By: Tom Maloney. Overview What is ProDiscover What it can be used for A few quick tools A real example ProDiscover vs. ENCASE ProDiscover IR Applications.

Slides:



Advertisements
Similar presentations
What is Computer Software?. Hardware vs Software Got to have both to get the job done!
Advertisements

PC Operating Systems in Review lesson 12. UNIX DOS The Macintosh Operating System Windows 3.x OS/2 Warp Windows NT Windows 95 and 98 Linux Windows 2000.
Computer Forensic Analysis By Aaron Cheeseman Excerpt from Investigating Computer-Related Crime By Peter Stephenson (2000) CRC Press LLC - Computer Crimes.
SEMINAR ON FILE SLACK AND DISK SLACK
Effective Discovery Techniques In Computer Crime Cases.
No Nonsense File Collection Presented by: Pinpoint Labs Presenter: Jon Rowe, CCE, ISFCE Certified Computer Examiner Members: The International Society.
Data Collection, Analysis and Preservation Computer Forensics: Data Collection, Analysis and Preservation Kikunda Eric Kajangu, Cher Vue, and John Mottola.
What You Will Learn Components of a computer’s system software The importance of an operating system Functions of an operating system Types of user interfaces.
Princeton PC Users Group Hard Drive Disaster! By Paul Kurivchack March 14, 2005.
Guide to Computer Forensics and Investigations Fourth Edition
Digital Forensics Module 11 CS /26/2004Module 112 Outline of Module #11 Overview of Windows file systems Overview of ProDiscover Overview of UNIX.
Chapter 8 Operating Systems and Utility Programs.
Retrieving Graphic Images From The Internet. Images, Subject, Search.
COS413 Capstone – EnCase Software Review Nathan Perkins.
Operating systems This work is licensed under a Creative Commons Attribution-Noncommercial- Share Alike 3.0 License. Skills: none IT concepts: popular.
COS/PSA 413 Day 3. Agenda Questions? Blackboard access? Assignment 1 due September 3:35PM –Hands-On Project 1-2 and 2-2 on page 26 of the text Finish.
COS/PSA 413 Day 5. Agenda Questions? Assignment 2 Redo –Due September 3:35 PM Assignment 3 posted –Due September 3:35 PM Quiz 1 on September.
The Operating System and the User Interface
I have lost all my vacation pictures due to memory card corruption. Can I get them back? I have accidently deleted some important Photos, Music files.
COEN 252 Computer Forensics Forensic Duplication of Hard Drives.
COEN 252 Computer Forensics
Guide to Computer Forensics and Investigations, Second Edition
RAID Acquisition Computer Forensics COEN 152/252.
Operating Systems Chapter 4.
TC2-Computer Literacy Mr. Sencer February 8, 2010.
NIST CFTT: Testing Disk Imaging Tools James R. Lyle National Institute of Standards and Technology Gaithersburg Md.
Your Interactive Guide to the Digital World Discovering Computers 2012.
IT GOVERNANCE AND CYBERCRIME Open Source Forensic Tools 19/04/10.
INTRODUCTION TO OPERATING SYSTEMS. An operating system is a program that controls the overall activity of a computer. Like an orchestra conductor an operating.
Computer Aided Design and Drafting
Guide to Computer Forensics and Investigations, Second Edition Chapter 2 Understanding Computer Investigation.
Teaching Digital Forensics w/Virtuals By Amelia Phillips.
Suntisak Thammavongsa Bachelor of IT (Honours) Supervised by Dr Raymond Choo University of South Australia Investigating a Private Ubuntu Enterprise.
Section 2 Software.
Your Interactive Guide to the Digital World Discovering Computers 2012.
Guide to Computer Forensics and Investigations Fourth Edition
Computer Forensics Infosec Pro Guide Ch 6 Testing Your Tools.
Computer Forensics An introduction Jessie Dunbar, Jr. Lynn Johnston Andrew Preece Kathy Spaulding September 18, 2007.
Remote Forensic Tools --- PDIR and EEE Tool review - remote forensic preservation and examination tools Editor : Eoghan Casey, Aaron Stanley Source : Digital.
By Mihail Blegeanu Affordable Computer Repair, Inc.
The Internet The History and Future of the Internet.
Introduction to Computer Operating Systems
Chapter 5 Processing Crime and Incident Scenes Guide to Computer Forensics and Investigations Fourth Edition.
CJ 317 – Computer Forensics
 Computer is an electronic tool that can accept, process, and accumulate data which can produce a result or output.  Computer System is a combination.
Forensics Jeff Wang Code Mentor: John Zhu (IT Support)
What is Computer Software?. Hardware vs Software Got to have both to get the job done!
Digital Communication Systems Comp Functions of the Operating System.
Operating Systems. Define OS Operating System is a type of system software. Operating system software includes instructions that allow a computer to run.
COEN 252 Computer Forensics Forensic Duplication of Hard Drives.
By: Jeremy Henry. Road Map  What is a cybercrime?  Statistics.  Tools used by an investigator.  Techniques and procedures used.  Specific case.
Computer Forensics Tim Foley COSC 480 Nov. 17, 2006.
1 Thinking How often do you use the internet? For what purposes to you use the internet the most? 2 Web Search What is the internet? When did.
Everything you know about DVDFab DVD copy DVDFab DVD copy is one of the most famous software used for copying and burning the DVD to the blank DVD disc.
2.00 Understand Computer Fundamentals Unit Objective: 2.01 Software.
By: Tom Maloney. Overview What is ProDiscover What it can be used for A few quick tools A real example ProDiscover vs. ENCASE ProDiscover IR Applications.
Computers: Tools for an Information Age
Know About MS Access Database
PC Operating Systems in Review
Operating Systems Overview
Windows 8 Microsoft Windows is the dominant operating system on personal computers around the world. The operating system is the most important software.
LO2: Understand Computer Software
CHFI & Digital Forensics [Part.1] - Basics & FTK Imager
An Introduction to Collaborative Online Documents
Computer Fundamentals
Digital Forensics Chris Rozic.
Visual recall of class information
PC Operating Systems in Review
Forensic Recovery of Evidence Device (FRED)
Presentation transcript:

By: Tom Maloney

Overview What is ProDiscover What it can be used for A few quick tools A real example ProDiscover vs. ENCASE ProDiscover IR Applications Conclusion

What is ProDiscover A program, released in 2002, used to read the contents of a disk Uses a GUI interface and combines older methods used through DOS to easily access and read disk drives Reads and makes a copy of the disk’s contents without altering any data

What ProDiscover is used for Computer Forensics View Deleted files Search for contents of a disk Retrieve a file that was accidentally deleted

Tools Copy image Report Search Content Internet Events Cluster

ProDiscover Basic vs. ENCASE Enterprise Cost Encase-Approx $3,000 Pro Discover- Free Can accomplish the same things however each has a few different tools ENCASE Enterprise can actually read information over a network using P2P Pro Discover needs to have a disk present to view

ProDiscover IR Able to read over a network Cost- Approx- $2200 Able to read files with MAC OS

How can we use it Police work Accepted in court cases Recover data

Conclusion What ProDiscover Is What it can be used for Tools An example of operation ProDiscover vs. Encase ProDiscover IR How we can use it

Citations Torres, Erik. "ProDiscover6_Brief_Tutorial." YouTube. YouTube, 11 Nov Web. 06 Oct "ProDiscover® Forensics - Disk Forensics Tool." ProDiscover® Forensics - Disk Forensics Tool. N.p., n.d. Web. 06 Oct "Computer Forensic Software - Encase Forensic." Computer Forensic Software - Encase Forensic. N.p., n.d. Web. 06 Oct