You are a digital forensics intern at AAA Computer Forensics, a privately owned forensics investigations
and data recovery firm. It’s a Friday morning and your manager calls you with good news. He tells you
that he is very happy with your performance and has a big task lined up for you. He also mentions that if
you do this task well, you will be hired as an employee in this company. You are thrilled! With a big grin,
you ask, “What’s the task?”
Your manager tells you that AAA Computer Forensics is working with Corporation Techs, a company that
has been struggling to maintain its customer base due to fierce competition with rival firm NetTech24x7. A
disgruntled former employee of NetTech24x7 approached the owner of Corporation Techs with a tip that
Corporation Techs’ internal strategy memos, customer lists, and other sensitive documents were being
Findings
IS4670 course textbook, System Forensics, Investigation, and Response (Vacca, 2011)
IS4670: Project: Investigate Evidence and Create a Report of the
passed along to a NetTech24x7’s sales manager. The former employee of NetTech24x7 claims that the
files were being downloaded from Corporation Techs’ Web site, but she did not know which specific folder
was being accessed. Corporation Techs is now concerned that sensitive internal documents might be
accessible to its competitor. It is also possible the disgruntled former employee is lying and only wants to
learn about potential security holes in the Corporation Techs network. Therefore, the CEO of Corporation
Techs has hired AAA Computer Forensics to conduct an informal investigation before involving law
enforcement or regulatory agencies.
A thorough search of the Web site has been conducted, and no files were found beyond the static HTML
Web pages expected. Three workstations are used to update content on the Web site, and a network
packet trace has been captured for traffic between the workstations and the internal FTP upload site for
posting data to the Web server. This packet trace is available for your use.
Once you understand the situation, your manager tells you to divide the investigation into three parts. The
first part involves the use of NetWitness Investigator to identify user credentials, correlate source host
address(s), and evaluate network traffic for unusual activity that might provide a starting point for your
system forensic investigation. In the second part, you will use Paraben P2 Commander to examine a
forensic system image and evaluate files, communications, and applications, which could be items of
potential evidentiary value in this investigation. You will use your findings from the first part of the
investigation to guide your selection of workstation(s) for review and user profile(s) for specific
investigation. In the third part, you need to document your results along with the investigative process and
any indicators you discovered that led to additional actions on your part. The investigation must be limited
to the scope identified by these indicators, and all investigative actions should be supportable if you are
called as an expert witness in later proceedings.
Findings
IS4670: Project: Investigate Evidence and Create a Report of the
Part 1: Review Packet Capture
Tasks
Perform the following steps:
1. Review demo labs and research the Internet and ITT Tech Virtual Library to find detailed
information on NetWitness Investigator.
2. A free download of the software is available in case you want to experiment with how the program
behaves, looks, and feels.
3. Examine how to access packet trace data using NetWitness Investigator.
4. Examine how to identify hosts within the Corporation Techs network, conducting FTP file
transmissions with the organization’s Web server.
5. Document how to develop a listing of user credentials and transferred files associated with each.
6. Report how to identify potential hosts and users whose activities warrant further investigation.
7. Document the process used to identify every indicator that provides cause for further
investigation.
Write the preliminary investigation document detailing the tasks mentioned above. This document should
include dates and details of the investigator to serve as supportive documentation for your investigation
later. All documentation should be made using a standard word processor format compatible with
Microsoft Word.
AAA Computer Forensics
Check your essay before you submit. See exactly what your professor sees.
See your AI and plagiarism results before your instructor does.Get the exact same report your professor uses. Trusted by 50,000+ students worldwide.
AAA Computer Forensics
Welcome to one of the most trusted essay writing services with track record among students. We specialize in connecting students in need of high-quality essay writing help with skilled writers who can deliver just that. Explore the ratings of our essay writers and choose the one that best aligns with your requirements. When you rely on our online essay writing service, rest assured that you will receive a top-notch, plagiarism-free A-level paper. Our experienced professionals write each paper from scratch, carefully following your instructions. Request a paper from us and experience 100% originality.


