Professional Documents
Culture Documents
Criminal story:
The office of personnel management, OPM for short, can be considered the US
government’s HR Department. Among other things, it keeps records of employee personal
information, such as height, weight, hair and eye color.
The OPM got hacked, and the information of 22 million government employees
leaked, most likely in the hands of a foreign government and the information related to
employees are deleted which is great loss and time consuming to collect the data from each
employee. This problem can be solved by recovering deleted data using ProDiscovery basic.
Chapter 1:
INTRODUCTION
ProDiscover Incident Response allows a forensics search through the entire disk for
keywords where regular expressions and phrases with full Boolean search capability to find
the necessary digital information which is stored on digital device. Hash comparison feature
can be used to find known illegal files or known-good files, e.g standard operating system
files, by utilizing the included Hashkeeper database from the external sources. ProDiscover
Incident Response is having best forensics search capability & it very fast and flexible,
allowing a keyword search for words or phrases anywhere on the disk which includes the
slack space.
Chapter 2:
FEATURES OF PRODISCOVER
Chapter 3:
1. Select save project option from the file menu, or button bar.
2. ProDiscover presents file Save As dialog if the current project has not yet been saved,
otherwise
the current project file will be updated without further action.
3. Select the project file to open and click Open button.
4. ProDiscover opens the project file and generates a template report in the work area.
5. Select the Add Disk option from the action menu, or tree-view.
Chapter 4:
Recover Deleted Files
7. ProDiscover displays the contents of the selected file at the bottom of the main window.
➢ files that have been deleted, or were erased will be shown with a red-x
8. Right click on a file that you want to create a copy of the file.
9. ProDiscover a pop-up dialog with the choice to View or Recover the selected file. Select
Copy File.
10. Enter the desired location and file name to save the file as in the "Save As" dialog box
that appears and click "Save".
Chapter 5:
Adavantages and Disadvantages
Advantages of ProDiscover
• Provide compressed or uncompressed image files
• No size restriction for disk-to-image files
• Provide space in the image file or segmented files for metadata
• Simple design with extensibility
• Internal consistency checks for self-authentication
Disadvantages of ProDiscover
• Inability to share an image between different tools
• File size limitation for each segmented volume
Chapter 6
CONCLUSION
1. Digital forensics is important for solving crimes with digital devices, Against digital
devices, against people where evidence may reside in a device
2. Several sound tools and techniques exist to search and analyze digital data
3. Regardless of existing tools, evolving digital age and development of technology requires
heavier research in digital forensics.
To solve OPM related problem that is to recovery the data of employee which is
deleted can be done using ProDiscovery basic efficiently with lesser time.
This tool gives a general idea of how to create a disk image file, hash the file, write
block the file, and perform a first-level analysis of the disk image in a Windows
environment. This is the basis of any digital forensics investigation. Knowing these basics
will enable you to focus on learning more involved and advanced aspects of digital forensics.
Chapter 7
REFERENCES
• http://nest.unm.edu/files/8113/9251/5519/Tutorial_4_-_FTK__ProDiscover_-
_Viewing.pdf