What email client was domex1 using and who was the third person he was conversing with?

computer science

Description

Using DFF (Digital Forensics Framework) Due date: September 11, 2019 at 6:25 pm Purpose: 

To introduce an open source application for collecting digital evidence. This lab will focus on basic methods employing an operating system tree structure. Application location: Virtual Computing Lab: FTK 5.0 / Windows 7 Preparation: Review the Lab 1 PowerPoint slides Evidence file: nps-2009-domexusers.aff (located in Forensic Data folder on VCL desktop) Questions to answer: 

1) What type of file system is Partition 1? 

2) After viewing the file structure of the partition, what is the operating system? Hint: look in data attribute window. 

3) After parsing the x86 partition, extract the word document titled “This is a word document sent by domex user 1” and list the information in the document. 

4) What email client was domex1 using and who was the third person he was conversing with? 

5) What are the account names that have logged onto this system? 

6) After customizing the attributes, list the accessed, altered, and creation date of the file “This is a spreadsheet by domex user 1”. 

7) One of the accounts has a picture in their folder. Describe this picture or include a copy. 

8) Give the file type and name of all deleted Office files found. What was their creation date? 


Related Questions in computer science category