Download presentation
Presentation is loading. Please wait.
Published byPierce Hodge Modified over 9 years ago
1
Implementation of Digital Forensics Lab Group : CNWIS-04 Mevan Alles Buddhika R.A.P Heshan Kumarage Lahiru Wijayapala
2
Digital Forensics Lab2 Introduction A framework to carry out digital forensics investigation Live system analysis (System + Memory) Offline media analysis (hard disks, removable drives, optical disks, etc) Online traffic (network related) data analysis and threat identification Independent of the underlying platform.
3
Digital Forensics Lab3 Work carried out Preparation of the initial documents Project Proposal System Requirements Specification Discussion of the design document Research done until now Live System process analysis File Carving Online traffic data acquisition and analysis
4
Digital Forensics Lab4 Prepared Documents Project Proposal Systems Requirements Specification Finalize the requirements by discussing with the project mentor. (especially hardware requirements) Identify the functional and the non- functional requirements. Abstract design of the framework.
5
Digital Forensics Lab5 Research work Live System process analysis (HijackThis, KillBox, Uniblue processScanner ) Helpful to identify the status of the current system, identify risky processes, processes that are likely to cause the problems. Online network traffic analysis (Wireshark) Helpful in situations where bot-net(s) are in action Identify the spreading of viruses and understand the communication of running viruses with the source cpmputers.
6
Digital Forensics Lab6 Research work cont… File Carving (File Scavenger) Is basically a method of recovering deleted files or parts of the files that are lost. Helix Live System analysis CD Provides methods to analyze live systems in various aspects like obtain memory dumps, file carve, Cookie analyze, root kit scans, etc.
7
Digital Forensics Lab7 Q & A
8
Digital Forensics Lab8 Thank You for Listening…
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.