Running head: LAB 3 REPORT
1
Lab 3 Report
Liberty University
Digital Forensics
CSCI 511
Dr. Jennifer Lee
November 5, 2018
LAB 1 REPORT
2
Lab 3 Report
Lab 1.6 Below is a screen shot showing the Network Information data within Helix
Lab 1.11 Below is a screen shot showing the PC on/off time window found inside the helix
software. This option keeps track of how long a target host has been powered on or
off.
LAB 1 REPORT
3
The PC on/off tool shows that this computer has only been powered on between 900
and 0930 today.
Lab 1.18 The last photo in the S-Tools folder was the image TravelPhoto.bmp, and it was
3164x2112 in size with a depth of 24bit.
LAB 1 REPORT
4
Lab 1.21 Below is a screen shot showing the properties of TravelPhoto.bmp in windows
explorer to fact check the details that were found in Helix. The details were the
same between the two sources.
MeUAcuUsAs
wIyuU/cuE7)
ey
21
We!
0
+
|b
>
ThisPC
»
Storage
(E)
»
S-Tools
Desktop
a
{i
Downloads
=
“Hl
Recent
places
1
Challengebmp
aer
(@
ConfederateCipher.
D2
pole
Desktop
®&
cryptib.at
as
[B
Administrator
&
GiFutit.at
Mt
This
PC
(i
MountRainier.bmp
TravelPhoto
bmp
ik
Desktop
I
StegoMessagebmp
BBtmap
image
Documents
2
S-Tools.exe
E\S-Tools
(B
Downloads
@
S-Tools.hip
7/15/2014
9:47
PM
7/5/2014
(Music
(&
TrevelPhoto.bmp
pe
542
PM
Biri
5
a
a
(i
Videos
|
chibie
om
Ba
Local
Disk
(C2)
BCD
Drive
(0:)
ca
Storage
(E!
peo
WINE3HSLAVAME
the
P)
&
Netwon
nd
Persona
iomaton
®
Control
Pane!
)
Recycle
Bin
+
end
(Zoe)
Cicer]
[te]
UL
Memory
Forensics
LAB 1 REPORT
5
LAB 1 REPORT
6
Lab 1.23 Below is a screen shot displaying the photo TravelPhoto.bmp after being resized to
be able to view the whole document.
deans
meee
Nae
ne
ne
ee
ean
eee
tay
RS
Ep
nr
ee
pee
eee
ne
ree
File
Edit
Event
Filter
Tools
Options Help
6H)
868
|
94@)
m5
|
eB)
a)o\m
Fath
Process
Name
FID
Operation
Resut
Data
a
aiBoplorer.
EXE
1124
i
RezOpenKey
HKLM\Software
\Policies\Microsoft\SQMClient\...
NAME
NOT
FOUND
Desired Access:
Read
1124
RegOpenkey
HKLM\Software\Microsoft\SQMClient\Windows
SUCCESS
Desired Access:
Read
=
1124
i&RegQueyValue
HKLM
SOFTWARE
\Microsoft\SQMClent
\Windo...
SUCCESS
‘Type:
REG_DWORD.
Length:
4,
Data:
0
1124
gi
RegCloseKey
HKLM\SOFTWARE)\Microsoft\
SQMCient\Windo...
SUCCESS
788
fi
RezOpenkey
HKLM
‘SUCCESS
Desired Access:
Maximum
Allowed,
Granted
Access:
Read
788
tit
RegQueryKey
HKLM
‘SUCCESS
Query:
HandleTags,
HandleTags:
(x0
788
fi
RezOpenkey
HKLMASYSTEM)CurrentContro
Set\Services\W3...
REPARSE.
Desired Access:
Read
788
fifReOpenKey
HKLM\System
\CurrentControlSet\Services\W32...
NAME
NOT
FOUND
Desired Access:
Read
788
fk
ReyCloseKey
HKLM.
‘SUCCESS
1124
RegOpenKey
HKLM
Software
Policies
\Microsoft\SQMClient\...
NAME
NOT
FOUND
Desired Access:
Read
1124
RegOpenkey
HKLM\Software\Microsoft\SQMClient\Windows
SUCCESS
Desired Access:
Read
1124
i&RegQueyValue
HKLM
SOFTWARE
\Microsoft\SQMClent
\Windo...
SUCCESS
‘Type:
REG_DWORD.
Length:
4,
Data:
0
1124
@&RReqCloseKey
HKLM\SOFTWARE
\Microsoft\SQMCient\Windo...
SUCCESS
1124
BACloseFile
(CAUsers\Administrator\
App
Data
\Local
\Microsoft..
SUCCESS
1124
BACloseFile
(CA
Users\Administrator\
AppData
\Local
\Microsoft..
SUCCESS
1124
RegOpenkey
HKLM\Software
Policies
\Microsoft\SQMCiint\...
NAME
NOT
FOUND
Desired Access:
Read
1124
RegOpenkey
HKLM\Software\Microsoft\SQMClient\Windows
SUCCESS
Desired Access:
Read
1124
i&RegQueyValue
HKLM
SOFTWARE
\Microsoft\SQMClent
\Windo...
SUCCESS
‘Type:
REG_DWORD.
Length:
4,
Data:
0
1124
i
RegCloseKey
SUCCESS
1124
RegOpenkey
NAME
NOT
FOUND
Desired Access:
Read
1124
RegOpenkey
‘SUCCESS
Desired Access:
Read
1124
i&RegQueyValue
SUCCESS
‘Type:
REG_DWORD.
Length:
4,
Data:
0
SUCCESS
(eae
NAME
NOT
FOUND
SUCCESS
Desired Access:
Read
SUCCESS
‘Type:
REG_DWORD.
Length:
4,
Data:
0
SUCCESS
SUCCESS
‘Thread
ID:
2616,
User
Tine:
0.000000,
Kemel
Time:
0.000000
SUCCESS
Iread
ID:
T88U,
User
line:
U.UDUUOUU,
Keme!
lime:
U.QUDUUUU
SUCCESS
‘Thread
ID:
732,
User
Time:
0.0186250,
Keme!
Time:
0.0312500
SUCCESS
‘Thread
ID:
2528,
User
Tine:
0.0312500,
Kemel
Time:
0,0468750
NAME
NOT
FOUND
Desired Access:
Read
1124
&ReaOpenKey
HKLM\Software\Microsoft\SQMCiient\Windows
SUCCESS.
Desired Access:
Read
16497631b-10F1-Acca-Qdat-c6d39651dea/topology/machine/d5e5268f-749e-43d3-a413-aefSToc95db8/\nc/#
CEIPEnable]
Type:
REG_DWORD,
Length:
4,
Data:
0
LAB 1 REPORT
7
Lab 2.8 Below is a screen shot showing the iexplore.exe process selected in Process
Monitor
LAB 1 REPORT
8
Lab 2.12 Below is a screen shot showing the contents of the FavoritesView software on the
target host.
LAB 1 REPORT
9
Lab 2.15 Below is a screen shot showing the contents of IECacheView after running it on the
target host.
LAB 1 REPORT
10
Lab 2.26 Below is a screen shot showing the contents of IECookiesView after running it on the
target host.
Lab 2.32 Below is a screen shot showing the contents of MyLastSearch after running it on the
target host.
LAB 1 REPORT
11
CQ 4.1 Below is a screen shot showing Hahn_WinAuditChallenge.pdf saved in Storage (E:)
CQ 4.2 While reviewing the WinAudit report from the target host, the following errors were
LAB 1 REPORT
12
discovered:
Application Errors- Software Protection Platform Service- License Activation
Failure and End User License Failure
System Errors- NetBT, server, and DCOM errors that were associated with a
conflicting/duplicate IP Address.
LA 1 Helix is an incident-response tool that is able to gather system information, create
system images for analysis, browse and scan local machine files and pictures, and is
able to document and record incident details. (Jones and Bartlett Learning, LLC.,
2014). This makes evidence gathering faster and less complex than having to
perform all these steps manually.
LA 2 Process Explorer can be used to monitor and track actual executables and
applications loaded and running on a computer to include viruses and other
malicious software. It can also help build a baseline definition for workstations and
servers to be used for comparison in a forensic examination, assisting an investigator
by helping them locate compromised system files. (Jones and Bartlett Learning,
LLC., 2014). Process Explorer can also enable someone to view the command line of
a process so you can understand what is launching the process possibly uncovering
malware or a logic bomb. Finally, the most useful thing about Process Explorer is
the Find command, which enables an investigator to locate a process much faster
than scrolling through a possible endless list of processes.
LAB 1 REPORT
13
LA 3 MyLastSearch is a tool used to view recent searches on a target host. MyLastSearch
collects Internet search queries made by a user on search engines such as Google,
Yahoo!, and Bing, as well as most social networking sites such as Facebook,
LinkedIn, Pinterest, and Twitter. The data can be sorted, copied, and saved to a text,
HTML, or XML file. (Jones and Bartlett Learning, LLC., 2014).
LA 4 IECacheView is able to assist a forensic investigator in many ways by reading and
displaying Internet Explorer’s cache folder for any user logged on to the local
machine and by listing all currently stored file types without looking at the cookies.
IECacheView enables the user to filter, copy, and paste the information into other
document formats such as Excel. (Jones and Bartlett Learning, LLC., 2014). Along
with the totality of the evidence uncovered, this would enable to investigator to
better understand the intent of the target user/suspect.
LA 5 The difference between data and evidence is easily explained using one
consideration; all digital evidence is comprised of data but not all data can be used
as evidence. The data uncovered in this lab is unfiltered and must be combed
through and used with consideration against the suspected crime to reveal which
sets of data can be admissible as evidence.
For example, if someone is suspected of using their computer to send phishing
emails which resulted in a financial loss to multiple victims, their browser history
LAB 1 REPORT
14
may be a good place to look for circumstantial evidence, but if nothing uncovered
from their history indicated that they were searching for ways to engineer malware,
then all that data from browsing history is just that, data. On the contrary, if it is
discovered that their browser history is rift full of searches for different phishing
techniques, then along with more concrete evidence, that data can be admitted as
evidence that, although circumstantial, would represent furtherance and intent.
LAB 1 REPORT
15
References
Jones and Bartlett Learning, LLC. (2014). Cyperpath Lab (Version Lab 2) [Computer software].
Retrieved November 1, 2018, from
https://jblcourses.com/webapp/BLTI/MainFrame.aspx?
hpath=https://jblcourses.com/Lab/kim_Lab14.html