Questions Relevant Guidelines For Forensic Investigations

Improved Essays
Questions Relevant to the Case

Things to keep in mind for the forensic investigation for this case:
• To identify the malicious activities with respect to 5Ws (Why, When, Where, What, Who).
• To identify the security lapse in their network.
• To find out the impact if the network system was compromised.
• To identify the legal procedures, if needed.
• To provide the remedial action in order to harden the system Relevant Guidelines for Initial Preparation

Before starting the investigation, I need to prepare in order to conduct the investigation efficiently. The following steps are needed to take in the preparation stage:
• Gathering all available information from the assessing the incident, such as severity of the incident.
• Identifying
…show more content…
Forensic imaging will be created by forensic tools such as FTK. FTK imager will help to preserve the original data as evidence without any changes in data which occurred during the investigation. I will use a write blocker to connect to the target system and copy the entire contents of the target drive to another storage device by using the forensic tool FTK imager. I will use a hard drive to clone the entire system. The hard drive cloning contains only a raw image, and every bit will be copied, and no other extra content will be added. Forensic imaging contains timestamps and it compresses all the empty blocks (Nelson, B., et al., …show more content…
After the disk is imaged, the hash values will be recorded in multiple locations and I will ensure that I do not make any changes to the data from the time of collection of the data till the end of the investigation. Target System Hard drives, External Storage devices, and the Windows NT Server Hard drive must be acquired for the digital forensic investigation in this case.
Examination of Data
Once I have gathered all the available evidences, there will be a need to conduct the examination by the help of various computer forensic investigation tools. I will also examine the file system, Windows registry, Network and Database forensic examination. File System Examination
The Master File Table (MFT) which contains information about all files and disks is the first file in the New Technology File System (NTFS). The files stored in MFT can be found in two (2) ways: resident and non-resident.
When a file is deleted in Windows, the file will be renamed by OS and moved it to the Recycle bin with a unique identity. The OS stores information about the original path and original file name. But if a file is deleted from the Recycle bin, then associated clusters are marked as available for new data. NTFS disks are a data stream, which means they can be added into another existing

Related Documents

  • Improved Essays

    The Forensic response readiness plan is for the Greiblock Credit Union to able to collect, preserve, protect and analyze digital evidence so that this evidence can be effectively used in any legal matters, in disciplinary matters, in an employment tribunal or court of law. It will also prepare the GCU organizations to measures that they can respond to incidents effectively, timely and efficiently. Define the business scenarios that require digital evidence. Greiblock Credit Union needs to take a look at the hazard and potential effect on the organizations from the different kinds of cyber crimes.…

    • 505 Words
    • 3 Pages
    Improved Essays
  • Superior Essays

    The use of forensics in criminal investigations is to establish possible guilt or innocence of the potential suspect, linking crime between the suspect…

    • 1469 Words
    • 6 Pages
    Superior Essays
  • Improved Essays

    DEA Forensic Analysis

    • 525 Words
    • 3 Pages

    At times, there are certain cases where investigators run into dead ends or obstacles depending on the circumstances at hand. As in this case of the kidnapping and murder of special agent Enrique Camarena and Captain Alfredo Zavala, the DEA and forensic investigators faced many hurdles. The processing of significant evidence was constantly put to a halt. The DEA and investigators were unable to do things in the way that they wanted to. This put them through many challenges and hurdles in the investigative process.…

    • 525 Words
    • 3 Pages
    Improved Essays
  • Great Essays

    1. The individuals I believe that ought to be interviewed for this investigation are Mr. McBride, Mr. Jenkins, Mr. McBride’s co-workers, and the forensic expert(s) who examined the evidence. Mr. McBride is innocent till proving guilty of taking “Product X” from Greenwood and his statement should be gathered accordingly. Mr. Jenkins statement would also need to be gathered to collect information as to how he came to believe Mr. McBride potentially stole the information and what the consequences would have been if obtained by competitors.…

    • 1217 Words
    • 5 Pages
    Great Essays
  • Decent Essays

    In paragraph eight, it states this. “But one thing is certain. Forensic evidence is static. Because unless the criminal takes something away from the crime scene, hard evidence doesn't leave.” Forensic evidence is the most…

    • 337 Words
    • 2 Pages
    Decent Essays
  • Improved Essays

    In order to establish an effective forensic readiness plan in the private sector, three major requirements need to be fulfilled. The first requirement is appropriate technology. Technology is critical in helping the organisation obtain evidence, preserve and protect…

    • 843 Words
    • 4 Pages
    Improved Essays
  • Improved Essays

    Bloodstain Patterns

    • 651 Words
    • 3 Pages

    Physical evidence that is left behind in a crime scene plays and important role in reconstructing the various events that took place during the crime . Crime scene reconstruction depends upon joint efforts of law enforcement personnels, medical examiners and criminologist to find the physical evidence and to understand the events that surrounds the occurrence of a crime. If there is a bloodstains then the location and the distribution of the blood stain along with the spatters maybe useful in explaining the events that caused the bleeding. An investigator can decipher from an individual bloodstain, the direction of blood, when it impacted the surface it was deposited on. Bloodstain patterns, consisting of many individual bloodstains…

    • 651 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Unit 2. Question 3: What are the similarities and differences between the investigation of criminal homicides and the investigation of criminal assaults? Homicides and criminal assaults although different by definition, contain many fundamental similarities particularly in regards to the circumstances leading upto the crimes and the process in which they are investigated. A homicide, or murder, is defined as the illegal killing of a person by another person.…

    • 505 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    The use of scientifically derived and proven methods toward the preservation, collection, validation, identification, analysis, interpretation, documentation, and presentation of digital evidence derived from digital sources for the purpose of facilitating or furthering the reconstruction of events found to be criminal, or helping to anticipate unauthorized actions shown to be disruptive to operations.…

    • 657 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Throughout many centuries, it has always been important to know how and why crimes have been committed. Criminal Investigators have participated in solving countless of cases in order to prevent future crimes. Many victims and those accused, which are known to be innocent, have been assisted to receive justice due to the help from the system. This job profession is just as important as any others in the federal justice system. Forensics investigation is a standard scientific application to criminal investigations, also an execution to law procedures ensuring evidence to present in court.…

    • 1540 Words
    • 7 Pages
    Improved Essays
  • Improved Essays

    2. After conducting a detailed exploration about the facts related to the case, the following are the details that gathered in a step by step manner: shooting left a 12-year-old dead and a 14-year-old injured in San Bernardino. 3. Pros and cons of Apple unlocking Farooq’s…

    • 701 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    All of the evidence collected at a crime scene is digitally stored, meaning it is saved for as long as the investigator needs it and can use it at a later date to continue the investigation. Officers that do not use it can lose any evidence at a scene forever.…

    • 652 Words
    • 3 Pages
    Improved Essays
  • Great Essays

    Using layman’s terms, explain laws and legal concepts that should be taken into account during the collection, analysis, and presentation of evidence. Investigators should tend to any hardware and software very cautiously because any and all evidence is crucial to the investigation. Investigators should keep any information especially private information regarding Mr. Oliver secret unless needed for question, or verification. Clients should keep the investigation a secret for confidentiality reasons and try as much as possible to avoid press. Others should come forward if they have any information potentially viable to the…

    • 711 Words
    • 3 Pages
    Great Essays
  • Improved Essays

    The CSI will walk through taking notes on anything needed for the investigations, things such as fingerprint dusting kit, or blood spatter. After it is noted on what equipment is needed, the true heart of the investigation process beings. “Trace evidence is any material such as hairs, fibers, glass, soil, paint, etc., found at a crime scene on a person or object.” This evidence is then used to help find out more information about the crime committed, such as who was there. When finding the trace evidence it is important the following steps are completed: the written down location, the amount collected, the type of material, the condition of the material, and proper packing to help transport the trace evidence to the lab.…

    • 1708 Words
    • 7 Pages
    Improved Essays
  • Improved Essays

    There are multiple stages of the criminal court process that create a burden of proof that contribute to criminal justice investigations. Every court process begins with a crime allegedly committed to determining its legal status. Law enforcement and detectives determine if the crime was illegal or legal due to the investigations. They investigate a crime by interviewing victims, witnesses, and suspects. They also gather physical evidence by taking pictures, fingerprint, and DNA samples.…

    • 1283 Words
    • 6 Pages
    Improved Essays