Discussion questions!

profileRoss_$
5discussionquestions.docx

Discussion 1

"Data Recovery"

In a few sentences, describe some first and important steps you would use to verify a MD5 checksum of downloaded software. Are there tools built into the operating system that will check the MD5 sum? Can you recommend a website with MD5 checkers as a potential resource? Share with your classmates, and provide links to any useful resource you find.

Additional post option: What would happen if you downloaded new software, and confirmed that the MD5 value does not match the site? What steps would you take to resolve this issue?

Discussion 2

"Hard Drive and File Systems"

In your labs you were introduced to three tools, WinHex (http://www.winhex.com/winhex/hex-editor.html), The Sleuth Kit and Autopsy (https://www.sleuthkit.org/). In a few sentences, describe a scenario when you might find a use for each of these tools. Is one tool preferred more than the others in this industry? Why do you think learning these tools is important? Using the Internet, recommend a website or video that provides a tutorial on how to best use one of the three tools? Share with your classmates, and provide links to any useful resource you find.

Additional post option: In your research, are there any other tools that can be used to perform the same tasks? Have you used them? Do you like them better or not as much?

Discussion 3

"Operating Systems (OS)"

Everything we do with a computer leaves a footprint. In a few sentences explain any tools you have learned about which are included in the Microsoft Windows Operating system to review these digital marks. If you haven’t found any, do some research and return here before posting your initial reply. What are your favorite tool(s) that are Linux-based allow us to monitor processes in a Linux System? How do you think the information collected from these tools assist us in a malware case? Can you recommend any other tools, either within the OS, or from the Internet that can be used to explore events and logs? Share with your classmates, and provide links to any useful resource you find.

Additional post option: In Linux, how much information can be gained from viewing the BASH history?

Discussion 4

"Obfuscation"

What do you believe was the original purpose of steganography tools, and how have criminals used them to their advantage? Share some steganography tools you’ve found on the web with your classmates, and provide links to any useful resource you find. Describe in a few sentences how you might use these tools for good, and how they might be used for nefarious purposes.

Additional post option: Search the Internet and find a FREE steganography tool, post your link and provide a brief explanation on how the tool is used

Discussion 5

"Investigating a Hard Disk"

In a few sentences discuss why you think it might be important to make a backup image of a hard disk to work from, instead of using the original drive. What built in Microsoft or third party tool(s) can be used to make a drive backup? Do you have a favorite? What recommendation for a command or tool for a Linux machine would you make to create an exact copy of a partition or drive? Share with your classmates, and provide links to any useful resource you find.

Additional post option: Are there any open source tools you have experience with that can be used to make a backup image?