Presentation is loading. Please wait.

Presentation is loading. Please wait.

Forensics Jeff Wang Code 610.2 Mentor: John Zhu (IT Support)

Similar presentations


Presentation on theme: "Forensics Jeff Wang Code 610.2 Mentor: John Zhu (IT Support)"— Presentation transcript:

1 Forensics Jeff Wang Code 610.2 Mentor: John Zhu (IT Support)

2 Computer Forensics Forensics is the application of science to answer questions to a legal system Forensics is the application of science to answer questions to a legal system Computer forensics pertains to legal evidence found in computers and other digital storage mediums Computer forensics pertains to legal evidence found in computers and other digital storage mediums

3 Responsibilities To recover data in the event of a hardware or software failure To recover data in the event of a hardware or software failure To gather evidence against an employee that an company wishes to terminate To gather evidence against an employee that an company wishes to terminate To gain information about how computer systems work for the purpose of debugging or performance optimization To gain information about how computer systems work for the purpose of debugging or performance optimization

4 Tools of the trade FTK (Forensic Toolkit) – scans hard drives looking for various information FTK (Forensic Toolkit) – scans hard drives looking for various information Encase – images storage medias, examines files stored on the media Encase – images storage medias, examines files stored on the media Examines parts of storage media that are not normally accessible by users Examines parts of storage media that are not normally accessible by users

5 Summary of what I did Wipeout data on old storage medias (such as hard drives and tapes) so they can be thrown out Wipeout data on old storage medias (such as hard drives and tapes) so they can be thrown out Remove all important from HDD so they can be reused Remove all important from HDD so they can be reused Help users retrieve data that they may have deleted Help users retrieve data that they may have deleted Help maintain network security Help maintain network security

6 How they can use forensics to improve IT support Use forensic tool to recover data in the event a user deletes date by mistake or in the event of a hardware failure Use forensic tool to recover data in the event a user deletes date by mistake or in the event of a hardware failure Use tools to thoroughly wipeout sensitive data off storage medias Use tools to thoroughly wipeout sensitive data off storage medias Use the tools to crack passwords Use the tools to crack passwords

7 The End


Download ppt "Forensics Jeff Wang Code 610.2 Mentor: John Zhu (IT Support)"

Similar presentations


Ads by Google