https://github.com/sondosaabed/digital-forensics-investigation
This report was written for the Digital Forensics Analysis coursework, specifically the first assignment. In which, steps and screenshots for each investigation process are recorded.
https://github.com/sondosaabed/digital-forensics-investigation
active-disk-editor digital-forensics file-recovery ftk-imager incident-response partitioning virtual-hardisk
Last synced: 8 months ago
JSON representation
This report was written for the Digital Forensics Analysis coursework, specifically the first assignment. In which, steps and screenshots for each investigation process are recorded.
- Host: GitHub
- URL: https://github.com/sondosaabed/digital-forensics-investigation
- Owner: sondosaabed
- License: mit
- Created: 2023-07-17T21:08:52.000Z (about 2 years ago)
- Default Branch: main
- Last Pushed: 2023-07-17T21:25:11.000Z (about 2 years ago)
- Last Synced: 2024-12-25T20:41:57.616Z (10 months ago)
- Topics: active-disk-editor, digital-forensics, file-recovery, ftk-imager, incident-response, partitioning, virtual-hardisk
- Homepage:
- Size: 2.5 MB
- Stars: 11
- Watchers: 1
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
README
# Digital-Forensics-investigation
Digital Forensics investigation using FTK-Imager and Active Disk EditorThis report was written for the Digital Forensics Analysis coursework, specifically the first assignment. In which, steps and screenshots for each investigation process are recorded.
## Summary
Throughout this investigation, the process was divided mainly into 4 sections. The first section is where the programs FTK and Active are introduced and the investigation is overviewed. The second section is concerned with building evidence, a virtual Hard disk drive image, and justifying why it was chosen. The third section presents the creation of a Virtual Hardisk Drive, and its partitions (primary and extended), then deleting two of them. The fourth section is about Evidence and file recovery.## Example Screenshots
- Using FTK Imager
- Using Active Disk Editor
