If you can see this check that
Web Browser Forensics |
This practical will guide you through a small investigation using Linuxzoo Caine.
***WARNING THE LAB HAS NOT YET BEEN EDITED FOR AUTOPSY 4.12***. Everything should still work, but the instructions will be out of date.
You will analyse Firefox forensic artefacts, which are stored mainly in SQLite databases, and explore what happens to deleted history.
It is expected that you use additional reference material as appropriate – some useful references are listed in the lecture slides. A starting point could be:
Morrill, D (2011), Firefox Forensics and SQLite Tables for Computer Forensics Analysis, available at https://resources.infosecinstitute.com/topics/digital-forensics/firefox-and-sqlite-forensics/ , gives a good overview of the different SQLite files and tables that Firefox uses to store user data.
From CCTV, the police identified a female suspect entering an internet cafe in Edinburgh at approx. 19:30 on Sunday 15/2/15. Her name is as yet unknown. After she left the internet cafe at approx. 20:55, the police obtained a warrant to seize the PC she was using. During the acquisition, they found a USB stick connected to the PC, which may belong to the suspect. While it is known through the manager of the cafe that the suspect did use the internet, no traces of relevant browsing history were found on the PC itself, and the router is configured not to store packet content information. It is now your task to analyse the USB stick. The police would like to know:
To reset all the check buttons from a previous attempt click here
Centos 7 intro: | Paths | BasicShell | Search |
Linux tutorials: | intro1 intro2 wildcard permission pipe vi essential admin net SELinux1 SELinux2 fwall DNS diag Apache1 Apache2 log Mail |
Caine 10.0: | Essentials | Basic | Search | Acquisition | SysIntro | grep | MBR | GPT | FAT | NTFS | FRMeta | FRTools | Browser | Mock Exam | |
Caine 13.0: | Essentials | Basic | Search | |
CPD: | Cygwin | Paths | Files and head/tail | Find and regex | Sort | Log Analysis |
Kali: | 1a | 1b | 1c | 2 | 3 | 4a | 4b | 5 | 6 | 7a | 8a | 8b | 9 | 10 | |
Kali 2020-4: | 1a | 1b | 1c | 2 | 3 | 4a | 4b | 5 | 6 | 7 | 8a | 8b | 9 | 10 | |
Useful: | Quiz | Forums | Privacy Policy | Terms and Conditions |
Linuxzoo created by Gordon Russell.
@ Copyright 2004-2024 Edinburgh Napier University