1

Subject: Computer forensics Q) Summarize where data of interest to a forensic investigator would reside in...

Question

Subject: Computer forensics Q) Summarize where data of interest to a forensic investigator would reside in...

Subject: Computer forensics

Q) Summarize where data of interest to a forensic investigator would reside in Linux systems. Discuss a tool that would be used to extract that data during an investigation.

Answers

The data of interest to a forensic investigator resides in hard disk,running processes, open network sockets and network connections, DLL's loaded for each process, cached registry hives, process IDs, and more of linux system.

Linux is an open source operating system that is installed in personal computer,super computer,servers etc.Linux having many file systems such as ext2, ext3, and ext4. The file system provides an operating system with a way to data on the hard disk.The file system also identifies how hard drive & device stores forensics data.The data of interest to a forensic investigator resides in these file systems on the hard disk of Linux systems.Data and file recovery techniques for these file systems include data carving, slack space, and data hiding. The important feature of OS forensics is memory forensics, which incorporates virtual memory, Linux memory, memory extraction, and swapping. The Forensic investigators should analyze the following folders and directories.

/etc [%SystemRoot%/System32/config]

This contains system configurations directory that holds separate configuration files for each application.

/var/log

This directory contains application logs and security logs.

/home/$USER

This directory holds user data and configuration information.

/etc/passwd

This directory has user account information

Digital forensic investigation required tools to extract desired data from the devices.
  
Followings are the tools used for digital forensic investigation

1. Forensic Toolkit for Linux:

Forensic investigators use a forensic toolkit to collect evidence data from a Linux Operating System. The forensic toolkit contains many tools such as Dmesg, Hunter.O,DateCat,Insmod, NetstatArproute and NC.

2. Helix:
Helix is the distributor of the Knoppix Live Linux CD. It provides access to a Linux kernel, hardware detections, and many other applications.

3. Volatility:
The memory analysis is the most important for digital investigations. Volatility is an memory forensics framework for incident response and malware analysis which allows to extract digital artifacts from volatile memory dumps such as RAM.The Volatility can extract information about running processes, open network sockets and network connections, DLL's loaded for each process, cached registry hives, process IDs, and more.


Similar Solved Questions

2 answers
Let U={u,n,i,t,e} A={n,i,t} B={n,e} C={u,n,i,t,e} D={u,e} Find each of the following: (a)A(with upside down horseshoe)B (b)C U D (c)D (with line over the D) show solution
Let U={u,n,i,t,e} A={n,i,t} B={n,e} C={u,n,i,t,e} D={u,e}Find each of the following:(a)A(with upside down horseshoe)B(b)C U D(c)D (with line over the D)show solution...
1 answers
OM in the News: The Productivity Challenge AUGUST 12, 2016 by Barry Render tags: Productivity, U.S....
OM in the News: The Productivity Challenge AUGUST 12, 2016 by Barry Render tags: Productivity, U.S. economy Plunging Productivity Gains in US worker productivity have slowed dramatically since the early 2000s, a trend that could restrain the economy's future growth Labor productivity (output per...
1 answers
Arrange the elements according to first ionization energy. Highest ionization energy Lowest ionization energy Answer Bank...
Arrange the elements according to first ionization energy. Highest ionization energy Lowest ionization energy Answer Bank Li Na K RD...
1 answers
Inventory for a manufacturing company includes raw materials, work in process, and finished goods. Inventory for...
Inventory for a manufacturing company includes raw materials, work in process, and finished goods. Inventory for a merchandising company includes goods primarily in finished form ready for sale. In a perpetual inventory system, inventory is continually adjusted for each change in inventory. Cost of ...
1 answers
2. Calculate AS for the conversion of10g of supercooled water at -10°C and 1.00 atm to...
2. Calculate AS for the conversion of10g of supercooled water at -10°C and 1.00 atm to ice at -10°C and 1 atm. Cp for supercooled water = 1.01cal/g; for ice Cp-0.5cal/g and the latent heat of fusion is 333.6J/g....
1 answers
176 Chapter 21 Chapter Assignment Sheets CASE STUDY r City Health Care, attends to patient p...
176 Chapter 21 Chapter Assignment Sheets CASE STUDY r City Health Care, attends to patient p Veronica Hernandez, a medical assisting extern at Inne examinations under the supervision of clinic manager is careful to follow all infection control methods during patient lthough Ver arilyn Johnson, CMA (...
1 answers
M13 SPR (4) SPM Axle (2) T889SPM (8) The M13 Bill of Material is given here....
M13 SPR (4) SPM Axle (2) T889SPM (8) The M13 Bill of Material is given here. The table below shows your current inventory levels of each item. Item Quantity Axle SPM 396 SPR T889 8 How many additional units of SPM are needed to make 75 M13s?...
1 answers
I need help filling this out for my Microbiology class.. please Respiratory effects Virulence factors (if...
I need help filling this out for my Microbiology class.. please Respiratory effects Virulence factors (if detailed in book) Skin or eye effects Organism Category / Biology Acanthamoeba Aspergillus Bacillus anthracis Bordella pertussis Candida albicons Respiratory effects Viru...
1 answers
3- (25 points) Assume you are using a list of dictionaries to store information about different...
3- (25 points) Assume you are using a list of dictionaries to store information about different cars. Write a Python script that uses lambda function to sort this dictionary out based on the price of the cars. For example: cars = [ {'make':'Acura', 'year':2019, 'model'...
1 answers
7) Please create a phylogenetic tree (cladogram) of these major deuterostome groups of animals. At each...
7) Please create a phylogenetic tree (cladogram) of these major deuterostome groups of animals. At each branch node, indicate the trait (or traits; or presence/absence) that you used to divide the groups. I know space is tight, but please write as legibly as you can! (11 pts; 1 pt each for node desc...
1 answers
Tipton Company manufactures shirts. During June, Tipton made 1,.200 shirts and gathered the following additional data:...
Tipton Company manufactures shirts. During June, Tipton made 1,.200 shirts and gathered the following additional data: 囲(Click on the icon to view the data.) Read the ecuirements. 7. Calculate the direct materials cost variance Select the formula, then enter the amounts and compute the cost v...
1 answers
Correction of Improper Cost Entries
Plant acquisitions for selected companies are presented below and on the next page.1 Natchez Industires Inc. acquired land buildings, and equipment from a bankrupt company, Vivace Co., for a lump-sum price of $680,000. At the time of purchase,Vivace's assets had the following book and appraisal ...
1 answers
Please help to answer these questions Please identify 3 critical points and write it up in...
Please help to answer these questions Please identify 3 critical points and write it up in a word document for Seizure precaution Client safety...
1 answers
Problem 2: Figure shows a pump and pipe network being used to transport heptane at 80F...
Problem 2: Figure shows a pump and pipe network being used to transport heptane at 80F to a large, elevated storage tank that is closed, but vented to ensure that the pressure above the hetane is atmospheric. The volumetric fiow rate of the heptane is 400 gpm. (a) Determine the pressure drop (psi) t...
1 answers
Professor Halfbrain has a night skewed data set He wants to find a transformation that will...
Professor Halfbrain has a night skewed data set He wants to find a transformation that will make the data approximately normal Ho produces the flowing Box Cox plot -17900 -17950 log-Likelihood -18000 Which -18050 - 18100 suggest he try? Y-log(x) or=x? or rx...
1 answers
Googl. G sbagov. Google S perfecting Baket O 21 Easy ways to ln. 囿Bakrt!Trangl u bekstre...
Googl. G sbagov. Google S perfecting Baket O 21 Easy ways to ln. 囿Bakrt!Trangl u bekstre rwh re R Mende thing len a ie,eMate gnment FULL SKIN PRINTER VERSION ·BACK Is a t-Distribution Appropriate? A sample with size n - 12 has -7.6 ands -1.6. The dotplot for this sample is given below....

-- 0.034801--