diff_months: 21

SIT703 Advanced Digital Forensics Innvestigation Report Assessment

Download Solution Now
Added on: 2022-08-20 00:00:00
Order Code: 9_19_5667_123
Question Task Id: 57589
  • Subject Code :

    SIT703

Task 1 (Scanning the machine)

To ensure that Arif’s machine is free of rootkit programs which may alter the investigation results, he decides to run a thorough scan on his investigation machine to ensure that there is no rootkit program. Choose at least two scanning programs and provide the screenshots of the scanning results.

Task 2 (Repairing Windows Logs) 

Having ensured the safety of his forensic investigation platform, Arif decompresses the file “Desktop.zip” and finds 4 Windows event log files. Describe the information stored in each log file and repair those important log files so that they can be viewed in Windows EventViewer.

Task 3 (Which account is created)

Having repaired the log files, Arif examines one of them in order to identify which account was created without Amy’s consents. Which log file and which EventID number should Atif search? Provide a screenshot for the account-creation event.

Task 4 (Where is Amy’s password)

Having identified the event that a new user was created on Amy’s laptop, Arif telephones Amy and asks whether she can provide more clues. Amy tells that she has a personal password safe as an encrypted ZIP file hidden on the university network, the link is at https://www.deakin.edu.au/~zoidberg/SIT703/2019/secret.zip . But Amy is confident that only she can access her account details because this password safe has multiple security protection mechanisms. However, Arif wants to demonstrate that Amy’s belief may be too optimistic. Provide screenshots and describe how Arif can easily access Amy’s account information.

Task 5 (Amy’s password)

Arif has extracted Amy’s password safe, but he wants to demonstrate to Amy that her Windows password can be easily cracked. So he calls Amy and Amy bets that he cannot get her password. Being challenged and authorized, Arif decides to crack Amy’s Windows password used on her laptop. Work out what the username and the password are on Amy’s laptop.

Task 6 (When did things go wrong?) 

Amy now realizes that Windows provides a very weak protection and she becomes concerned about the safety of her research data. Arif decides to look through the log files again in order to identify when the bogus account logged on to Amy’s laptop. Use two screenshots to indicate when the bogus account was logged on and logged off.

Task 7 (I know what you did)

Arif believes that he can find all important activities on Amy’s system during the session time identified in Task 6. Which event recorded in the system log file will tell Arif about the actions performed by the bogus account? When did this event terminate?

Task 8 (Using LogParser)

Arif recalls that some events with EnventID 11728 are closely related to the installation of Windows programs. He decides to use the program LogParser to search for the events with EventID 11728 in the log files. List all the events Arif will find by using LogParser (screenshots are required).

Task 9 (The valuable Registry)

Arif feels that things might be very serious, so he decides to go through the Registry file “Server.reg” in the “Desktop.zip” file. What program(s) will Arif classify as suspicious? Provide strong reasons.

Task 10 (Before calling the police)

Arif and Amy feel that they must report to the police about their findings. Before they write a formal complaint to the forensic team, Arif recalls that he has intercepted an NTLM authentication session of user “helpdesk” and the hash is: 3520EFAAD3850A27AAD3B435B51404EE:13C1E98BECA440FADC09F3D24670EA72 Arif guesses that the password is 3 characters long but contains special symbols. Now, crack this password by using your own rainbow tables (screenshots are required).

  • Uploaded By : Katthy Wills
  • Posted on : September 12th, 2018
  • Downloads : 2
  • Views : 834

Download Solution Now

Can't find what you're looking for?

Whatsapp Tap to ChatGet instant assistance

Choose a Plan

Premium

80 USD
  • All in Gold, plus:
  • 30-minute live one-to-one session with an expert
    • Understanding Marking Rubric
    • Understanding task requirements
    • Structuring & Formatting
    • Referencing & Citing
Most
Popular

Gold

30 50 USD
  • Get the Full Used Solution
    (Solution is already submitted and 100% plagiarised.
    Can only be used for reference purposes)
Save 33%

Silver

20 USD
  • Journals
  • Peer-Reviewed Articles
  • Books
  • Various other Data Sources – ProQuest, Informit, Scopus, Academic Search Complete, EBSCO, Exerpta Medica Database, and more