1. Select a Computer Device to stage the creation of any type of fictitious digital evidence.
    (This will require a fair amount of creativity on your part, I will accept any reasonable creation of an artifact including log files, digital images, Document files, Data Base data, Email files, geolocation info. and other metadata, deleted files, evidence of password changes, etc.)
  2. Create the target artifact using the selected device – Shutdown and restart the device.
  3. Create a digital forensic image of the selected device using FTK.
  4. Examine a working copy of the forensic Image using Autopsy to locate the target artifact or artifacts.
  5. Display the relevant sections showing the relevant data on Autopsy and take a screenshot to submit for full lab credit. (Show timestamps, data, text, images, etc. several screenshots is required). Please include a statement explaining the rationale behind the evidence you have created. (how is it relevant as evidence – What does it prove?

Sample Solution

This question has been answered.

Get Answer