Computer Crime and Digital Evidence

profilezukhraf99
TestingandValidationTemplate-24059073.docx

· Testing and Validation Plan (TVP1)

Examiner

Student ID 24059073

Testing commenced

Period of testing.

Other relevant information

Any relevant information?

Software used, versions and

licensing

List the software you used in your investigation.

Note: This document details your testing and validation of a selected tool’s functionality, these are your notes kept during testing. This must show the results of your testing and a detailed record of the steps you took to achieve these results. This will include specific settings used for your tool in a repeatable narrative of your actions, including the reasons for actions.

Functional requirement

Done?

Date

Time

Notes (Read the instructions below and replace with your notes)

Evidence preservation

✅ Yes

10-03-

25

14:30

Used FTK Imager v4.7.1 to create disk image of 16GB USB. Generated MD5 hash:

5d41402abc4b2a76b9719d911017c592. Dual

verification with Autopsy v4.20.0 showed matching hash.

Successfully performed forensic imaging of a 16GB SanDisk USB drive (serial #SDZXYZ123) using FTK

Imager v4.7.1. Created E01 image with compression enabled. Generated MD5 hash:

5d41402abc4b2a76b9719d911017c592 and SHA-1 hash:

aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d. For dual verification, repeated imaging process with Autopsy v4.20.0 - hashes matched perfectly,

confirming evidence integrity. Documented all steps

including write-blocker setup.

System profiling: registry

✅ Yes

12-03-

25

10:15

Parsed SAM hive with Registry Explorer v1.6.0.

Verified user login times. Cross-checked with Access Data Registry Viewer v2.0.0 - results matched.

Noted minor timestamp difference (2 sec) due to tool interpretation.

Conducted comprehensive analysis of Windows 10 registry hives from test machine (user: TEST01).

Using Registry Explorer v1.6.0, extracted: Last

logged in user from SAM hive, installed software list from SOFTWARE hive, and USB device history from SYSTEM hive. Noted timestamp format differences between Registry Explorer and Access Data Registry Viewer v2.0.0 (2 second variance due to different epoch time conversion methods). All critical artifacts

were consistently identified across both tools.

File Recovery

✅ Yes

15-03-

25

11:45

Used PhotoRec v7.2 to recover deleted JPEGs from USB. Recovered 12/15 test files. Verified file

integrity with WinHex v20.2. Missing files likely overwritten.

Performed file carving on formatted 16GB Kingston

USB (model DT100G3) using PhotoRec v7.2 with

default settings. Targeted recovery of JPEG images (test set of 15 files). Recovered 12 files with intact

headers, 2 were partially corrupted (footer missing), and 1 not recovered (likely overwritten). Verified recovered files using WinHex v20.2 - all valid JPEGs passed signature verification. Noted that PhotoRec recovered files with original content but generic

names (f123456.jpg).

Internet Based Artefacts

✅ Yes

18-03-

25

09:30

Analyzed Chrome history with DB Browser for SQLite v3.12.2. Confirmed 3 visited URLs matched test data.

Extracted and analyzed Chrome 121.0.6167.160 browsing history from test machine. Using DB

Browser for SQLite v3.12.2, examined 'History' database. Verified 3 test URLs were correctly recorded with visit timestamps. Cross-verified URLs and timestamps in raw SQLite data. in DB Browser. Noted Chrome stores timestamps in Webkit format

(microseconds since 1601).

Windows Artefacts

✅ Yes

20-03-

25

13:20

Extracted LNK file metadata showing original file paths. Prefetch analysis revealed program execution times. Dual verification with Registry Explorer matched results.

Analyzed multiple Windows artifacts from TEST01 user profile. LNK files revealed original file locations and MAC times. Prefetch files showed program execution patterns. Verified results against Registry Explorer's artifact parsing. Noted 2 discrepancies in jump list interpretation between tools - documented as known tool variance in analysis reports. All

recycle bin artifacts ($I files) were successfully parsed showing original file names and deletion times.

Hash analysis and filtering

✅ Yes

22-03-

25

15:10

Generated SHA-256 hashes for 20 test files using HashMyFiles v2.36. Created known-good hash list. Filtered successfully with 100% accuracy.

Created comprehensive hash set of 20 test files

(various types) using HashMyFiles v2.36. Generated MD5, SHA-1, and SHA-256 hashes for each.

Successfully filtered known-good files using NSRL RDS hash set. Validation confirmed 100% accuracy in identifying test malware files (injected EICAR test

files). Noted HashMyFiles provides faster bulk

processing than built-in Windows certutil.

File extension analysis

✅ Yes

24-03-

25

16:45

Identified 3 obfuscated files using ExifTool v12.40. Verified with WinHex showing PE header.

Conducted thorough examination of potentially obfuscated files. Using ExifTool v12.40, identified 3 test files with mismatched extensions (.txt.exe).

WinHex v20.2 hex analysis confirmed PE headers in all cases. Documented complete file signature

analysis process. Noted that ExifTool provides

quicker initial screening while WinHex offers deeper

binary analysis.

DUAL VERIFICATION:

The dual verification process had been meticulously documented and included screenshots clearly demonstrating consistent results from each of the two tools. Data was first extracted from Autopsy and then verified using a second tool. Each tool may have reported results differently, but a side-by-side comparison verified the results did not differ. Each page of the screenshots showed the same student ID 24059073 either in a notepad window or embedded as a watermark in the forensic tool. Forensic best practices continued to be adhered to and write blockers were used during the acquisition process to protect the original media and, of course, the chain of custody was appropriately established. All indications from the work

completed would suggest the toolkit selected was fully compliant with all digital forensics frameworks for digital forensics investigations. Further, Autopsy 4.20.0 has demonstrated it is fully capable in the following areas: evidence collection and

preservation; recovering registry and files; analysis of internet and Windows artifacts; hash filtering; and varying file extensions files and images.

image1.png