Professional Documents
Culture Documents
- If you were not able to delete the volume in the Disk Management tool, you will need to use
the Diskpart command line tool to clear the portable hard drive:
Q1: What is the name and size of your partition? Name: NEW VOLUME (Q:) Size: 127 MB
Section B:
- Once the partition has been created, open Notepad and create a simple txt file (Your
name.txt) and type “This is the test.”, and save it to the partition.
Q2: What is the name and size (KB) of the text file that you generated? Name: Steven_Tran.txt Size:
1KB
- After saving it to the partition, find the file in the partition and delete it.
Part 2: Using Imaging Tools
Data Dump:
- Navigate to the Piazza’s Resources and download the dd.exe file located under “General
Resources”.
- Once downloaded, open a command prompt and navigate to the location of dd.exe.
- Enter “dd --list” to see a list of all available partitions, and find which partition is the one you
just created. (You can usually tell by the drive letter.)
- Enter in “dd if=\\.\x: of=c:\Users\user\Desktop\$$.img bs=1M --size --progress” where “x” is
the drive letter of the partition, “$$” is the image name, and “user” is the user you’re logged
in as. This should create a raw image file and save it to the Desktop.
FTK Imager:
- Open up FTK Imager and go to File -> Add Evidence Item.
- Select “Logical Drive” and the partition that you had created.
- Once opened, go to File -> Export Disk Image.
- Click to add an image destination and select E01 for the image type.
- Enter some text for the fields in the Evidence Item Information and click Next.
- For the Image Destination folder, select the Desktop, and type in a file name.
- Once everything is entered click “Finish” and then “Start” on the next screen.
Name: 002.E01
Checksum: 66ada344eb436d0e224a97e696c6b58fff0294d8
Part 3: Using Autopsy
- Launch Autopsy from the desktop
- Click on New Case, type your case name (ex. 001).
- Choose your Base Directory. (ex. Desktop)
- Click on Next. And use case number 001 and fill out the name of the examiner. Click on
Finish.
- Adding data source (images). Click on Disk Images or VM File. Click on Next, click on
Browse. Choose the image you made, Click on Open and Next to finish.
- Go ahead and select Data Sources. Click on the plus sign, click on the plus next to image name
(ex. cse469.e01), select any volume, and you can see the files inside that volume.
- X marks mean that the files have been deleted
Q5: Try to extract (export) the file you deleted to the Desktop. List the files that you recovered.
Q6: Try to find all the files that contain a text “test”. List the all date/time and the contents of the file.
Q7: Try to auto-generate a report. And attach the snapshot of the first page.