : Write on the base of the movie Paper Tigers - Alexander Street, What are some physical and/or psychological symptoms that can occur from toxic stress.
Identify contemporary policy the field of education : Identify a contemporary policy the field of education that is relevant to an issue or challenge faced by your school or district.
Does the sender have any other unusual activities : Does the sender have any other unusual activities? What were the processes that were running on the employees computer?
State constitutions represent the fundamental law of state : State constitutions represent the fundamental law of the state
What is remote monitoring and how it being use in healthcare : What is remote monitoring, and how is it being used in healthcare? What are the benefits of remote monitoring for patients and healthcare providers?
Roles of social engagement in language development : For Piaget's theory and Vygotsky's Socioculturalism primary language acquisition theories, what are the roles of socialization.
Governmental entity to represent the organization : A person employed by a governmental entity to represent the organization before the legislature is called a A person employed by a governmental

Reviews

Write a Review

Computer Engineering Questions & Answers

  Mathematics in computing

Binary search tree, and postorder and preorder traversal Determine the shortest path in Graph

  Ict governance

ICT is defined as the term of Information and communication technologies, it is diverse set of technical tools and resources used by the government agencies to communicate and produce, circulate, store, and manage all information.

  Implementation of memory management

Assignment covers the following eight topics and explore the implementation of memory management, processes and threads.

  Realize business and organizational data storage

Realize business and organizational data storage and fast access times are much more important than they have ever been. Compare and contrast magnetic tapes, magnetic disks, optical discs

  What is the protocol overhead

What are the advantages of using a compiled language over an interpreted one? Under what circumstances would you select to use an interpreted language?

  Implementation of memory management

Paper describes about memory management. How memory is used in executing programs and its critical support for applications.

  Define open and closed loop control systems

Define open and closed loop cotrol systems.Explain difference between time varying and time invariant control system wth suitable example.

  Prepare a proposal to deploy windows server

Prepare a proposal to deploy Windows Server onto an existing network based on the provided scenario.

  Security policy document project

Analyze security requirements and develop a security policy

  Write a procedure that produces independent stack objects

Write a procedure (make-stack) that produces independent stack objects, using a message-passing style, e.g.

  Define a suitable functional unit

Define a suitable functional unit for a comparative study between two different types of paint.

  Calculate yield to maturity and bond prices

Calculate yield to maturity (YTM) and bond prices

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd