$20 Bonus + 25% OFF
Securing Higher Grades Costing Your Pocket? Book Your Assignment at The Lowest Price Now!

Digital Forensic Case Study

tag 191 Downloads10 Pages / 2,301 Words tag Add in library Click this icon and make it bookmark in your library to refer it later. GOT IT

Question - Write a case study on Digital Forensic methodology?




Executive Summary.


      Global Finance Background and Concern.

Digital Forensic Methodology.

      Scope of the Case.

Digital Forensic Methodology Approach.

       Investigation Process.


       Volatile Data Capture.

       Non- Volatile Data Capture.


       File System Examination.

       Windows Registry Examination.

       Network Forensic Examination.

       Database Forensic Examination.








Executive Summary

Global Finance company stands to be one of the largest finance company, providing the investment, superannuation and retirement services in Australia. It has a wider range of clients right from individuals to the corporation and superannuation fund investors. Very soon the company has widened its services throughout the globe with information technology support and strives to overcome the security challenges of the company.


Global Finance company experiences a suspect or compromise of the information in one manager’s computer, working in the Queensland branch. Information security officer is accountable to this challenge and enforced an investigation audit team to investigate the source of the compromise to overcome the challenge.

Global Finance Background and Concern

The Global Finance Company is in the following state as considered by the audit team.

  1. Global Finance is a huge international player company with more than 10,000 employees employed throughout the world, with sector interests.
  2. The concern with the security is the compromise of the manager’s computer, in one of its branches in Australia.
  3. Global Finance company has been spread worldwide with the support of information technology.
  4. Networking and application infrastructure in the branch offices are missing after 2000, so the there is flat network environment with no access restrictions.
  5. Servers and workstations in the head office and all the branch offices are based on Microsoft Windows.
  6. Implementation of the network segmentation and firewall is poor.
  7. Though instruction detection and logging detection are existing, these are not regularly used.
  8. Head office has the necessary information technology infrastructure and technology with potential investigative and forensic capabilities.
  9. Information security officer has initiated the investigation by enforcing an audit team for digital forensic investigation.
  10. Auditing team has got the responsibilities of digital forensic analysis, documentation and presentation of the same to the information security officer.

Digital Forensic Methodology

Digital forensic investigation methodology is recommended and employed by the information security officer, as the methodology can find and reveal the source of compromise of the manager’s computer, by detecting all the workstations and networking among them. Digital forensic investigation methodology involves the sub tasks of data recovery, in case if any of the potential data is lost and network forensic to find if there is any compromise caused through the network.

Before the investigation started by the audit team, they need to follow the following principles.

  1. Data present in the media should not be modified and the data has to be presented as is to the information security officer.
  2. Each team member of the audit must be well acquainted with enough expertise to ensure that the data is handled safely, without loss.
  3. The team has to preserve all the relevant documented information done, during the investigation.
  4. The whole and sole accountable person in this investigation is the information security officer, so everything has to be communicated and submitted to the information security officer.



Scope of the Case

          Digital forensic investigation done in the Global Finance company has the following scope.

  • Identification of any malicious activities and investigation of 5ws or why, when, what, where and who
  • Identifying the security lapse in the network
  • Identification of all possible digital evidence within the network
  • Finding and estimating the impact of the investigation, if the compromise happened
  • Identification of the legal procedure, in case the misconduct is found illegal
  • The extent of investigation and further security steps are taken by the information security officer, who is whole and sole accountable person

Digital Forensic Methodology Approach

There are many digital forensic methodology approaches followed according to the situation, so there is no one common approach that fits all the cases. In the case of the compromise of the branch of the Global Finance company, the approach recommended is FSFP or Four Step Forensics Process.

The approach has the following processes.


The arrow is the indication of preservation of the document evidence throughout the process.

Investigation Process

Digital forensic investigation is done in the following phases.


Collection consists of identification, labeling and recording the data from all the sources possible, followed by the maintaining the integrity of the data. Data is primarily collected as both volatile and non volatile data.

The same LAN connection is to be used to access the forensic workstation of the manager and other workstations. Server of manager’s computer is taken as the target in this case. Microsoft Windows software is run in this server. To hear from the server, ‘cryptcatp tool is used. The team creates toolset optical drive and opened through a trusted console, comd.exe.

The following statements are then executed.

Cryptcat 6543 – k key

Use the following command, for the data capture from the forensic workstation.

Cryptcat -1 –p 6543 –k key >>

Other tools that can be used here are the graphical user interface tools, like Process Explorer, Tcpview and Rootkit Revealer. The other Windows based tools used to capture the data are,

Ipconfig – for collection of the subject system details

HBGray’s fastDump – to acquire the local physical memory

Doskey or history - for collection of command history

HBGray’s F-Response – to acquire remote physical memory

Netfile – for identification of the drivers and services

Netusers and qusers – for identification of the logged in user information

Other potential data is collected from the clipboard. Other potential data is network connection present, running processes and network data.

Volatile Data Capture

Volatile data capture involves the data collection from the RAM, registry and cache memory.

Non- Volatile Data Capture

Potential non volatile data collection involves the collection of the antivirus logs, database logs, windows event logs, IDS logs, domain controller logs, application logs, firewall logs and other online data. Collection of the non volatile data is also called as forensic imaging.

The non volatile data collection involves data present in the hard disc and other removable discs, like flash drives, USB drives, CD, DVD, memory cards, remote hard drives and remote computers, in the form of MS Outlook, MS Word and Spreadsheet. Collection continues with the other computers, switches, network topology documentation, network diagrams, routers and servers. Live networking traffic can clue very significant and potential digital data for the investigation.

Forensic imaging involves copy of the entire non volatile data from the manger’s system and no further alterations are to be done. Various tools used for forensic imaging are FTK, EnCase and ProDiscover with write block. Forensic imaging is better than the hard disc cloning, as it copies the integrated data that includes the metadata, which is significant in the investigation. The audit team does both this offline data and other online data using the tools, ethereal and Wireshrk tools.

All the collected data is well documented by the audit team.


After the digital data collection is done, examination is conducted using forensic investigation tools. Investigation is done for the manager’s computer, as the following.

File System Examination

New Technology File System disc or NTFS disc file has MFT or Master File Table information. MFT has all the files and disc crucial information. MFT contains the metadata of the files, which are existing and deleted, noted by the operating system.

The data in file is stored as

c: echo text_mass > file1.txt:file2.txt

The following command is used to retrieve the above,

c:more <file1.txt:file2.txt

virus is also another potential data malfunction and so has to be considered for investigation.



Windows Registry Examination

          Windows registry logs can reveal modification of the file information according to the time, lastwrite registry details, precise data in a database for the user application along with the hardware device reference point.

The Windows registry structure is






The important keys and values are,

User Activity: user performed actions and activities over the manager’s computer can be accessed through HKEY_CURRENT_USER

Autostart : This registry is a set that is launched without initiation of the user.

MRU or Most Recent Used List: to keep track of the current activities.

Other important clues are USB Removable storage, UserAssit, Wireless SSIDs, etc.

Network Forensic Examination

Tracking of packet forensics or packet mining is tracked via the network to track the network traffic like mails, browsing history, queries, etc.

Network forensic tools can be applied in one of the two ways, security related and the other is forensic data according to the enforcement of the law. The team uses many network forensic tools and techniques to discrete investigated data like registry information, process listing, service listing, system information, logged on users, registry users, network connections and binary memory dump to explore and investigate. Packet sniffers help identifying and mapping the fingerprinting, web services and email communication, etc.

Database Forensic Examination

Database data is tracked through the queries for data identification and then preserved to analyze. IP addresses are tracked for remote connections. Database transactions are tracked though Data Manipulation and Data Definition Languages, DML and DDL. Customized file configuration is used to execute Database Consistency Checker and Distributed Management Views towards intrusion explosion.


          Detailed data analysis is done after considering each of the digital evidence data. The analysis includes the following actiivites.

  1. Unusual application requests
  2. Looking the unusual and hidden files along with unusually opened sockets
  3. Malicious activies
  4. Complete analysis for memory
  5. Unusual accounts
  6. Malware analysis
  7. Complete analysis of timeline
  8. Patching level system
  9. Updated levels
  10. Complete analysis of file systems
  11. Complete analysis of event correlation

The crucial malware analysis includes various tasks within, like, examining the logs, prefetch examination, search of known malware using either dynamic or static analysis.


After the analysis the findings are summarized as,

  1. Identification of the compromise of the manager’s computer
  2. Identification of persistent remote access or direct access by the attacker
  3. Installing OS patch if not done in the target computer
  4. Malware that is suspected


Investigation is done over the manager’s computer and all other computers and computing devices present in the branch office. Audit team creates a formal report and then submitted to the information security officer.

Final Report


The report has the purpose of submission of the formal investigated information, related to the sources of compromise occurred to the manager’s and all other computers.

Author of the Report

Information Security Officer

Incident Summary

All the source of the compromise that are found and suspected on manager’s computer.

Digital Evidences

All relevant log files and other potential digital evidences found in the investigation


Analysis of the sources of the compromise


The manager’s computer is digitally investigated for the sources of compromise, along with the and other computers in the regional office

Supporting Documents

Volatile, non- volatile data, registry info, log info and the reports generated from the tools.




The suspected manager’s or targeted computer is completely digitally investigated using digital forensic technology, from the Queensland branch office and finally the formal report is being submitted to the information security officer.


“Cyber Forensic Investigation Plan”, International Journal of Advance Research (2008),, Volume 1, Issue 1, accessed on 9 January, 2015.

7safe, (2013) “Good Practice Guide for Computer-Based Electronic Evidence”.

Siti Rahayu Selamat, Robiah Yusof, Shahrin Sahib (2008), “Mapping Process of Digital Forensic Investigation Framework”, JCSNS International Journal of Computer Science and Network Securit, Vol 8.

ACPO (2013), “Good Practice Guide for Computer-Based Electronic Evidence”, V4.0

Aquilina, M.J., (2003), “Malware Forensics, Investigating and Analyzing Malicious Code”, Syngress,

Kenneth J. Zahn (2013), “Case Study: 2012 DC3 Digital Forensic Challenge Basic Malware Analysis Exercise”, GIAC (FREM) Gold Certification

Fowler, K., (2007), “Forensic Analysis of a SQL Server 2005 Database Server”.



Khanuja, H.K., and Adane, D.S., (2011), “Database Security Threats and Challenges in Database Forensic: A Survey”, IPCSIT vol.20 (2011), Singapore: IACSIT Press.

John Ashcroft (2001), “Electronic Crime Scene Investigation, A guide for First Responders”, NIJ Guide

M Reith, C Carr, G Gunsch (2002). "An examination of digital forensic models". International Journal of Digital Evidence

Kent, K.,, (2006). “Guide to Integrating Forensic Techniques into Incident Response”, National Institute of Standards and Technology (Ed.) (Vol. 800-86): U.S. Department of Commerce.

Richard Brian Adams (2012), “The Advanced Data Acquisition Model (ADAM): A Process Model for Digital Forensic Practice”

Agarwal, A., Gupta, M., Gupta, S., & Gupta, S. C. (2011). “Systematic Digital Forensic Investigation Model”, International Journal of Computer Science and Security, 5(1), 118-130.

Shiner, D.L.D., and Cross, M., (2002), ” Scene of the Cybercrime”, 2nd edn, Syncress: Burlington.

Reino, A. (2012), “Forensics of a Windows System”, Roche.

Armstrong, C. (2003), “Mastering Computer Forensics. In C. Irvine & H. Armstrong”, Security Education and Critical Infrastructures Kluwer Academic Publishers.

Download Sample

Get 100% money back after download, simply upload your unique content* of similar no. of pages or more. We verify your content and once successfully verified 100% value credited to your wallet within 7 days.

Upload Unique Document

Document Under Evaluation

Get Credits into Your Wallet

*The content must not be available online or in our existing Database to qualify as unique.

Cite This Work

To export a reference to this article please select a referencing stye below:

My Assignment Help. (2015). Digital Forensic Case Study. Retrieved from

"Digital Forensic Case Study." My Assignment Help, 2015,

My Assignment Help (2015) Digital Forensic Case Study [Online]. Available from:
[Accessed 15 August 2020].

My Assignment Help. 'Digital Forensic Case Study' (My Assignment Help, 2015) <> accessed 15 August 2020.

My Assignment Help. Digital Forensic Case Study [Internet]. My Assignment Help. 2015 [cited 15 August 2020]. Available from: is the perfect solution to render quality solution for all sort of academic issues. We have hired professionals from different fields of study to provide assistance with different subjects. We successfully have provided different types of assignment solutions on 100+ subjects. We have hired industry experts to deliver nursing assignment, hr assignment and finance assignment help. To offer quality content with IT assignments, we have hired IT professionals to render programming language assignment help and IT assignment help for other types of IT assignments as well.

Latest Programing Samples

CMP3747M Cloud Computing

Download : 0 | Pages : 9
  • Course Code: CMP3747M
  • University: University Of Lincoln
  • Country: United Kingdom

Answer: Introduction Internet of Things (IoT) refers to the concepts of working with the network devices by sensing and gathering the data from the real-time environment. Then the data will be shared via the internet by processing and using it for various purposes. It comprises of smart equipment where it is used for interacting and interconnecting with the other equipment, infrastructures and environment. People are connected to establish co...

Read More arrow Tags: United Kingdom lincoln Programming Cloud Computing Other 

CSE1OOF-Oriented Programming Fundamentals

Download : 0 | Pages : 12
  • Course Code: CSE1OOF
  • University: La Trobe University
  • Country: Australia

Answer: Task 1: Vector Coding: // CSE1/4OOF Semester 2 2019 - Progress Check Test import*; import java.util.*;   // Vector class is used to store array of values and number of values public class Vector { protected int[] values; protected int size; // constructor of class with integer array of values and default value public Vector(int[] pValues, int pDefaultValue){ // if integer array is null or if its ...

Read More arrow Tags: Australia Programming Object Oriented Programming with Java La Trobe University 

CSE2DBF Database Fundamentals

Download : 0 | Pages : 5
  • Course Code: CSE2DBF
  • University: La Trobe University
  • Country: Australia

Answer: Task 1. Employee (EmployeeID, EmployeeName, Phone, Email, Address, Gender, DOB, JoiningDate, DepartmentID) Central (EmployeeID, CANumber) Local (EmployeeID, EFPOSID) Casual (EmployeeID, HourlyRate) PartTime (EmployeeID, WeeklyHours, Salary) FullTime (EmployeeID, HourlyRate, Salary) Store (StoreID, StoreAddress, WeekDaysHour, WeekendHours, DepartmentID ) Department (DepartmentID, DepartmentTitle, NoOfEmployees) Account (Ac...

Read More arrow

OODP101 Object Oriented Design And Programming 2

Download : 0 | Pages : 5

Answer: Design Task 1 PseudocodeA. startCalculations Input: NAReturns: NA Call printWelcomeMessage Set hours as double array with size MAX. Set gPay as double array with size MAX. Set nPay as double array with size MAX. Set index as 0 Repeat: Set name as user String input Set hours[index] as return value from getDouble Set hourlyRate as return value from getDouble Set gPay[index] as hours[index] * hourlyRate Set taxP as return valu...

Read More arrow Tags: Australia 46 object oriented design and programming Kent Institute Australia 

ICT320 Database Programming Assessment

Download : 0 | Pages : 3

Answer: Data Tables and Data types Field Datatype Reason CustomerID (PK) INT(4) The field is containing max 9999 Lastname VARCHAR(20) The field is containing up to 20 characters Firstname VARCHAR(15) The field is containing up to 15 characters Address VARCHAR(30) The field is containing up to 30 characters Postcode CHAR(4) The fiel...

Read More arrow

Save Time & improve Grade

Just share Requriment and get customize Solution.

We will use e-mail only for:

arrow Communication regarding your orders

arrow To send you invoices, and other billing info

arrow To provide you with information of offers and other benefits




Overall Rating



Our Amazing Features


On Time Delivery

Our writers make sure that all orders are submitted, prior to the deadline.


Plagiarism Free Work

Using reliable plagiarism detection software, only provide customized 100 percent original papers.


24 X 7 Live Help

Feel free to contact our assignment writing services any time via phone, email or live chat.


Services For All Subjects

Our writers can provide you professional writing assistance on any subject at any level.


Best Price Guarantee

Our best price guarantee ensures that the features we offer cannot be matched by any of the competitors.

Our Experts

Assignment writing guide
student rating student rating student rating student rating student rating 4/5

248 Order Completed

100% Response Time

Lloyd Bernabe

MSc in Accounting

London, United Kingdom

Hire Me
Assignment writing guide
student rating student rating student rating student rating student rating 4/5

1309 Order Completed

100% Response Time

Gemmie Chen

MSc in Nursing

Singapore, Singapore

Hire Me
Assignment writing guide
student rating student rating student rating student rating student rating 5/5

798 Order Completed

97% Response Time

Benjamin Blakeman

MSc in Medical Technology

London, United Kingdom

Hire Me
Assignment writing guide
student rating student rating student rating student rating student rating 5/5

1692 Order Completed

98% Response Time

Alfred Dodd

PhD in Computer and Information Science with specialization in Database

Wellington, New Zealand

Hire Me

FREE Tools


Plagiarism Checker

Get all your documents checked for plagiarism or duplicacy with us.


Essay Typer

Get different kinds of essays typed in minutes with clicks.


GPA Calculator

Calculate your semester grades and cumulative GPa with our GPA Calculator.


Chemical Equation Balancer

Balance any chemical equation in minutes just by entering the formula.


Word Counter & Page Calculator

Calculate the number of words and number of pages of all your academic documents.

Refer Just 5 Friends to Earn More than $2000

Check your estimated earning as per your ability




Your Approx Earning

Live Review

Our Mission Client Satisfaction

Awesome work. Awesome response time. Very thorough & clear. Love the results I get with MAH!


User Id: 383727 - 31 Jul 2020


student rating student rating student rating student rating student rating

Work was done in a timely manner took it through grammarly checked for plagiarism very well satisfied


User Id: 463334 - 31 Jul 2020


student rating student rating student rating student rating student rating

Great work for the short notice given. Thank you for never disappointing and helping out.


User Id: 194216 - 31 Jul 2020


student rating student rating student rating student rating student rating

I received a full point on the assignment. Thank you for all the help with the assignment.


User Id: 411395 - 31 Jul 2020


student rating student rating student rating student rating student rating
callback request mobile
Have any Query?