Dr. Bill Pugh IS 3513 Information Assurance & Security Lab Assignment Instruction Set Image retrieved from: medium.com Lab created by

Dr. Bill Pugh
IS 3513 Information Assurance & Security
Lab Assignment Instruction Set
Image retrieved from: medium.com
Lab created by Naveen Bommu, Graduate Student, UTSA MSIT

OVERVIEW

This lab exercise will introduce you to digital forensics and how it helped solve the infamous

“BTK Case.” There are many digital forensics tools, but in this exercise, you will be using

Autopsy to investigate a “floppy image file” collected from the perpetrator known as “BTK.”

American serial killer Dennis Rader, known as the BTK killer, murdered 10 people, including two

children, over a 17-year period. The BTK killer was active from 1974 to 2005. In 2005, BTK

provided the police a floppy disk with a “test” note, and from there the police later discovered

hidden metadata revealing the eventual identity of the “BTK” killer. This lab is a walkthrough of

the steps law enforcement used to capture this notorious serial killer.

More info:

OBJECTIVE

Given the following instructions, complete the deliverables and submit your results for credit.

RESOURCES

• Computer, or laptop computer meeting College of Business, Information Systems & Cyber

Security Majors specifications:

• Autopsy Software (Available for Windows, OS X)

• Internet access for uploading assignment to Blackboard

EVALUATION

Your grade will be based on meeting the following criteria within the scheduled deadline:

• Downloading and installing the Autopsy software with screenshots (10%)

• Answering ALL the questions contained in the “Instructions” AND provide screenshots

showing your work (30%)

• Provide feedback on the lab exercise with a minimum of a 500-word, single spaced, 12 pt.

font report on your experience, highlights, and suggested improvements for the lab (60%)

INSTRUCTIONS

• Download the latest Autopsy Software version (Available for Windows, OS X) from the

website: download/

• Download the image file named “btkcase.ima”.

• Once you have downloaded the files, follow the instructions below:

download/

Autopsy download page.

Click “Download” (Current version is now 4.20.0)

Select “Next”

Select “Next” then select “Install.”

Select “Finish.”

Now open the autopsy software and select “New Case.”

Provide the case name of your choice and the directory you want. Click “Next.”

You can ignore the below information and select “Finish.”

Select “Next” here.

Select “Disk Image or VM File” to input the image file, then select “Next.”

Select “Browse,” then in the “Files of type:” field, select “All Files” then click “Next.”

Keep the selected “ingest modules” and select “Next,” then “Finish.”

At the home page of Autopsy, you can see the image file is successfully loaded. Now, expand

the “Deleted Files” section, then click on “File System,” then click on the “Agenda Church

Council Meeting.docx” file.

Then below, select “Data Artifacts.”

QUESTION 1: Whose name appears next to “Owner?”

Next, expand “Data Sources,” then “btkcase.ima_1 Host,” then btkcase.ima,” then

“$CarvedFiles,” then click on “f0000000.docx.” Click on the right-side frame, click on

“image1.png.”

QUESTION 2: What does the image show?

Next, as you are discovering important clues from this floppy disk, you quickly go to the

internet and search for the organization shown in the picture . . .

But . . . it isn’t 2005 so you now must go “back in time” to the web page as it was in February of

2005 here:

QUESTION 3: Do you see anyone on the page with the first name found above in “Data

Artifacts” and “Owner?” What is his name?

Share This Post

Email
WhatsApp
Facebook
Twitter
LinkedIn
Pinterest
Reddit

Order a Similar Paper and get 15% Discount on your First Order

Related Questions

CASE STUDY: FEDERAL/STATE/LOCAL COLLABORATION NETWORKS IN DISASTERS Please address each of the following

CASE STUDY: FEDERAL/STATE/LOCAL COLLABORATION NETWORKS IN DISASTERS Please address each of the following questions related to federal-state-local collaboration during disasters.  Support your analysis using peer-reviewed journal articles, textbooks, PowerPoint presentations, and research from textbooks and journals.  Integrate a Biblical perspective within the analysis State the theory first and then apply

WRK100 – PREPARING FOR THE FUTURE OF WORK Name: Professor Name:

WRK100 – PREPARING FOR THE FUTURE OF WORK Name: Professor Name: Date: Week 3 Assignment – Reflecting on Your Skills, Goals, and Experiences Overview In this assignment, you will fill in the assignment template to reflect on your values, strengths, areas of improvement, and experiences. This will prepare you for

Choose TWO of the following passages: Genesis 3:1-7; Exodus 14:1-12; Leviticus 16:29-34; Numbers 14:11-19; Deuteronomy 30:15-20, and provide a one-page

Choose TWO of the following passages: Genesis 3:1-7; Exodus 14:1-12; Leviticus 16:29-34; Numbers 14:11-19; Deuteronomy 30:15-20, and provide a one-page interpretation of the passage for each based on what you have learned/acquired from the previous assignments performed for this course. As part of this presentation, a clear and concise principle

First, create an outline or concept map that summarizes your communication plan for a significant organizational change or event. Consider the following

First, create an outline or concept map that summarizes your communication plan for a significant organizational change or event. Consider the following examples: a new company branding initiative; the restructuring of a team, department or business unit; a company-wide community service project; the transition of an executive leader; an emergency