investigation 04 | Computer Science homework help

Purpose

In this assignment, you will examine a volatile memory dump to investigate a potential malware case. Your analysis will primarily be done with Volatility Workbench, but you may also use other utilities to look at the disk from other perspectives. In Autopsy, the evidence can be imported as an Unallocated Space image to run intake scripts. Be sure to make a note of all applications and methods you use in your examination.

Instructions

You’ll need to use the following resources to complete the assignment:

  • Investigation 04 Sample Evidence*
  • Volatility Workbench*
  • (Optional) Download and use the report template (See the Investigation and Forensics Challenge module for the templates)
  • (Optional) StringsLinks to an external site.
  • (Optional) Autopsy the open-source forensic suite* (or another suite, such as EnCase or FTK.)

*Accessed via the Virtual Lab.

After reading the Investigation 4 Scenario, open your forensic tool and import the sample evidence into the case. Begin a forensic report to document your examination.

Scenario

This scenario takes place circa 2010.

Company X has contacted you to perform forensics work on a recent incident that occurred. One of their employees had received an email from a fellow co-worker that pointed to a PDF file. Upon opening, the employee did not seem to notice anything. However, recently they have had unusual activity in their bank account.

Company X was able to obtain a memory image of the employee’s virtual machine upon suspected infection. Company X wishes you to analyze the virtual memory and report on any suspected activities found.

Questions

  1. What specific indicators in the memory image indicate possible malicious activity?
  2. Is there any evidence of malware execution or persistence mechanisms in the memory image? 
  3. Is there any evidence of privilege escalation or unauthorized access to the memory image?
  4. Is there any evidence of memory-resident malware or rootkits that could avoid traditional detection methods?
  5. Was there any sensitive information, such as credentials or financial data, has been accessed or altered within the memory image? 
  6. Are there any unusual processes or applications running in the virtual machine’s memory during the suspected infection?
  7. Does the sender have any other unusual activities? 
  8. What were the processes that were running on the employees computer? 

Format

You can submit your forensic report in Adobe PDF format. It should be a complete report. A template has been provided if you need help, but be aware that not all sections shown in the template will be relevant to this investigation:

  • Upload one file (PDF).
  • Your forensic report should include a cover page and a page dedicated to answering the accompanying questions at the end.
  • You may include screenshots or other evidence to support your conclusions, but a screenshot is not a shortcut to a complete report.

Grading and Submission

In brief, I’ll be evaluating you on the following:

  • Forensic Reporting
  • The report is complete and contains only the truth.
  • Examination Process
  • Your examination is fully documented and uses accepted practices.
  • Identifying Evidence
  • While you are not expected to find every relevant evidence item, you should discover enough to adequately support the conclusions in your report.
Place your order
(550 words)

Approximate price: $22

Calculate the price of your order

550 words
We'll send you the first draft for approval by September 11, 2018 at 10:52 AM
Total price:
$26
The price is based on these factors:
Academic level
Number of pages
Urgency
Basic features
  • Free title page and bibliography
  • Unlimited revisions
  • Plagiarism-free guarantee
  • Money-back guarantee
  • 24/7 support
On-demand options
  • Writer’s samples
  • Part-by-part delivery
  • Overnight delivery
  • Copies of used sources
  • Expert Proofreading
Paper format
  • 275 words per page
  • 12 pt Arial/Times New Roman
  • Double line spacing
  • Any citation style (APA, MLA, Chicago/Turabian, Harvard)

Our guarantees

Delivering a high-quality product at a reasonable price is not enough anymore.
That’s why we have developed 5 beneficial guarantees that will make your experience with our service enjoyable, easy, and safe.

Money-back guarantee

You have to be 100% sure of the quality of your product to give a money-back guarantee. This describes us perfectly. Make sure that this guarantee is totally transparent.

Read more

Zero-plagiarism guarantee

Each paper is composed from scratch, according to your instructions. It is then checked by our plagiarism-detection software. There is no gap where plagiarism could squeeze in.

Read more

Free-revision policy

Thanks to our free revisions, there is no way for you to be unsatisfied. We will work on your paper until you are completely happy with the result.

Read more

Privacy policy

Your email is safe, as we store it according to international data protection rules. Your bank details are secure, as we use only reliable payment systems.

Read more

Fair-cooperation guarantee

By sending us your money, you buy the service we provide. Check out our terms and conditions if you prefer business talks to be laid out in official language.

Read more