Acquiring-Forensic-Evidence-computer-science-homework-help
Acquiring Forensic Evidence
New Content: Acquiring Evidence
This will be 2–3 pages of new content.
Complete the following:
- Download this forensics tool.
- Note: You will have to register to be able to download the tool, but it is free.
- Create an image.
- Once installed, go to File and select Create Disk Image. You may use any media for this (e.g., USB stick, CD, external hard drive)
- Note: This will go much faster if you choose small size media (e.g., a small flash drive).
- Follow through the Wizard to create the copy of your evidence.
- When the Create Image window appears, click Add. For image type, select E01.
- You can leave Evidence Item Information blank, but you would fill it in for a real case.
- Select your image destination folder and file name.
- When you return to the main Wizard window, click Start.
- Once the copy is created, look for the text file saved to the same location, and ensure that the hash files are verified (that you have an exact copy).
- Once installed, go to File and select Create Disk Image. You may use any media for this (e.g., USB stick, CD, external hard drive)
- Analyze the image.
- Go to File and select Add an Evidence Item.
- Select the Source of Evidence, and follow through the Wizard to acquire your evidence.
- Click here to view a 15-minute video to assist you with the installation and use of this forensics software.
Include the following in your Electronics Management Plan:
- Describe what you found by answering the following questions:
- What did you see on the media (evidence) that you used before you acquired it in the forensics tool?
- How did you verify that your acquisition was an exact copy of the original?
- What did you see when you used the forensics tool?
- What were the differences?
- What did you learn about that media?
- Use screen captures to illustrate your explanation.