You are tasked with investigating a compromised system suspected of a security breach. During the investigation, you realize that certain commands are required for deeper analysis.
Task 1:
Install a Kali Linux machine and VMware on your desktop/PC, and record the installation process. Upload the recording.If already installed, open and use the software, and upload the recording.
Answer the questions in the Evidence File, include your name, and upload it.
The Cyber Crime Unit of City receives a report of suspicious activity on a corporate laptop, which is believed to have been used to access unauthorized files from the company's server. The company suspects internal fraud, as critical financial documents have been tampered with. The forensic team is called in to investigate the case and identify any digital evidence that could support the claims. You are tasked with creating a forensic image of the laptop to preserve the data for further analysis.
Task 2:
Download FTK, install it on your system, and create a forensic image of the evidence to ensure data integrity during the investigation.​
You have been provided with a forensic image of a suspect’s hard drive, created using AccessData FTK Imager, as part of an investigation into a cybercrime. The goal is to examine this image for digital artifacts that could link the suspect to unauthorized access of a secure network.
Task 3:
Upload the screenshot showing the Hash values of the Forensic Image.
A law enforcement agency has brought in a digital forensic expert to recover critical evidence from a compromised laptop. The laptop belonged to a suspect involved in a high-profile financial fraud case. The device was subjected to a deliberate attempt at data destruction. The agency needs to retrieve deleted files, emails, and financial records for their investigation.
Task 4:
Perform data recovery on the evidence, download the evidence and then move it to an external drive(such as pendrive). Delete the file from the external drive and then recover the file. Upload the Screenshot of the recovered file.
A design firm suspects that a former employee has stolen proprietary designs and shared them with a competitor. Investigators are tasked with analyzing the metadata of files to uncover evidence of unauthorized copying and distribution. Key points include identifying file creation, modification, and access times, as well as any changes to ownership metadata.
Task 5:
You are tasked with conducting a metadata analysis on evidence suspected of being involved in the design theft. Upload the report of metadata analysis
A global technology firm suspected a data breach and engaged a forensic expert to investigate suspicious emails. The emails, believed to be from unknown sources. The expert needs to identify forged email headers and timestamps, confirming any signs of intentional tampering.
Task 6:
Your task is to track and analyze the email to identify the region and city from where the mail was delivered.
A multinational company suffered a ransomware attack that encrypted all its critical files. Initial investigation revealed that the attacker gained access through an employee's compromised credentials.
Task 7:
Your task is to test whether the password and username in the evidence file could be captured using Wireshark.
A medium-sized e-commerce company, recently suffered a cyber attack where customer payment information was compromised. The attackers spread a malicious link along with some genuine links.Â
Task 8: Your task is to investigate the domain and website associated with the link. Upload a screenshot which indicates whether the link is safe to use or not.
A multinational corporation, suspects that one of its employees has been leaking sensitive proprietary data to a competitor. IT security team discovered suspicious image files on the employee's workstation. The files appear to be innocuous at first glance, but the security team suspects that steganography has been used to hide confidential data within the image files. They have asked for a thorough forensic analysis to confirm the presence of hidden information.
Task 9: Check whether the evidence contains any encrypted message or not. If the image contains a message, upload a screenshot of the message.
A healthcare organization reported a breach of patient records, with sensitive data appearing on unauthorized platforms. Initial findings suggested the breach originated from a doctor’s compromised mobile device, which had access to the organization's electronic medical records system.
Task 10:
Your task is to create a case in autopsy and examine the evidence. Upload a screenshot of information you find about the evidence.
A law enforcement agency discovered leaked classified investigation reports on an underground forum. Initial investigations pointed to a detective’s mobile device, suspected of unauthorized access and sharing of the sensitive files.
Task 8: Your task is to generate a report in using the autopsy tool of the evidence.
As a forensic professional working in a forensic lab, You were as assigned to examine a case. The digital evidence provided for examination included the employee’s laptop, a USB drive, and an email archive.
Task 9: Prepare a comprehensive forensic report detailing the acquisition, analysis, findings, and conclusions of any evidence that you have worked on.