Professional Documents
Culture Documents
CSOL-590-02-FA18
Abstract
The USD digital forensic team was tasked with determining how data was stolen from the laptop
of Jean Jones, CFO of M57dotBIZ, a start-up web company developing a body art catalogue. To
follow, is a complete computer forensic examination report, documenting our progression and
Timeline of events 6
Conclusion 7
References 8
Contents Page
MODULE 7 FINAL PROJECT – COMPUTER FORENSIC EXAMINATION REPORT 5
A small web start-up company, M57dotBIZ, is developing a catalogue for body art. A few
weeks into the company’s inception, a spreadsheet containing private corporate information and
the personal data of its top executives was found posted to the comments section of a
competitor’s website. This spreadsheet only existed on the laptop of Jean Jones, the CFO of the
company. Jean has indicated the spreadsheet was emailed to company President, Alison Smith, at
Ms. Smith’s request. Ms. Smith has indicated she never requested the spreadsheet, nor did she
The goal of our investigation was to determine if data from the laptop of the CFO was
stolen, and if so, how. In addition, we attempted to establish a timeline of events leading-up to,
and including, exfiltration of the spreadsheet. The tools employed during this investigation were
Guidance Software’s EnCase and The Sleuth Kit’s Autopsy. Encase was used to acquire the
image of the CFO’s laptop, and Autopsy was leveraged to ingest and analyze the data.
MODULE 7 FINAL PROJECT – COMPUTER FORENSIC EXAMINATION REPORT 6
There were several legal questions we needed to address prior to moving forward with our
2. Who is our client, and do they have the authority to approve access to the evidence
a. A first-round funder for the start-up company is our client, and they have the
As it relates to this case, the evidence in question has already been identified, preserved,
and distributed to the forensic team in the form of an EnCase image of the CFO’s PC…which
i. http://downloads.digitalcorpora.org/corpora/drives/nps-2008-m57-jean/nps-2008-jean.E01
i. http://downloads.digitalcorpora.org/corpora/drives/nps-2008-m57-jean/nps-2008-jean.E02
Data obtained from the image files making-up the CFO’s laptop were ingested and
analyzed leveraging Autopsy. The actions taken to carry-out these tasks are documented below:
c. All ingest modules available from Autopsy were run against the image of the
website
ii. M57dotBIZ President, Alison Smith, claims she never requested the
iii. M57dotBIZ CFO, Jean Jones, claims Alison Smith did, in fact, request the
e. Verification of the image file was carried-out leveraging the MD5 hash value
several hits:
discovered
alison@m57.biz
tuckergorge@gmail.com
simsong@xy.dreamhostps.com
manipulation
iii. Confirmation of the original hash value was, once again, verified (below):
value)
MODULE 7 FINAL PROJECT – COMPUTER FORENSIC EXAMINATION REPORT 11
6. Timeline of events
Based on the evidence provided, the following timeline of events is, what we believe to
be, reflective of the events leading to the exfiltration of the corporate data exposed on the
information
response
simsong@xy.dreamhostps.com
2. Reply to = tuckgorge@gmail.com
MODULE 7 FINAL PROJECT – COMPUTER FORENSIC EXAMINATION REPORT 12
called M57biz.xls
tuckgorge@gmail.com
simsong@xy.dreamhostps.com
1. Subject = Thanks!
2. Reply to = tuckgorge@gmail.com
6. Conclusion
Based on the evidence provided, the summary below is what we have concluded occurred
the night of Saturday, July 19, 2008. These events, we believe, would eventually lead to the
a. The email account belonging to M57dotBIZ President, Alison Smith, was spoofed
by a malicious actor
b. Jean Jones was lured into believing a request for confidential corporate
8. References
1. The
Sleuth Kit (2017). Autopsy User's Guide. Retrieved December 6, 2018 from
http://sleuthkit.org/autopsy/docs/user-docs/4.3
2. Guidance Software (2018). OpenText EnCase Forensic. Retrieved December 6, 2018 from
https://www.guidancesoftware.com/docs/default-source/document-library/product-brief/
encase-forensic-product-overview.pdf?sfvrsn=761867a2_34