Bharani Sankar Website

Home > Project Page

Project Page

I am enrolled in Dr. Lau's ISYS 377 Cyber Forensics! 

Class Description:

This is a fundamental required course as part of an interdisciplinary curriculum that is very much in demand in today's society. This course covers cyber forensics as part of one of the    three academic areas in the interdisciplinary curriculum. The three areas covered are cyber security, cyber forensics, and cyber policy and law. This class covers methods and tools for gaining forensic information from computer systems and networks.  It includes case studies of cyber crimes as well as the application and management of cyber forensics.  The course introduces students to forensics tools using hands-on experience and the Internet. 

(This description was from the http://www.longwood.edu/business/56873.htm)

This class is great and it gives me great insight on what the Forensics side of Computer Systems entails. I was able to learn a lot of how different programs could be used to extract vital information for the authorities when it comes to finding information. I hope that I can use some of the skills I learned from projects in the class and apply it to a potential internship or job.

Here is a description of a project we did using FTK which was written by Dr. Lau

) Identity File Metadata using FTK Demo

         - Start Microsoft Word, and in the new document, type Student's Full Name (On line 1); Instructor's Full Name (On line 2); insert a reasonably sized photo of yourself (below the 2nd line); type, By creating a file, you can identitfy the author with file metadata (Below the picture).

         - Hide the instructor's full name and your photo.

         - Save the file as InChp05-01.docx to your work folder. Close the word file.

         - Open FTK

         - Click GO DIRECTLY TO WORKING IN PROGRAM, and then click OK. Click FILE, ADD EVIDENCE from the menu.

         - In the add evidnce dialog box, enter your name as the investigator, and then click NEXT. In the evidence processing options dialog box, accept the default stiing, and then click NEXT.

         - In the main add evudebce to case dialog box, click the ADD EVIDENCE button. In the next add evidence to case dialog box, click the INDIVIDUAL FILE option button, and then click CONTINUE.

         - In the browse for folder dialog box, navigate to your work folder, click InChp05-01.docx, click OPEN, and then click OK. Click NEXT, and then click FINISH.

         - In the main window, click the OVERVIEW tab, if necessary. Under the file category heading, click the DOCUMENTS button. Click to select the InChp05-01.docx file in the bottom pane; its contents are then displayed in the upper-right pane.

         - On the file list toolbar at the upper right, click the VIEW FILES IN NATIVE FORMAT button, if the button isnt already selected.

         - Next, click the VIEW FILES IN FILTERED TEXT FORMAT button. If you enetered your usernname and organization when you installed word, that information is displayed. 

         - Exit FTK.   

 

Author: BharaniVyas Sankar
Last modified: 4/29/2015 1:13 PM (EDT)