Lab-3 forensics

.docx

School

Laurentian University *

*We aren’t endorsed by this school

Course

SP24

Subject

Computer Science

Date

Jun 24, 2024

Type

docx

Pages

27

Uploaded by HighnessMaskDinosaur35

Computer Forensics Lab Assignments Course Code: CPSC_5207EL_62 Spring 2024 LAB-3 Module 4 Data Acquisition and Duplication Submitted to Professor: Sk Md Mizanur Rahman Submitted by Student Name: Israt Khan Mojlish Student ID:0443734
Module 04: Data Acquisition and Duplication Lab Objectives The objective of this lab is to help students learn to monitor a system remotely and to extract hidden text strings and other tasks that include: Creating a dd image file Converting image file to a bootable virtual machine Memory acquisition (RAM) on Windows workstation Extracting the hidden content from hard drives Lab Tasks Recommended labs to assist you in data acquisition and duplication: Creating a dd image of a system drive Converting acquired image file to a bootable virtual machine Acquiring RAM from Windows workstation Viewing contents of forensic image file
Lab 1: Creating a dd Image of a System Drive Lab Tasks 1. By default  Windows Server 2019  virtual machine is selected. Clickeded  Windows 10  to select  Windows 10  virtual machine. Clicked  Ctrl+Alt+Delete .
2.By default,  Admin  user profile is selected, clicked qwerty@123 to paste the password in the  Password  field and pressed   Enter  to login.Before beginning this lab, copied   dd  folder from  Z:\DFE Module 04 Data Acquisition and Duplication\Data Acquisition Tools  and pasted it onto  Desktop .
To obtain information about the available drives on Microsoft Windows, the  wmic  command is issued in  Windows PowerShell . To launch PowerShell as an administrator, right-clicked on the  Windows  icon and select  Windows PowerShell (Admin) .
3.Windows PowerShell  appears; typed the command  wmic diskdrive list brief /format:list  and pressed  Enter . 4.Now, use  cd  command to navigate to the directory  C:\Users\Admin\Desktop\dd .
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help