CYSE 407

Digital Forensics

This course introduces the basic concepts and technologies of digital forensics. Students will learn the fundamental techniques and tools utilized for collecting, processing, and preserving digital evidence on computers, mobile devices, networks, and cloud computing environments. Students will also engage in oral and written communication to report digital forensic findings and prepare court presentation materials.

At the end of this course students will be able to:

  1. Recognize the duties of a digital forensic investigator and the requirements of a lab environment.
  2. Utilize data collection tools and methods necessary for recovering and identifying different digital forensic artifacts left by attacks.
  3. Utilize appropriate methods to preserve the integrity of digital evidence and acquire a forensically sound image.
  4. Analyze different types of digital evidence to extract the related information important to a case under investigation.
  5. Prepare evidence, findings and results of analysis in a digital forensic report.

Course Projects

Digital Forensics Laboratory Plan (3-Year Plan)

This project involved developing a three-year plan for establishing and operating a digital forensics laboratory for a mid-sized police department. I designed the plan around the practical requirements of a professional forensic environment, including laboratory layout, evidence storage, forensic equipment and software, accreditation, maintenance, and staffing.

Summary:

This document outlines the comprehensive 3-year digital forensics laboratory plan for a mid-sized police department. 
The lab is designed exclusively for computer and digital forensics operations. The plan provides a structured approach to physical layout, equipment inventory, accreditation preparation and steps, maintenance procedures, and staffing requirements.

  1. Physical Lab Layout

The digital forensics laboratory will consist of secure, access-restricted zones to ensure proper handling, storage,and analysis of digital evidence. 

The layout includes:
• Evidence Storage Room: Secure, temperature-controlled area with individual evidence lockers and surveillance.
• Two Analysis Workstations: Equipped with high-performance forensic computers, dual monitors, and write-blocking devices.
• Imaging & Acquisition Area: Dedicated space for forensic imaging with appropriate hardware and documentation stations.
• Lab Manager Office: Contains case management tools, administrative systems, and secure document storage.
• Security Elements: Badge/PIN dual access control, and restricted access points.

  1. Equipment Inventory

Hardware:
Forensic workstations (2), dual 27-inch monitors, UPS backup units.
Tableau and WiebeTech forensic write-blockers.
Faraday boxes/bags, mobile device extraction tools (Cellebrite, Oxygen Forensics).
RAID storage systems, PowerEdge R660 servers, cable kits, anti-static lab equipment, tool cabinets. Unitrends 9016S 16TB Backup Storage Appliance.
NAS systems for secure storage and evidence backups.
Computer Chairs (29)

RFID Badge readers

APC SMT750RM2UC UPS, APC BE650G1 Desktop UPS

PC Power Cables

20 IDE Cables, 20 SATA Cables

Juniper Switch EX2300


Software:
• EnCase Forensic, FTK, X-Ways Forensics, Autopsy Suites.
• Cellebrite UFED, Oxygen Forensics, Magnet AXIOM Mobile.
• Wireshark, Kali Linux, Ghidra, and volatility tools.
• VMware Workstation, malware sandbox environment, evidence management software.

  1. Accreditation Plan (ISO/IEC 17025)

The lab will follow a structured 3‑year path toward accreditation under ISO/IEC 17025 standards:

Year 1:
• Develop Standard Operating Procedures (SOPs) for acquisition, analysis, reporting, and chain‑of‑custody.
• Establish a Quality Management System (QMS) and perform internal audits.
• Begin certification training for staff (CFCE, CCE, CHFI, GCIH optional).

Year 2:
• Implement accreditation-focused training and documentation.
• Formalize equipment calibration, evidence handling, and peer review processes.
• Conduct external proficiency testing.

Year 3:
• Submit accreditation application to ANAB.
• Complete pre‑assessments, address findings, and complete final evaluation.

  1. Lab Maintenance Plan

To maintain operational readiness and accreditation compliance, the following schedule will be used:

Daily Maintenance:
• Validate write‑blockers and forensic tools.
• Perform workstation performance checks.
• Conduct evidence intake reviews and maintain cleanliness.

Weekly Maintenance:
• Back up all case files to secure NAS.
• Review chain‑of‑custody logs.
• Reset malware sandbox environments.

Monthly Maintenance:
• Hardware diagnostics, software integrity checks.
• Update QMS documentation and inspect CCTV systems.

Annual Maintenance:
• Renewal of licenses and certifications.
• Complete forensic proficiency testing.
• Full inspection and audit of evidence storage.

  1. Staffing and Job Descriptions

Two primary roles will be required for the initial launch of the lab:

Lab Manager:
Responsibilities:

Direct and manage the day-to-day operations of the digital forensics lab, including workflow, resource allocation, and project prioritization.

Develop and implement standard operating procedures (SOPs) for data collection, preservation, and analysis that meet legal and forensic standards.

Oversee the maintenance and calibration of all forensic hardware and software, ensuring the lab is equipped with the latest tools and technologies.

Qualifications:
Certified Forensic Examiner (CFE), EnCase Certified Examiner (EnCE), or similar.

Relativity Certified Administrator (RCA) or other relevant eDiscovery software certifications.

GIAC certifications (e.g., GCFA, GCFE) are a significant plus.



Digital Forensic Technician:
Responsibilities:
Conduct forensic imaging and data acquisition.
Maintain and inventory equipment.
Assist analysts with mobile and computer extractions.

Apply knowledge to the enforcement of Title 18, Title 31, and other applicable statutes of the Federal Criminal Code, and the seizure and forfeiture of illegally derived property

Conduct research and analysis using open source information, national and international databases, and corporate record filings to match investigative findings and summarize data into a finished professional product

Qualifications:
Associate or bachelor’s degree in a technical field.
Experience with forensic tools and operating systems.
Knowledge of chain‑of‑custody and evidence handling procedures.

4+ years cyber fraud investigations related experience

1+ years of experience supporting law enforcement with cryptocurrency investigations

6+ months experience with blockchain intelligence tools (Chainalysis, TRM Labs, Elliptic)

 

Optional Year 3 Expansion:
• Additional examiner specializing in mobile, network, or malware forensics as case volume increases.

 

Conclusion: This lab plan establishes a structured and sustainable framework for a fully operational digital forensics laboratory. Through proper planning, accreditation preparation, maintenance scheduling, and staffing, the lab will support reliable and defensible digital investigations for years to come.

 

Final Case report

This project involved developing a digital forensics investigation report documenting the examination of a mobile device and laptop in a simulated investigation. I developed a forensic methodology that included evidence preservation, acquisition, imaging, hashing, artifact analysis, deleted-data recovery, timeline construction, and network and financial record correlation.

 

Digital Forensics Investigation Report

Case Overview

  • Case Identifier / Submission #: DF-RUSINT-3255
  • Case Investigator: Kenneth Thomas
  • Case submitted by: Kenneth Thomas
  • Date of Receipt: November 28, 2023

Back Ground and Context:
The subject is a senior U.S. government official who has retained counsel and declined to comment on alleged contacts with Russian operatives (“Red Ralph”). A forensic examination was performed on the subject’s primary mobile device (Samsung Galaxy S23) and personal laptop (HP Envy 17‑T). The purpose of this report is to document the methodology, findings, and conclusions for possible use in criminal proceedings.

1. Items Submitted for Examination

Item Make / Model Serial # Color Description
Cellular Device Samsung Galaxy S23 (SM‑S911U) TMNT804S19A Graphite 256 GB, Android 13, locked with PIN & biometric lock.
Personal Laptop HP Envy Laptop 17‑T (HP 17T‑CW000) CND7613245890 Silver 15.6″ FHD, Intel i7‑12700H, 512 GB SSD, Windows 11 Pro.

2. Examination Environment & Tools

Category Tool / Hardware Version / Source
Hardware Write‑Blocker Tableau Standalone Forensic Imager (TD4) Firmware 2.5
Imaging Station UltraKit v5 + TD4 Forensic Imager Digital Intelligence
Analysis Workstation FRED L Forensic Laptop (16 CPU, 64 GB RAM) Digital Intelligence
Mobile Extraction MOBILedit Forensics Pro (Physical & Logical) 12.2
SIM Card Access USB‑CAC Smart Card Reader (Military grade) 1.0
Disk Imaging Tableau Forensic Imager (E01 format) 3.0
File & Artifact Analysis Autopsy (Sleuth Kit)  v4.24 Open‑source
Additional Utilities FTK Imager, Bulk Extractor, RegRipper, Wireshark (network capture), Hashcat (hash verification) Latest releases

All tools were verified for integrity (SHA‑256 hash match) prior to use. The examination followed NIST SP 800‑101 and ACPO good practice guidelines.

3. Methodology

3.1 Mobile Device (Samsung S23)

  1. Seizure & Preservation  Device placed in Faraday bag; power left on to preserve volatile memory.
  2. Acquisition  Performed a logical extraction via MOBILedit Pro (USB‑C cable) to obtain contacts, SMS/MMS, call logs, app data, and cloud backups.
  3. SIM Card Bypass  Utilized the USB‑CAC reader to clone the SIM; MOBILedit’s SIM‑PIN bypass removed the 4‑digit PIN without altering the original card.
  4. Data Export  Exported artifacts to E01 container; generated MD5/SHA‑256 hashes for each file.
  5. Keyword & String Searches  Executed targeted searches for: “Ralph”, “Red Ralph”, “meeting”, “lunch”, “consulting”, “payment”, plus Russian Cyrillic equivalents.
  6. Deleted Data Recovery  Enabled “undelete” mode in MOBILedit to recover soft‑deleted SMS and app caches.
  7. Timeline Construction  Correlated timestamps (UTC) with device clock drift correction (±2 seconds).

3.2 Laptop (HP Envy 17‑T)

  1. Write‑Blocking & Imaging  Connected SSD via USB‑3.0 to Tableau imager; created a bit‑for‑bit forensic image (E01) with SHA‑256 verification.
  2. Verification  Compared hash of source and image; confirmed 0% mismatch.
  3. Mounting & Indexing  Mounted image read‑only in Autopsy; indexed all file systems (NTFS, FAT32 partitions).
  4. Email Extraction  Parsed Outlook PST files and local mail client SQLite databases; exported all inbound/outbound messages.
  5. Keyword Searches  Conducted Boolean searches for: (“Red Ralph” OR “Ralph”) AND (“consult*” OR “payment” OR “fee”).
  6. Deleted File Recovery  Employed Autopsy’s “File Carving” module (foremost) and “Slack Space” analysis to locate remnants of ZIP archives.
  7. Metadata & Hash Verification  Extracted EXIF, document properties, and computed SHA‑256 hashes for recovered files.
  8. Web Log Correlation  Analyzed Chrome/Edge browsing histories, DNS cache, and firewall logs; cross‑referenced timestamps with file‑upload timestamps from the file‑sharing service (see Section 4).
  9. Financial Records  Imported PDF bank statements; performed OCR (Tesseract) to extract transaction dates, amounts, and counterparties.

All actions were logged in a tamper‑proof chain‑of‑custody bags.

4. Findings

4.1 Mobile Device Artifacts

Artifact Date/Time (UTC) Details
Contact Entry 2015‑12‑03 09:12 UTC “Red Ralph”  Mobile #:  +7(922) 555‑1543; label “Russian liaison”.
SMS Meeting Confirmation 2016‑02‑14 16:45 UTC From: +7 (922) 555‑1543 → Subject’s number. <br>Message: “Let’s meet at Chili’s on Main Street for lunch tomorrow at 12:00 PM.”
SMS Follow‑up 2016‑02‑15 08:02 UTC “Looking forward to our lunch at 12 PM. Bring the documents.”
Deleted SMS (Recovered) 2016‑02‑13 22:30 UTC “Did you receive the files I sent?” (sent by Subject).
Cloud Backup Retrieval 2023‑12‑08 14:21 UTC OneDrive sync log shows upload of “meeting_notes.docx” (size 42 KB) on 2016‑02‑14.
App Data Messaging Various (2015‑202) WhatsApp logs contain encrypted blobs referencing “Ralph” but no readable content after decryption failure (no key).

4.2 Laptop Artifacts

Artifact Date/Time (UTC) Summary
Email Initial Contact 2016‑01‑27 13:04 UTC From: official@state.gov → To: RedRalph@gmail.com <br>Subject: “Intro & Potential Collaboration”.
Email Consulting Agreement 2016‑02‑02 09:57 UTC Attachment: “Consult_Agreement.pdf” (SHA‑256: 3a1f…e9c). Terms: $150,000 per month for “strategic advisory”.
Email Payment Confirmation 2016‑02‑10 18:22 UTC From: official@state.gov → To: RedRalph@gmail.com <br>Body: “Wire transfer of $150,000 completed. Ref: TX‑20260210‑US‑RUS.”
Email Follow‑up 2016‑02‑14 11:31 UTC “Please confirm receipt of the documents before lunch tomorrow.”
Deleted ZIP Archives (Recovered) 2016‑02‑13 02:14 UTC (carved) Two ZIP files (≈ 3.2 MB total) containing: <br>• “Classified_Documents/Project_Sunscreen‑Report.pdf” <br>• “Classified_Documents/Strategic_Plan.docx” <br>Hashes: ZIP‑1 SHA‑256 = d4b2…; ZIP‑2 SHA‑256 = 9f73…
Web Upload Log 2016‑02‑13 02:20 UTC Browser POST to “fileshare.io/upload”  filename “Project_Sunscreen‑Report.zip”; response code 200; IP 185.23.44.77 (Russia‑based CDN).
Network Capture (Wireshak) 2016‑02‑13 02:18‑02:22 UTC TLS handshake to fileshare.io; encrypted payload size matches ZIP archive size.
Bank Statements 2015‑12‑01  2016‑03‑01 Multiple outbound ACH transfers to “RedRalph LLC” (Account # 987654321, Routing 021000021). Total transferred: $450,000.
Windows Registry  Run Keys 2016‑02‑14 07:45 UtC Persistence entry for “svchost.exe” pointing to a renamed copy of “russian_helper.dll” in %APPDATA%.

4.3 Corroborating Timeline

UTC Time Event
2016‑02‑13 02:14 Carved ZIP archives recovered from unallocated space.
2016‑02‑13 02:18 Network traffic captured uploading the ZIPs to a foreign file‑sharing service.
2016‑02‑14 09:12 Subject receives confirmation email from Red Ralph (payment received).
2016‑02‑14 16:45 SMS confirming lunch meeting for next day.
2016‑02‑15 12:00 Scheduled lunch at Chili’s (verified via calendar entry on phone).
2016‑02‑15 13:05 Subject’s phone logs show GPS coordinates matching Chili’s location.
2016‑02‑15 13:30 Subject’s device disconnects from-network (possible post‑meeting data wipe).

5. Conclusions

  1. Existence of Direct Communications  Both the mobile device and laptop contain evidence of communication between the subject and an individual identified as “Red Ralph,” a Russian contact (phone prefix +7). The messages clearly arrange a face‑to‑face meeting on February 15, 2016.
  2. Financial Transactions  Bank records demonstrate three separate ACH transfers totaling $450,000 to an entity linked to the Red Ralph email address, consistent with the “consulting services” described in the recovered emails.
  3. Transfer of Classified Material  Carved ZIP archives contain documents marked “Classified  Project Sunscreen” and “Strategic Plan.” Network logs confirm these files were uploaded to a foreign‑hosted file‑sharing service on February 13, 2016, two days before the scheduled meeting.
  4. Intent to Conceal  Deletion of the ZIP archives, subsequent overwriting attempts, and the presence of a persistence mechanism (malicious DLL) indicate deliberate effort to hide the exchange.
  5. Legal Relevance  The artifacts satisfy the evidentiary standards for relevance, authenticity, and chain‑of‑custody under Federal Rules of Evidence (Rule 901‑902). The timestamps, hash values, and corroborating network logs provide a robust foundation for admissibility.

End of Report