FTK report
PART I: Familiar with FTK Imager
Bonus Exercise 1 (5 points): Assume that you have a write-protected USB device.
Image a USB device or a floppy disk to create an image in a DD format. (Note: You are not able to use the 841_Win_Forensics_Updated VM to perform this bonus exercise. You have to use your own computer for this exercise).
Provide a snapshot from FTK Imager.
Requires: a USB device or a floppy disk
Launch FTK Imager
Click File > Create Disk Image
Click Physical Drive and Next
Select the device and select Raw (dd) Image Type
Exercise 2: View images
Click File > Add Evidence Item
Select Image file and then click Next
Browse to your WinLabEnCase.E01 image and click Finish
View the image in the Evidence Tree view
Question 1: What is the VBR file used for? How to export this file? How to export a file Hash?
VBR file contain information that will enable client machine to use the remote application . we can export this file by press export , hash file will export as a plain text.
Exercise 3: Convert the WinLabEnCase image to a DD image
Exercise 4: Verify images
Question 2: What are the results of verification? Comparing both hashes, are they same or not?
The verification matched and both hashes are the same
PART II: Working with FTK 1.8x
DETAILED PROCEDURES THAT MAY HELP YOU TO GO THROUGH THE FTK SOFTWARE
Exercise 1: Starting a New Case
Question 3: What information is required to create a new case using the FTK New Case Wizard?
The information needed are : investigator name , address , phone , email , case number , case name , case path , case folder and case destination
Question 4: What are the types of evidence that can be added to a case in FTK?
Image of drive , local drive , folders and individual file
Exercise 2: Working with FTK
Click the OVERVIEW tab; note the numbers for each type of file.
Question 5: How to make the number of the Checked Items to go up? How to make the number of Flagged Thumbnails to go up?
After open each file , items will added to the checked item folder , flagged thumbnails will go up with each file we change the point which down it from red to green .
File Signatures
A file type (JPEG, Word Document, MP3 file) can be determined by the file’s extension and by a header that precedes the data in the file. If a file’s extension has been changed, then the only way to determine its type is by looking at its header.
Question 6: Click on Bad Extension from Overview tab. Do you find any signature mismatch? What are they?
There are 11 files , 8 of them are TMP extension , 1 XLS , 1 PDF and 1 DOC
Data Carved Files:
Question 7: Check the number of Data Carved Files, what is the number?
zero
Question 8: Check the number of Data Carved Files from Overview, how many files added to the case by data carving?
TWO
Question 9: What are those files found by performing data carving process? Why is this process so important?
The files which found are the files with GIF extension , th.
JAPAN: ORGANISATION OF PMDA, PHARMACEUTICAL LAWS & REGULATIONS, TYPES OF REGI...
FTK report PART I Familiar with FTK ImagerBonus Exerc.docx
1. FTK report
PART I: Familiar with FTK Imager
Bonus Exercise 1 (5 points): Assume that you have a write-
protected USB device.
Image a USB device or a floppy disk to create an image in a DD
format. (Note: You are not able to use the
841_Win_Forensics_Updated VM to perform this bonus
exercise. You have to use your own computer for this exercise).
Provide a snapshot from FTK Imager.
Requires: a USB device or a floppy disk
Launch FTK Imager
Click File > Create Disk Image
Click Physical Drive and Next
Select the device and select Raw (dd) Image Type
Exercise 2: View images
Click File > Add Evidence Item
Select Image file and then click Next
Browse to your WinLabEnCase.E01 image and click Finish
View the image in the Evidence Tree view
Question 1: What is the VBR file used for? How to export this
file? How to export a file Hash?
VBR file contain information that will enable client machine to
use the remote application . we can export this file by press
2. export , hash file will export as a plain text.
Exercise 3: Convert the WinLabEnCase image to a DD image
Exercise 4: Verify images
Question 2: What are the results of verification? Comparing
both hashes, are they same or not?
The verification matched and both hashes are the same
PART II: Working with FTK 1.8x
DETAILED PROCEDURES THAT MAY HELP YOU TO GO
THROUGH THE FTK SOFTWARE
Exercise 1: Starting a New Case
Question 3: What information is required to create a new case
using the FTK New Case Wizard?
The information needed are : investigator name , address ,
phone , email , case number , case name , case path , case folder
and case destination
Question 4: What are the types of evidence that can be added to
a case in FTK?
Image of drive , local drive , folders and individual file
Exercise 2: Working with FTK
Click the OVERVIEW tab; note the numbers for each type of
file.
Question 5: How to make the number of the Checked Items to
go up? How to make the number of Flagged Thumbnails to go
3. up?
After open each file , items will added to the checked item
folder , flagged thumbnails will go up with each file we change
the point which down it from red to green .
File Signatures
A file type (JPEG, Word Document, MP3 file) can be
determined by the file’s extension and by a header that precedes
the data in the file. If a file’s extension has been changed, then
the only way to determine its type is by looking at its header.
Question 6: Click on Bad Extension from Overview tab. Do you
find any signature mismatch? What are they?
There are 11 files , 8 of them are TMP extension , 1 XLS , 1
PDF and 1 DOC
Data Carved Files:
Question 7: Check the number of Data Carved Files, what is the
number?
zero
Question 8: Check the number of Data Carved Files from
Overview, how many files added to the case by data carving?
TWO
Question 9: What are those files found by performing data
carving process? Why is this process so important?
The files which found are the files with GIF extension , this
process is very important because it helps the investigator to
4. focus on one type of files which he looking for .
ExploreTab
Checkmark List all descendants.
Question 10: What is the file system of this Image?
FAT 16
Question 11: Right-click a folder and select File Properties,
What information do you get?
Path , file name , system attributes , file source info and file
content info .
Question 12: Select a file, and right-click on that file and select
File Properties, What information do you get?
Path , file name , system attributes , file source info , file
content info and file size .
Question 13: Select Documents and SettingspsmithRecent,
what kind of files contain in this folder? Select each file in this
folder, what kind of information do you get from the up-right
window?
The latest files which open on this machine are on recent file .
We can get information about each file like creation time , last
write time , last access time and what kind of file it is.
Question 14: Select Documents and SettingspsmithLocal
SettingsHistoryHistory.IE5index.dat, what kind of files
contain in this file? Select each file, what kind of information
5. do you get from the up-right window?
We can fine internet explorer daily browsing history , we can
get last accessed time for different websites which opened in
the browser .
Question 15: Select Documents and SettingspsmithFavorites,
what are psmith’s favorite links?
www.monster.com
www.aerospace-technology.com/contractors
www.jsfirm.com/searchcontractors.asp
yahoojobs
as we see the suspect man was looking for a job
Question 16: Looking into the Recycled folder, which files are
currently in the recycler? Select the INFO2 file from the
Recycled folder, what information do you get from that file?
We found 2 files , ogdiagram.gif , tse082800.pdf , in the info2
file we get information about last file which put in the recycle ,
what is the name and the time when the file deleted .
Question 17: Looking into WINDOWSSystem32spool folder,
what information can you get from this folder?
From spool we get information about all the drivers and printers
which install on that machine .
Windows Registry
Locate ntuser.dat from the Documents and Settingspsmith
folder
Export the ntuse.dat; then launch the AccessData Registry
Viewer to include this file in the Registry Viewer. (You may
also right click the file and choose View in Registry Viewer
In the Registry Viewer, explore the list.
6. Action 18: List any interesting results
All the information about registry and all softwares which are
on that machine .
Graphics Tab
The Graphics Tab allows you to quickly see all the pictures in
the case.
Checkmark List all descendants.
You will now see all of the pictures contained on all of the
devices in the case.
Question 19: If a file’s extension has been changed to a non-
graphics file type (such as changing jpg to txt), will it be
displayed in the Gallery view? Provide one example to support
your statement. Does EnCase work in the same way?
Yes it does , and this is an advantage of FTK compared to
encase
Export and Copy Special
Export these five graphics to your desktop.
Question 20: What is the major difference between Export a file
and Copy Special a file?
Export will copy the file to a specific location on the machine
while copy special give us option to copy what we need from
file like file type , modification date and so on.
Keywords and Searching
Searching evidence for information pertaining to a case can be
one of the most crucial steps in the examination. FTK support
two kind of search, indexed and live searches. An indexed
7. search uses the index file to find a search term while a live
search involves an item-by-item comparison with a search term.
The index file could be generated during the creation of a case
or be indexed later.
Question 21: What is the advantage to use indexed search vs.
the live search?
Index search will look inside the files for the needed
information while live search check the subject of each file only
Examining the Options and Import feature in the indexed Search
Question 22: What are these two features used for?
Options need for change search brooding options , search result
options and search limiting options.
Import search in side the files as a text file
Question 23: Do you find any files containing US Phone
numbers? List two files that in the result list.
I found 299 hits in 8 files .
Aviation.htm
Contacts.htm
Email
Question 24: Read the manual and find out what kind of email
formats do FTK support?
FTK now supports the decryption of RSA standard PKCS7
8. S/MIME email items. This
includes support for MBOX, DBX, RFC822, and some PST/EDB
archives
Question 25: Did anything happen? Do you find any important
information? If so, what kind of information you got?
ye s I found a lot of information like that the suspect talk with
someone about meeting and offering him an offer of work
Case Report
After performing a thorough forensic investigation, it is critical
that you are able to publish and present your findings. FTK has
a sophisticated report wizard that allows you to assemble and
publish case information. The final report generated by the FTK
wizard is in HTML format.
Click File > Report Wizard
Fill in the Case information which will appear on the Case
Information page of the report.
Create a report to include the following:
a) all bookmarks and export all bookmarked files
b) Export full-size graphics and link them to the thumbnails
c) Include the Date and Time file Properties for the Bookmarked
Files
d) Include only graphics flagged green in the Graphics View
e) Group 6 thumbnail per row
f) Include Bad Extension files in the report and export the files
to the report along with its data and time property
g) Add one or more of your own file to the report that support
your statement
h) Create a custom graphic for the report.
10. 1
Computer Forensics - FTK
Engineering Computer Systems Management – 767425
Project #1
(Due date: Monday 19 August 2013)
The aim of this project is for you to discover how to use a
spreadsheet to “model” a typical engineering
problem, in this case a heat transfer situation. And to discover
how this model can be used to solve
problems that would otherwise require lengthy analytical or
trial and error solutions. The model can then
be used as a design/analysis tool to try out various “what if”
scenarios.
Hot oil is used as an alternative to steam for providing process
heat in some industries. In our scenario the
hot oil is being pumped to the process equipment through an
insulated pipe and we want to determine the
rate of heat loss per metre of pipe. The pipe is made from mild
steel and is insulated with fibreglass and
clad with stainless steel. Heat is being lost from the stainless
steel cladding surface by convection and by
11. radiation. The initial problem is to determine the heat loss ̇
and cladding surface temperature for
various thicknesses of the fibreglass insulation.
Heat Transfer Situation:
The following data is given:
hot oil temperature,
............................................................ 180°C
steel pipe internal diameter,
..................................................... 80 mm
steel pipe external diameter,
.................................................... 90 mm
pipe length,
................................................................................. nominal,
1 m
inside convection heat transfer coefficient,
............................... 50 W/m
2
°C
14. �̇�
�̇�
�̇� �
At first glance this looks to be a relatively simple problem,
however to solve it we need to find the surface
temperature, before we can find the heat loss, ̇ . To solve
for analytically would require the
solution of a polynomial (quartic) equation. With the
spreadsheet we can solve this fairly easily using a trial
and error approach or using one of the advanced tools available
in Excel to automate this process...
Specific requirements:
You are required to:
using Microsoft Excel, as detailed below.
omments and results
as also detailed below.
1. Spreadsheet Model
Set up your spreadsheet model of the heat transfer situation
with an area for input values (all of the
data given above), an area for intermediate answers (eg radii, ̇
, ̇ , ̇ ), and an area for the
final results, and ̇ . Your model should be set up to be as
15. flexible as possible to produce
answers for and ̇ for a given insulation thickness.
(Imagine other engineers might use your
spreadsheet as a tool for similar heat loss situations, so make it
clear, easy to use and helpful).
In your Report (Word document) :
functions or tools you used, and how
you used them to solve for s and ̇loss for a given insulation
thickness.
Provide a table summarising your results ( and ̇ ), for
the following insulation thicknesses:
25 mm, 50 mm, 75 mm and 100 mm.
2. Further Analysis
Use your spreadsheet model to determine the thickness of
insulation required to give a cladding
surface temperature of say 50°C.
In your Report (Word document) :
3. “What if” analysis
Set the insulation thickness to 75mm and then use your model to
investigate the following “what if”
16. situations (ie what happens to surface temperature, and heat
loss, ̇ if the following changes
occurred).
4 or even 0.8
over a period of time as the stainless
steel became more oxidised?
that the thermal conductivity increased
to a value of say 0.06 or 0.1 W/m°C?
ture increased to 250°C or
decreased to 120°C?
increases to 30°C?
to 12 W/m
2
°C or increases to
50 W/m
2
°C.
to 30 W/m
2
°C or increases to
100 W/m
2
17. °C
In your Report (Word document) :
values and new values of and ̇ and
discuss whether or not you think the change is significant.
main factors that affect the rate of heat
loss for an insulated hot oil pipe like this … (use your results
from the above “What if” analysis).
4. Comments and Conclusion
In your Report add a Comments and Conclusions section and
briefly comment on the following:
this on a spreadsheet compared to
using a calculator and /or hand calculations.
-if”
scenarios?
this on a spreadsheet, and other people
using it?
Note: Marks will also be awarded for layout (of spreadsheet
model) and overall ease of use. Bonus
18. marks may be awarded for additional helpful features…
5. Submit the spreadsheet and supporting document for marking
by 4:00 pm, Monday 19 August 2013,
using AUTonline. Instructions for doing this are provided
below and in the Assessments area on
AUTonline for this paper.
Instructions: How to submit Project #1…..
1. Once you have completed Project #1, log on to AUTOnline
and select this paper: Engineering
Computer Systems Management
2. Click the “Projects” button on the menu
3. Select “Project 1 – Excel Model”
4. Click this item:
5. In the section “2. Assignment Materials”…
and word
document), alongside “Attach File” click
the button and select your Project #1 spreadsheet that you are
handing
in for marking, then click the button. This will attach the file
ready for
submitting.
19. ur Project #1 Word
document (Report) that you are
handing in for marking.
to remove the
incorrect file and then repeat the above steps to add the correct
file(s).
t about your assignment if you wish…
6. Once you have attached the two files you are submitting for
Project #1 then in section “3.
Submit”, click the button to submit the two files to your
lecturer for marking.
7. Once you have submitted your Project you cannot resubmit it.
If you have made an error or
mistake after you have clicked the button you will need to see
your lecturer to reset
your Project #1 account.