E-design is a medium enterprise design

profileSuperClass
 (Not rated)
 (Not rated)
Chat

Last week, each student has designed a CASE for other students to investigate. Each student should have posted the following two items of his/her case for this week:

 

  1. A case description.

     

  2. Acquired disk images.

     

This week, you need to investigate at least two cases designed by other students. You need to find the evidence and make a detailed report. Please try to be as professional as possible in your report. That is, you are assumed to present the evidence in court and the defending attorney may ask you all kinds of questions to invalidate

your evidence.

 

Case#1:

Case Study

 

 

E-design is a medium enterprise design company creates many types of inventive designs such as cockpit, headlight, rear light, especially for car manufacturer companies. The company has recently started to notice anomalies. One of the car manufacturer, which is E-design’s good customer for a while has informed E-design they have decided not to work with them. They claim that E-Design sells the same design to other companies as well. E-design finished creating the car cockpit design a few months ago, which will be using the new model of 2016’s cars. However, it has been noticed that the cockpit design of another manufacturer’s new car is almost same (even sizes match with the design) with the E-design’s design.

 

IT Team of E-Design has been tasked to perform an initial check of log files. IT Team has noticed that many suspicious entries, large amount of data being sent from the IP Address of an internal user outside the company firewall. However, the file names and extensions in log file.

 

The company has decided to investigate the computer of suspected IP address and the all storage devices including floppy drive, USB flash memories, SD Cards, external hard drives , CD/DVD’s and all mass storage devices of the user of this computer so that to make sure the sender of designs and secrets of the company, find out if there are any other designs sent to outside (Each design team can only access their own design and there is only 3 people who can access all designs. The users of this computer is one of 3 people) and if there is any malware injected to the company’s computers.

 

Since the company has a small of IT Team (8 people), but they do not feel comfortable to carry out a forensic investigation, the company has hired a digital forensic investigator.

WinHex tool has been used to image the suspected disk. The image file has been attached to this post.

 

MD5 Hash: 8AE6FDEA6AB815E4D72560B3C8A16B8B

Regards,

Koray

 

Case#2:

Pinto´s Case for Investigation

# 1- In Luanda city there are a very intensive nightlife during the weekends and holidays where the young people are lost in the night ballads to have fun in the clubs as well as in the house parties.

The house parties are usually organized by group of people who hire a DJ, the buy drinks and prepare foods, and make advertisement on the radio stations and television broadcast for promotion and sell the party invitations. The same applies to the party in the nightclubs. Many of these parties in nightclubs there are abuse of drinking alcohol and many other things; in the nightclubs mostly visited by tourists and Western foreigners, some young people put drugs on the girls’ drinks to take advantage of the effects of excessive alcohol and the drugs.

The girls were taken to the beach late at night and were violated and left there over.

One of the girls made the participation to the police; during the investigation, one of the suspects was picked by surprise in his apartment when the detectives of the criminal investigation were knocking the door of suspect house, he immediately deleted all the photos he had downloaded to the computer that contained evidence that could incriminate him.

The detectives did search the whole house, and took the suspect's laptop to the laboratory of the local police agency to perform the collection, examination, and analysis of data to find digital evidence related to the illegal drug possession, kidnapping and sexual violation.

 

# 2 for this exercise please see compressed file attached, I have used the Elite Unzip software because it worked well with my Windows 8.1 Operating System.

# 3 In this case we need to find on the disk image some digital evidence such as deleted photographs of the girls that were taken together with young people in the disco and any other images that can be related to the crime described above that can help the computer forensic investigators to clarify the crime in the court. The materials that were deleted from the computer are mostly files containing photos type jpg. I have deleted 2 files and have renamed one file with extension .jpg to extension .doc

Reference,

Elite Unzip Software available at: http://downloadzipfree.com (accessed: 4 February 2015)

 

File MD6WK4Project.Zip (43.216 KB)

 

</pclass="msonormal">

    • 10 years ago
    E-design is a medium enterprise design A+ Tutorial use as Guide
    NOT RATED

    Purchase the answer to view it

    blurred-text
    • attachment
      e-design_is_a_medium_enterprise_design.docx