Cyber Forensics and Incident Response (ICT600)
Cyber Forensics and Incident Response (ICT600)
Final Assignment
Groups Name: _______________________
Group members: _______________________
Total mark: _______________________
Sections Yes/No/Partially
(Y/N/P) Marks Awarded
A. Discuss if there is there any evidence of illegal drug activity (Methamphetamine). Explain your position on this. What evidence did you find if any? How sound / reliable do you believe your evidence collection to be?
[0-15 marks]
1 Discuss if there is there any evidence of illegal drug activity (Methamphetamine). Explain your position on this. (/5) 2 What evidence did you find if any? (/5) 3 How sound or reliable do you believe your evidence collection to be? (/5) Detailed comments:
B. Present any evidence in a timeline format, signposting the points where you believe any offence may have occurred and other significant dates/times in the case. Compare any evidence found and timeline information side by side with the different tools available to you (e.g. ProDiscover/ OSFOrensics/ FTK Imager) and highlight any differences. Be sure to state the pros and cons of using one tool over the other.
[0-15 marks]
1 Present any evidence in a time line format, signposting the points where you believe any offence may have occurred and other significant dates/times in the case. (/5) 2 Compare any evidence found and timeline information side by side with the different tools available to you (e.g. ProDiscover/ OSFOrensics/ FTK Imager) and highlight any differences. (/5) 3 Be sure to state the pros and cons of using one tool over the other. (/5) Detailed comments:
C. You were provided with two sets hard drive images. Are there any differences between them, considering they are purported to be of the same computers? What do you think has occurred here? What are the differences between the sets of the drive images? Which images do you think are the originals and why? How do you think the sets of drive images were created?
[0-15 marks]
1 You were provided with two sets hard drive images. Are there any differences between them, considering they are purported to be of the same computers? (/3) 2 What do you think has occurred here? (/3) 3 What are the differences between the sets of the drive images? (/3) 4 Which images do you think are the originals and why? (/3) 5 How do you think the sets of drive images were created? (/3) Detailed comments:
D. A common defence is that the actions were committed unintentionally or that the perpetrator did not know the actions were illegal. With these possible defences in mind, address how you would respond to these defences. Are there any clues that indicate intent or knowledge of criminal activity?
[0-10 marks]
1 A common defence is that the actions were committed unintentionally or that the perpetrator did not know the actions were illegal. With these possible defences in mind, address how you would respond to these defences. (/5) 2 Are there any clues that indicate intent or knowledge of criminal activity? (/5) Detailed comments:
E. Conduct some research into ways that image files (graphic images) could be tampered with. Are there ways that are undetectable, or difficult to detect? Present your findings in a short section written in a formal referenced style. You are only expected to have approximately 5 references (good quality: reputable journal or conference papers).
[0-10 marks]
1 Conduct some research into ways that image files (graphic images) could be tampered with. (/5) 2 Are there ways that are undetectable, or difficult to detect? Present your findings in a short section written in a formal referenced style. You are only expected to have approximately 5 references (good quality: reputable journal or conference papers). (/5) Detailed comments:
F. Referencing and Formatting [0-15]
1 Quality references [minimum 3] (/5) 2 Consistent formatting, captioning all figures/tables and explaining all throughout the main content (/5) 3 Cover Page, Table of Contents and Executive summary (/5) Detailed comments:
G. Methodology [0-10]
1 Explaining all tools and the process of examining images with references (/10) Detailed comments:
H. Summary and Appendix [0-10]
1 To be relevant to the main content, accurate findings (5 marks each) Detailed comments:
Total Mark out of 100: Late penalty 10% marks per day (regardless of the hours)
Over 10% of word limitation- 10% penalty Total Mark with late penalty