{"id":502,"date":"2026-07-02T02:49:40","date_gmt":"2026-07-02T02:49:40","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/jacobasare\/?page_id=502"},"modified":"2026-07-02T03:32:20","modified_gmt":"2026-07-02T03:32:20","slug":"skills-1","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/jacobasare\/skills-1\/","title":{"rendered":"SKILL 1: INCIDENT RESPONSE"},"content":{"rendered":"\n<p class=\"has-text-align-center\"><strong>1. INCIDENT RESPONSE, DIGITAL FORENSIC &amp; ANALYSIS<\/strong><\/p>\n\n\n\n<p>Intro Paragraph<\/p>\n\n\n\n<p>Incident Response &amp; Digital Forensics is one of my strongest skill areas, developed through hands\u2011on labs involving evidence extraction, deleted\u2011file recovery, metadata analysis, and timeline correlation. These artifacts demonstrate my ability to investigate suspicious activity, analyze digital evidence, and produce clear, structured forensic reports. This skill directly aligns with cybersecurity and incident response job roles that require analytical reasoning, attention to detail, and the ability to interpret multi\u2011source digital information.<\/p>\n\n\n\n<p>Artifact 1 \u2014 Mobile Device SMS Recovery (Text Message Analysis)<\/p>\n\n\n\n<p>Description: This artifact shows my skill in mobile device forensics. I extracted SMS data from a phone image, located messages confirming a suspicious meeting, and preserved the recovered text thread as evidence.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"626\" height=\"309\" src=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-26.png\" alt=\"\" class=\"wp-image-471\" srcset=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-26.png 626w, https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-26-300x148.png 300w, https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-26-600x296.png 600w\" sizes=\"(max-width: 626px) 100vw, 626px\" \/><\/figure>\n\n\n\n<p><strong>Artifact 2 \u2014 Email Evidence Extraction (Forensic Analysis)<\/strong><\/p>\n\n\n\n<p>This artifact demonstrates my ability to extract and analyze email evidence using Magnet AXIOM and the Outlook PST recovered from the laptop image. I processed the PST file to review message content, metadata, and communication patterns relevant to the investigation, identifying emails between the suspect and&nbsp;<em>RedRalph@gmail.com<\/em>&nbsp;that referenced consulting payments, file uploads, and a meeting scheduled for February 15, 2026. All email content was preserved exactly as recovered and documented through screenshots, supporting the broader findings presented in the full forensic report.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"617\" height=\"413\" src=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-25.png\" alt=\"\" class=\"wp-image-470\" srcset=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-25.png 617w, https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-25-300x201.png 300w, https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-25-448x300.png 448w\" sizes=\"(max-width: 617px) 100vw, 617px\" \/><\/figure>\n\n\n\n<p>Artifact 3 \u2014 Deleted File Recovery (ZIP Archive Metadata Analysis)<\/p>\n\n\n\n<p>Description: This artifact demonstrates deleted\u2011file recovery and metadata analysis. I recovered deleted ZIP archives from unallocated space, analyzed metadata, and correlated browser logs showing uploads to ShareBoxCloud.net.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"209\" height=\"61\" src=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-27.png\" alt=\"\" class=\"wp-image-472\" \/><\/figure>\n\n\n\n<p>Case Identifier: DF\u20112026\u20111472                                                                                                                                   Submission Number: 001                                                                                                                                            Case Investigator: Jacob Asare, Digital Forensic Examiner                                                                                   Submitting Agency: Office of Special Investigations (OSI)                                                                                     Submitter: Assistant U.S. Prosecutor, National Security Division                                                                                           Date of Evidence Receipt: March 12, 2026                                                                                                                    Date of Report: April 04, 2026<\/p>\n\n\n\n<p><strong>Artifact #9 \u2014 Digital Forensic Investigation Report<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-center\">&nbsp;Overview<\/p>\n\n\n\n<p>This artifact demonstrates my ability to conduct a complete digital forensic investigation using industry\u2011standard tools and methodologies. The case simulates a real\u2011world scenario involving suspicious communications, deleted files, and potential data exfiltration. The investigation followed proper forensic procedure, including evidence acquisition, chain of custody, examination, analysis, correlation, and reporting.<\/p>\n\n\n\n<p>This artifact aligns directly with job requirements for:<\/p>\n\n\n\n<ul>\n<li>Cybersecurity Analyst<\/li>\n\n\n\n<li>Digital Forensics Analyst<\/li>\n\n\n\n<li>Incident Response Analyst<\/li>\n\n\n\n<li>SOC Analyst<\/li>\n<\/ul>\n\n\n\n<p>1. Evidence Items Examined<\/p>\n\n\n\n<ul>\n<li>Item 1 \u2014 Laptop Computer<\/li>\n\n\n\n<li>Make\/Model: Dell Latitude 7420<\/li>\n\n\n\n<li>Serial Number: DL 7420 A19X55<\/li>\n\n\n\n<li>OS: Windows 10 Enterprise<\/li>\n\n\n\n<li>Storage: 1 TB NVMe SSD<\/li>\n\n\n\n<li>Condition: Seal intact, powered off<\/li>\n\n\n\n<li>Item 2 \u2014 Mobile Phone<\/li>\n\n\n\n<li>Make\/Model: Apple iPhone 12 Pro<\/li>\n\n\n\n<li>Serial Number: IP12 PR 9932K<\/li>\n\n\n\n<li>iOS Version: 16.3<\/li>\n\n\n\n<li>Condition: Powered on, locked; access gained via warrant\u2011approved biometric unlock<\/li>\n<\/ul>\n\n\n\n<p>Forensic Objectives<\/p>\n\n\n\n<ol start=\"1\">\n<li>Identify suspicious communications.<\/li>\n\n\n\n<li>Recover deleted files.<\/li>\n\n\n\n<li>Determine whether data exfiltration occurred.<\/li>\n\n\n\n<li>Correlate evidence across devices.<\/li>\n\n\n\n<li>Produce a courtroom\u2011ready forensic report.<\/li>\n<\/ol>\n\n\n\n<p>2. Forensic Examination Procedures<\/p>\n\n\n\n<p>2.1 Laptop Examination<\/p>\n\n\n\n<ul>\n<li>Forensic Imaging: FTK Imager 4.5; MD5 + SHA\u2011256 hash verification<\/li>\n\n\n\n<li>File System Analysis: Autopsy 4.21, EnCase v8<\/li>\n\n\n\n<li>Email Extraction: Outlook PST analyzed using Magnet AXIOM<\/li>\n\n\n\n<li>Deleted File Recovery: Scalpel + Bulk Extractor to carve deleted ZIP archives containing fragments of classified material.<\/li>\n\n\n\n<li>Browser Artifact Review: Browser History Examiner<\/li>\n<\/ul>\n\n\n\n<p>2.2 Mobile Phone Examination<\/p>\n\n\n\n<ul>\n<li>Logical Extraction: Cellebrite UFED 7.49<\/li>\n\n\n\n<li>SMS\/iMessage Review: Keyword searches (\u201cRalph,\u201d \u201cmeeting,\u201d \u201c2\/15\u201d)<\/li>\n\n\n\n<li>Contact List Analysis: AddressBook.sqlitedb<\/li>\n\n\n\n<li>Application Data Review: Messaging apps, call logs, location history<\/li>\n<\/ul>\n\n\n\n<p>3. Examination Results and Findings<\/p>\n\n\n\n<p>3.1 Text Message Evidence (Mobile Phone)<\/p>\n\n\n\n<ul>\n<li>Extracted SMS database.<\/li>\n\n\n\n<li>Located messages between user and contact labeled \u201cRed Ralph.\u201d<\/li>\n\n\n\n<li>Identified message confirming a meeting on 2\/15\/2026.<\/li>\n<\/ul>\n\n\n\n<p><em>All message content is preserved exactly as recovered and is presented as screenshots<\/em><\/p>\n\n\n\n<p>Exhibit 3.1 \u2014 Text Message Screenshot<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"627\" height=\"338\" src=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-36.png\" alt=\"\" class=\"wp-image-514\" srcset=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-36.png 627w, https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-36-300x162.png 300w, https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-36-557x300.png 557w\" sizes=\"(max-width: 627px) 100vw, 627px\" \/><\/figure>\n\n\n\n<p>3.2 Email Evidence Extraction (Laptop)<\/p>\n\n\n\n<ul>\n<li>Loaded email archive into Autopsy.<\/li>\n\n\n\n<li>Located messages referencing meetings and payments.<\/li>\n\n\n\n<li>Identified sender: RedRalph@gmail.com.<\/li>\n\n\n\n<li>Added relevant emails to the case as forensic artifacts.<\/li>\n<\/ul>\n\n\n\n<p>Exhibit 3.2 \u2014 Email Screenshot<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"603\" height=\"411\" src=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-38.png\" alt=\"\" class=\"wp-image-520\" srcset=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-38.png 603w, https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-38-300x204.png 300w, https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-38-440x300.png 440w\" sizes=\"(max-width: 603px) 100vw, 603px\" \/><\/figure>\n\n\n\n<p>Message referencing \u201cconsulting payments\u201d and \u201cmeeting on 2\/15\/2026.\u201d<\/p>\n\n\n\n<p>3.3 Deleted File Recovery<\/p>\n\n\n\n<p>During forensic analysis, four deleted ZIP archives including \u201cBriefing_Notes_SECURE.zip\u201d and \u201cIntel_Summary_Restricted.zip\u201d were recovered from unallocated space.<\/p>\n\n\n\n<p>Recovered fragments contained:<\/p>\n\n\n\n<ul>\n<li>Classified briefing headers<\/li>\n\n\n\n<li>Redacted intelligence summaries<\/li>\n\n\n\n<li>Internal government document templates<\/li>\n<\/ul>\n\n\n\n<p>Browser logs showed uploads to ShareBoxCloud.net on February 14, 2026, with filenames matching the deleted ZIP archives.<\/p>\n\n\n\n<p>It remains unknown whether external parties downloaded the files.<\/p>\n\n\n\n<p>Exhibit 3.3 \u2014 Autopsy View of Deleted ZIP Metadata<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"197\" height=\"48\" src=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-35.png\" alt=\"\" class=\"wp-image-513\" \/><\/figure>\n\n\n\n<p>3.4 Timeline Analysis<\/p>\n\n\n\n<ul>\n<li>Correlated email timestamps, text messages, and deleted file activity.<\/li>\n\n\n\n<li>Determined that communications and file deletion occurred within the same 24\u2011hour period.<\/li>\n\n\n\n<li>Established a sequence indicating possible data exfiltration prior to the meeting.<\/li>\n<\/ul>\n\n\n\n<p>4. Chain of Custody Record<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"252\" src=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-37.png\" alt=\"\" class=\"wp-image-515\" srcset=\"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-37.png 624w, https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-37-300x121.png 300w, https:\/\/sites.wp.odu.edu\/jacobasare\/wp-content\/uploads\/sites\/37982\/2026\/07\/image-37-600x242.png 600w\" sizes=\"(max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>Evidence stored in OSI Digital Forensics Lab \u2013 Locker 3B. No additional transfers occurred.<\/p>\n\n\n\n<p>5. Tools &amp; Methods Used<\/p>\n\n\n\n<ul>\n<li>Forensic Imaging<\/li>\n\n\n\n<li>FTK Imager 4.5<\/li>\n\n\n\n<li>File System &amp; Artifact Analysis<\/li>\n\n\n\n<li>Autopsy 4.21<\/li>\n\n\n\n<li>EnCase v8<\/li>\n\n\n\n<li>Magnet AXIOM<\/li>\n\n\n\n<li>Deleted File Recovery<\/li>\n\n\n\n<li>Scalpel<\/li>\n\n\n\n<li>Bulk Extractor<\/li>\n\n\n\n<li>Mobile Device Forensics<\/li>\n\n\n\n<li>Cellebrite UFED 7.49<\/li>\n\n\n\n<li>Browser Artifact Analysis<\/li>\n\n\n\n<li>Browser History Examiner<\/li>\n\n\n\n<li>Methodology<\/li>\n\n\n\n<li>Write blocker usage<\/li>\n\n\n\n<li>Hash verification<\/li>\n\n\n\n<li>Analysis performed only on forensic copies<\/li>\n<\/ul>\n\n\n\n<p>6. <a>Executive Summary for Prosecutor<\/a><\/p>\n\n\n\n<p><a>The forensic evidence establishes<\/a>:<\/p>\n\n\n\n<ul>\n<li>Direct communication between the suspect and \u201cRed Ralph\u201d<\/li>\n\n\n\n<li>Confirmed meeting on February 15, 2026<\/li>\n\n\n\n<li>Transfer of sensitive materials via unauthorized ZIP uploads<\/li>\n\n\n\n<li>Payment discussions tied to document transfers<\/li>\n\n\n\n<li>Intentional concealment, including deleted files and operational\u2011security instructions<\/li>\n<\/ul>\n\n\n\n<p>The evidence supports potential charges involving:<\/p>\n\n\n\n<ul>\n<li>Unauthorized disclosure of classified information<\/li>\n\n\n\n<li>Conspiracy<\/li>\n\n\n\n<li>Abuse of official position<\/li>\n\n\n\n<li>Unauthorized use of government systems<\/li>\n<\/ul>\n\n\n\n<p>All findings are supported by validated forensic tools and standard procedures.<\/p>\n\n\n\n<p>7. &nbsp;Conclusion<\/p>\n\n\n\n<p>The forensic investigation uncovered:<\/p>\n\n\n\n<ul>\n<li>Coordinated communication between the suspect and \u201cRed Ralph.\u201d<\/li>\n\n\n\n<li>Evidence of deleted classified files.<\/li>\n\n\n\n<li>Indicators of possible data exfiltration.<\/li>\n<\/ul>\n\n\n\n<p>This artifact demonstrates my ability to:<\/p>\n\n\n\n<ul>\n<li>Conduct forensic analysis<\/li>\n\n\n\n<li>Recover deleted data<\/li>\n\n\n\n<li>Analyze communication artifacts<\/li>\n\n\n\n<li>Correlate multi\u2011device evidence<\/li>\n\n\n\n<li>Document findings professionally<\/li>\n\n\n\n<li>Produce a structured forensic report<\/li>\n<\/ul>\n\n\n\n<p>These skills directly match job requirements for Cybersecurity Analyst, Incident Response Analyst, and Digital Forensics roles.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. INCIDENT RESPONSE, DIGITAL FORENSIC &amp; ANALYSIS Intro Paragraph Incident Response &amp; Digital Forensics is one of my strongest skill areas, developed through hands\u2011on labs involving evidence extraction, deleted\u2011file recovery, metadata analysis, and timeline correlation. These artifacts demonstrate my ability to investigate suspicious activity, analyze digital evidence, and produce clear, structured forensic reports. This skill&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/jacobasare\/skills-1\/\">Read More<\/a><\/div>\n","protected":false},"author":29145,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-json\/wp\/v2\/pages\/502"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-json\/wp\/v2\/users\/29145"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-json\/wp\/v2\/comments?post=502"}],"version-history":[{"count":5,"href":"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-json\/wp\/v2\/pages\/502\/revisions"}],"predecessor-version":[{"id":537,"href":"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-json\/wp\/v2\/pages\/502\/revisions\/537"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/jacobasare\/wp-json\/wp\/v2\/media?parent=502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}