SLP-Digital Forensics and Information Security
SLP- Digital Forensics and Informational Security
For this SLP, the object is to review digital hardware tools for performing forensic analysis of digital information in a small organization. The tools should be able to copy the contents of a hard drive, find and recover files deleted from a hard drive, determine history of web sites visited, search a computer’s hard drive for key words, compare contents of files on the computer’s hard drive, copy contents of other storage devices, and log the activities performed.
Here are some tools to evaluate: AccessData FTK Imager AccessData Forensic Toolkit EnCase ProDiscover DFF, https://tools.kali.org/forensics/dff
Once you have explored two of the tools, answer the following questions in 3-4 pages:
· Provide a brief description of the tool and what it is supposed to do
· Explain how it might help forensic operations in finding evidence for digital crimes
· Describe the possible advantages of using this tool
· Describe the possible drawbacks of using this tool
· Provide an example of its application.
Background Readings:
Incident Response Plan by Skillset.com https://www.youtube.com/watch?v=PhROeWMPBqU
All things Entry Level Digital Forensics and Incident Response Engineer DFIR https://www.youtube.com/watch?v=Cst8K64j5_Y
Gregory, P. H. (07/24/2019). CISM®: Certified information security manager all in one McGraw-Hill. Chapter 5
Harris, S., & Maymi, F. (2018). CISSP all-in-one exam guide, 8th edition, McGraw-Hill, Chapter 7 Skillsoft Material
Automating Incident Response and Forensics https://www.youtube.com/watch?v=f_EcwmmXkXk
Memory Acquisition in Digital Forensics and Incident Response https://www.youtube.com/watch?v=UgfIV4Q042k
Maras, Marie-Helen (2015). Computer forensics. Jones and Bartlett Learning, Chapters 10 -14. ISBN:9781449692223. Available in the Trident Online Library.
Johnson, L. R. (2014). Computer incident response and forensics team management: Conducting a successful incident response. Syngress Publishing. SBN:9781597499965, Chapter 10-16. Available in the Trident Online Library.