Examine file system image on virtual desktop infrastructure

Assignment Help Computer Network Security
Reference no: EM132221979

Instructions

Use The Sleuth Kit. (TSK) to examine the file system image diskimage.dd on the Virtual Desktop Infrastructure (VDI) at Champlain to complete the Lab.

Using The Sleuth Kit (TSK) on the VDI

"The Sleuth Kit is a collection of command line tools and a C library that allows you to analyze disk images and recover files from them. It is used behind the scenes in Autopsy and many other open source and commercial forensics tools."

Questions:

1. Copy the attached onto your desktop on the VDI:
diskimage.dd (file)
bin (folder)

Take a screenshot of these items on your desktop with the URL of the VDI. The file name, folder name, and URL should be clearly visible in the screenshot.

Attach the screenshot to answer this question.

Note: The TSK programs will not work unless the bin folder and the forensic images being examined are on the VDI desktop.

2. According to the TSK Overview, which TSK program is used to find the layout of a hard drive, including partition information?

3. According to the TSK Overview, which TSK program is used to find the file system statistics of a hard drive?

4. According to the TSK Overview, which TSK program is used to find the files on a forensic image?

5. According to the TSK Overview, which TSK program is used to find the meta data of a given file?

6. At what sector do the FAT CONTENTS begin on diskimage.dd?

7. Where are the file allocation tables begin and end on diskimage.dd?

8.Use the appropriate program to determine the number of sectors in each cluster of diskimage.dd.

Each cluster of diskimage.dd consists of ________ sectors. [Enter number of sectors.]

9. According to Marko's paper, which TSK program would you use to determine whether there is a Host Protected Area on a hard disk?
Why is this information important from a forensic standpoint?

(Include the page number of Marko's paper where you found this answer.)

10. The following resulted from using bin\mmls.exe image2.dd, with image2.dd being a forensic image of a hard drive:

How many active partitions are on this hard drive?

Explain how you reached this conclusion. (Marko's paper provides an explanation of how partitions are labeled in TSK output.

11.Using the output for Question 10, at what sector does the file system start on image2.dd?

12.Use the appropriate TSK program to the layout and partition information for diskimage.dd. Direct the output to a .txt file. Copy the output into answer.

13. How many active partitions does diskimage.dd contain?

14.Use the appropriate program to find file system statistics for diskimage.dd. What is the cluster size for diskimage.dd?

15.What is the volume label for diskimage.dd? What forensic relevance could the volume label have?

16. Use the appropriate TSK program to view the files on diskimage.dd. Which files, if any, are deleted? Explain how you determined this information.

17. Which file on diskimage.dd is largest? Explain how you determined this information.

18. Use the appropriate TSK program to determine the metadata associated with the file bullies.jpg. When was bullies.jpg created, written, and accessed?

19. At what sectors does the Master Boot Record begin and end on diskimage.dd? Explain how you arrived at this conclusion.

Attachment:- lab.rar

Verified Expert

In this assignment we have studied different types of concept of forensics science.Here we have run different command of different TSK program.Here we have solved the 19th questions.

Reference no: EM132221979

Questions Cloud

Strengths of job descriptions and discern : What are the strengths of job descriptions and discern how those strengths contribute to the overall effectiveness of the descriptions.
Differences between quantitative and qualitative research : What are examples of each and explain how we might use both qualitative and quantitative research methods in the same research project.
What is competitive advantage in strategic management : What is competitive advantage in strategic management? How does a company assess and measure its competitive advantage?
Determine the optimum decision for the toy manufacturer : Determine the optimum decision for the toy manufacturer if he wishes to maximize his total profits.
Examine file system image on virtual desktop infrastructure : Examine the file system image diskimage.dd on the Virtual Desktop Infrastructure (VDI) at Champlain to complete the Lab
The principles of lean to improve performance : Discuss how SHC has used the principles of lean to improve performance.
Win-win means everyone wins equally : Office politics is part of every business. Win-win means everyone wins equally. Exchanging favors is a part of office politics.
The instrumentation and record audit measurements : Discuss with diagrams / sketches how you would set up the instrumentation and record the audit measurements for the following situations:
Describe the phases of team development : Describe the phases of team development. Describe an example where directing leadership is appropriate.

Reviews

len2221979

1/23/2019 10:18:02 PM

I need assistance with the digital forensics questions in the attached assignment. examine the file system image diskimage.dd on the Virtual Desktop Infrastructure (VDI) at Champlain to complete the Week 2 Lab. Thank You

Write a Review

Computer Network Security Questions & Answers

  What sorts of protection is provided by the bank

What sorts of protection is provided by the bank to ensure secure online banking? Justify why the bank would use these security measures.

  Reasonable to compute rsa signature on long message

Would it be reasonable to compute an RSA signature on a long message by first finding what the message equals, mod n, and signing that?

  What type of malware caused danny the problem

Meanwhile, at Danny's Dinosaurs, things are not going very well.  Danny downloaded a game from the Internet, but the game wasn't all it appeared to be. When he ran it, the program actually opened the doors to the velociraptor cage, freeing them in..

  What data or property is threatened and how critical is it

What data or property is threatened and how critical is it? What is the impact on the business should the attack succeed? Minimal, serious, or critical?

  A detailed description of what worms and trojan horses

a detailed description of what worms and Trojan horses

  What steps would you take to implement the given solution

Your employer, Terapin Technologies, a Microsoft-certified solutions provider, has been approached by a local company requesting help them with a project. What steps would you take to implement this solution for the company? Be very specific.

  What is ciphertext generated by encryption of character

A particular cipher is implemented by combining the ASCII representation of plaintext characters with pseudorandom bytes. What is the ciphertext (in binary form) generated by the encryption of the character D?

  Discuss the key data protection points that must be taken

As the CIO of a company engaged in business today, one of the main areas of focus is data protection. Discuss the key data protection points that must be taken into consideration prior to a strategy plan and policy being established for a company ..

  Explain one of the cryptography standards

Imagine that you are explaining encryption standards to a nontechnical audience. Use one of the following to help explain one of the cryptography standards: Flow chart

  Limited management abilities

Originally Linux/UNIX systems had one all-powerful user called root that managed systems and discuss the risks of having a single root user and how more limited management abilities can be given to others users on Linux/UNIX systems.

  Develop a technology proposal - windows network proposal

Describe the technical and business reasons for each choice, citing other resources as appropriate. The Windows Server 2012 operating system should be used

  Describe the need for information security

Describe the need for information security, The potential issues and risks that exist and what benefits they can gain from the new wireless fidelity (W-Fi) project

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd