{"id":127,"date":"2025-02-10T01:07:12","date_gmt":"2025-02-10T01:07:12","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/cyberimpact1\/?page_id=127"},"modified":"2026-08-18T11:32:50","modified_gmt":"2026-08-18T11:32:50","slug":"cyse-407","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/cyse-407\/","title":{"rendered":"CYSE 407"},"content":{"rendered":"<h1 style=\"text-align: center\">Digital Forensics<\/h1>\n<p class=\"p1\">This course introduces the basic concepts and technologies of digital forensics. Students will learn the fundamental techniques and tools utilized for collecting, processing, and preserving digital evidence on computers, mobile devices, networks, and cloud computing environments. Students will also engage in oral and written communication to report digital forensic\u00a0findings and prepare court presentation materials.<\/p>\n<p class=\"p1\">At the end of this course students will be able to:<\/p>\n<ol>\n<li class=\"p1\">Recognize the duties of a digital forensic investigator and the requirements of a lab environment.<\/li>\n<li class=\"p1\">Utilize data collection tools and methods necessary for recovering and identifying different digital forensic artifacts left by attacks.<\/li>\n<li class=\"p1\">Utilize appropriate methods to preserve the integrity of digital evidence and acquire a forensically sound image.<\/li>\n<li class=\"p1\">Analyze different types of digital evidence to extract the related information important to a case under investigation.<\/li>\n<li class=\"p1\">Prepare evidence, findings and results of analysis in a digital forensic report.<\/li>\n<\/ol>\n<h1>Course Projects<\/h1>\n<p><b>Digital Forensics Laboratory Plan (3-Year Plan)<\/b><\/p>\n<p>This project involved developing a three-year plan for establishing and operating a digital forensics laboratory for a mid-sized police department. I designed the plan around the practical requirements of a professional forensic environment, including laboratory layout, evidence storage, forensic equipment and software, accreditation, maintenance, and staffing.<\/p>\n<p><span style=\"font-weight: 400\">Summary:<\/span><\/p>\n<p><span style=\"font-weight: 400\">This document outlines the comprehensive 3-year digital forensics laboratory plan for a mid-sized police department. \u2028The lab is designed exclusively for computer and digital forensics operations. The plan provides a structured approach to physical layout, equipment inventory, accreditation preparation and steps, maintenance procedures, and staffing requirements.<\/span><\/p>\n<ol>\n<li><b> Physical Lab Layout<\/b><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400\">The digital forensics laboratory will consist of secure, access-restricted zones to ensure proper handling, storage,and analysis of digital evidence.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">The layout includes:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Evidence Storage Room: Secure, temperature-controlled area with individual evidence lockers and surveillance.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Two Analysis Workstations: Equipped with high-performance forensic computers, dual monitors, and write-blocking devices.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Imaging &amp; Acquisition Area: Dedicated space for forensic imaging with appropriate hardware and documentation stations.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Lab Manager Office: Contains case management tools, administrative systems, and secure document storage.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Security Elements: Badge\/PIN dual access control, and restricted access points.<\/span><\/p>\n<ol start=\"2\">\n<li><b> Equipment Inventory<\/b><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400\">Hardware:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Forensic workstations (2), dual 27-inch monitors, UPS backup units.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Tableau and WiebeTech forensic write-blockers.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Faraday boxes\/bags, mobile device extraction tools (Cellebrite, Oxygen Forensics).<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">RAID storage systems, PowerEdge R660 servers, cable kits, anti-static lab equipment, tool cabinets. Unitrends 9016S 16TB Backup Storage Appliance.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">NAS systems for secure storage and evidence backups.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Computer Chairs (29)<\/span><\/p>\n<p><span style=\"font-weight: 400\">RFID Badge readers<\/span><\/p>\n<p><span style=\"font-weight: 400\">APC SMT750RM2UC UPS, APC BE650G1 Desktop UPS<\/span><\/p>\n<p><span style=\"font-weight: 400\">PC Power Cables<\/span><\/p>\n<p><span style=\"font-weight: 400\">20 IDE Cables, 20 SATA Cables<\/span><\/p>\n<p><span style=\"font-weight: 400\">Juniper Switch EX2300<\/span><\/p>\n<p><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Software:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 EnCase Forensic, FTK, X-Ways Forensics, Autopsy Suites.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Cellebrite UFED, Oxygen Forensics, Magnet AXIOM Mobile.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Wireshark, Kali Linux, Ghidra, and volatility tools.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 VMware Workstation, malware sandbox environment, evidence management software.<\/span><\/p>\n<ol start=\"3\">\n<li><b> Accreditation Plan (ISO\/IEC 17025)<\/b><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400\">The lab will follow a structured 3\u2011year path toward accreditation under ISO\/IEC 17025 standards:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Year 1:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Develop Standard Operating Procedures (SOPs) for acquisition, analysis, reporting, and chain\u2011of\u2011custody.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Establish a Quality Management System (QMS) and perform internal audits.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Begin certification training for staff (CFCE, CCE, CHFI, GCIH optional).<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Year 2:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Implement accreditation-focused training and documentation.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Formalize equipment calibration, evidence handling, and peer review processes.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Conduct external proficiency testing.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Year 3:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Submit accreditation application to ANAB.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Complete pre\u2011assessments, address findings, and complete final evaluation.<\/span><\/p>\n<ol start=\"4\">\n<li><b> Lab Maintenance Plan<\/b><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400\">To maintain operational readiness and accreditation compliance, the following schedule will be used:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Daily Maintenance:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Validate write\u2011blockers and forensic tools.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Perform workstation performance checks.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Conduct evidence intake reviews and maintain cleanliness.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Weekly Maintenance:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Back up all case files to secure NAS.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Review chain\u2011of\u2011custody logs.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Reset malware sandbox environments.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Monthly Maintenance:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Hardware diagnostics, software integrity checks.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Update QMS documentation and inspect CCTV systems.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Annual Maintenance:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Renewal of licenses and certifications.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Complete forensic proficiency testing.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Full inspection and audit of evidence storage.<\/span><\/p>\n<ol start=\"5\">\n<li><b> Staffing and Job Descriptions<\/b><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400\">Two primary roles will be required for the initial launch of the lab:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Lab Manager:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Responsibilities:<\/span><\/p>\n<p><span style=\"font-weight: 400\">Direct and manage the day-to-day operations of the digital forensics lab, including workflow, resource allocation, and project prioritization.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Develop and implement standard operating procedures (SOPs) for data collection, preservation, and analysis that meet legal and forensic standards.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Oversee the maintenance and calibration of all forensic hardware and software, ensuring the lab is equipped with the latest tools and technologies.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Qualifications:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Certified Forensic Examiner (CFE), EnCase Certified Examiner (EnCE), or similar.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Relativity Certified Administrator (RCA) or other relevant eDiscovery software certifications.<\/span><\/p>\n<p><span style=\"font-weight: 400\">GIAC certifications (e.g., GCFA, GCFE) are a significant plus.<\/span><\/p>\n<p><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Digital Forensic Technician:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Responsibilities:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Conduct forensic imaging and data acquisition.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Maintain and inventory equipment.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Assist analysts with mobile and computer extractions.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Apply knowledge to the enforcement of Title 18, Title 31, and other applicable statutes of the Federal Criminal Code, and the seizure and forfeiture of illegally derived property<\/span><\/p>\n<p><span style=\"font-weight: 400\">Conduct research and analysis using open source information, national and international databases, and corporate record filings to match investigative findings and summarize data into a finished professional product<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Qualifications:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Associate or bachelor\u2019s degree in a technical field.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Experience with forensic tools and operating systems.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">Knowledge of chain\u2011of\u2011custody and evidence handling procedures.<\/span><\/p>\n<p><span style=\"font-weight: 400\">4+ years cyber fraud investigations related experience<\/span><\/p>\n<p><span style=\"font-weight: 400\">1+ years of experience supporting law enforcement with cryptocurrency investigations<\/span><\/p>\n<p><span style=\"font-weight: 400\">6+ months experience with blockchain intelligence tools (Chainalysis, TRM Labs, Elliptic)<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400\">Optional Year 3 Expansion:<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><span style=\"font-weight: 400\">\u2022 Additional examiner specializing in mobile, network, or malware forensics as case volume increases.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Conclusion: <\/b><span style=\"font-weight: 400\">This lab plan establishes a structured and sustainable framework for a fully operational digital forensics laboratory. Through proper planning, accreditation preparation, maintenance scheduling, and staffing, the lab will support reliable and defensible digital investigations for years to come.<\/span><\/p>\n<p>&nbsp;<\/p>\n<div>\n<p><b>Final Case report<\/b><\/p>\n<p>This project involved developing a digital forensics investigation report documenting the examination of a mobile device and laptop in a simulated investigation. I developed a forensic methodology that included evidence preservation, acquisition, imaging, hashing, artifact analysis, deleted-data recovery, timeline construction, and network and financial record correlation.<\/p>\n<p>&nbsp;<\/p>\n<p><b>Digital Forensics Investigation Report<\/b><b><\/b><\/p>\n<h3><span style=\"font-weight: 400\">Case Overview<\/span><\/h3>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Case Identifier \/ Submission #:\u202fDF-RUSINT-3255<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Case Investigator:\u202fKenneth Thomas<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Case submitted by: Kenneth Thomas<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Date of Receipt:\u202fNovember\u202f28,\u202f2023<\/span><\/li>\n<\/ul>\n<p><b>Back Ground and Context:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400\">The subject is a senior U.S. government official who has retained counsel and declined to comment on alleged contacts with Russian operatives (\u201cRed\u202fRalph\u201d). A forensic examination was performed on the subject\u2019s primary mobile device (Samsung\u202fGalaxy\u202fS23) and personal laptop (HP\u202fEnvy\u202f17\u2011T). The purpose of this report is to document the methodology, findings, and conclusions for possible use in criminal proceedings.<\/span><\/p>\n<h2><span style=\"font-weight: 400\">1. Items Submitted for Examination<\/span><\/h2>\n<table>\n<tbody>\n<tr>\n<td><b>Item<\/b><\/td>\n<td><b>Make \/ Model<\/b><\/td>\n<td><b>Serial #<\/b><\/td>\n<td><b>Color<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<\/tr>\n<tr>\n<td><b>Cellular Device<\/b><\/td>\n<td><span style=\"font-weight: 400\">Samsung\u202fGalaxy\u202fS23 (SM\u2011S911U)<\/span><\/td>\n<td><span style=\"font-weight: 400\">TMNT804S19A<\/span><\/td>\n<td><span style=\"font-weight: 400\">Graphite<\/span><\/td>\n<td><span style=\"font-weight: 400\">256\u202fGB, Android\u202f13, locked with PIN &amp; biometric lock.<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Personal Laptop<\/b><\/td>\n<td><span style=\"font-weight: 400\">HP\u202fEnvy\u202fLaptop\u202f17\u2011T (HP\u202f17T\u2011CW000)<\/span><\/td>\n<td><span style=\"font-weight: 400\">CND7613245890<\/span><\/td>\n<td><span style=\"font-weight: 400\">Silver<\/span><\/td>\n<td><span style=\"font-weight: 400\">15.6\u2033 FHD, Intel\u202fi7\u201112700H, 512\u202fGB SSD, Windows\u202f11 Pro.<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><span style=\"font-weight: 400\">2. Examination Environment &amp; Tools<\/span><\/h2>\n<table>\n<tbody>\n<tr>\n<td><b>Category<\/b><\/td>\n<td><b>Tool \/ Hardware<\/b><\/td>\n<td><b>Version \/ Source<\/b><\/td>\n<\/tr>\n<tr>\n<td><b>Hardware Write\u2011Blocker<\/b><\/td>\n<td><span style=\"font-weight: 400\">Tableau\u202fStandalone Forensic Imager (TD4)<\/span><\/td>\n<td><span style=\"font-weight: 400\">Firmware\u202f2.5<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Imaging Station<\/b><\/td>\n<td><span style=\"font-weight: 400\">UltraKit\u202fv5 + TD4 Forensic Imager<\/span><\/td>\n<td><span style=\"font-weight: 400\">Digital Intelligence<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Analysis Workstation<\/b><\/td>\n<td><span style=\"font-weight: 400\">FRED\u202fL Forensic Laptop (16\u202fCPU, 64\u202fGB RAM)<\/span><\/td>\n<td><span style=\"font-weight: 400\">Digital Intelligence<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Mobile Extraction<\/b><\/td>\n<td><span style=\"font-weight: 400\">MOBILedit\u202fForensics\u202fPro (Physical &amp; Logical)<\/span><\/td>\n<td><span style=\"font-weight: 400\">12.2<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>SIM Card Access<\/b><\/td>\n<td><span style=\"font-weight: 400\">USB\u2011CAC Smart Card Reader (Military grade)<\/span><\/td>\n<td><span style=\"font-weight: 400\">1.0<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Disk Imaging<\/b><\/td>\n<td><span style=\"font-weight: 400\">Tableau\u202fForensic Imager (E01 format)<\/span><\/td>\n<td><span style=\"font-weight: 400\">3.0<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>File &amp; Artifact Analysis<\/b><\/td>\n<td><span style=\"font-weight: 400\">Autopsy (Sleuth Kit)\u00a0 v4.24<\/span><\/td>\n<td><span style=\"font-weight: 400\">Open\u2011source<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Additional Utilities<\/b><\/td>\n<td><span style=\"font-weight: 400\">FTK Imager, Bulk Extractor, RegRipper, Wireshark (network capture), Hashcat (hash verification)<\/span><\/td>\n<td><span style=\"font-weight: 400\">Latest releases<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400\">All tools were verified for integrity (SHA\u2011256 hash match) prior to use. The examination followed NIST SP\u202f800\u2011101 and ACPO good practice guidelines.<\/span><\/p>\n<h2><span style=\"font-weight: 400\">3. Methodology<\/span><\/h2>\n<h3><span style=\"font-weight: 400\">3.1 Mobile Device (Samsung\u202fS23)<\/span><\/h3>\n<ol>\n<li style=\"font-weight: 400\"><b>Seizure &amp; Preservation<\/b><span style=\"font-weight: 400\">\u00a0 Device placed in Faraday bag; power left on to preserve volatile memory.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Acquisition<\/b><span style=\"font-weight: 400\">\u00a0 Performed a <\/span><i><span style=\"font-weight: 400\">logical extraction<\/span><\/i><span style=\"font-weight: 400\"> via MOBILedit\u202fPro (USB\u2011C cable) to obtain contacts, SMS\/MMS, call logs, app data, and cloud backups.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>SIM Card Bypass<\/b><span style=\"font-weight: 400\">\u00a0 Utilized the USB\u2011CAC reader to clone the SIM; MOBILedit\u2019s SIM\u2011PIN bypass removed the 4\u2011digit PIN without altering the original card.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Data Export<\/b><span style=\"font-weight: 400\">\u00a0 Exported artifacts to E01 container; generated MD5\/SHA\u2011256 hashes for each file.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Keyword &amp; String Searches<\/b><span style=\"font-weight: 400\">\u00a0 Executed targeted searches for: \u201cRalph\u201d, \u201cRed\u202fRalph\u201d, \u201cmeeting\u201d, \u201clunch\u201d, \u201cconsulting\u201d, \u201cpayment\u201d, plus Russian Cyrillic equivalents.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Deleted Data Recovery<\/b><span style=\"font-weight: 400\">\u00a0 Enabled \u201cundelete\u201d mode in MOBILedit to recover soft\u2011deleted SMS and app caches.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Timeline Construction<\/b><span style=\"font-weight: 400\">\u00a0 Correlated timestamps (UTC) with device clock drift correction (\u00b12\u202fseconds).<\/span><\/li>\n<\/ol>\n<h3><span style=\"font-weight: 400\">3.2 Laptop (HP\u202fEnvy\u202f17\u2011T)<\/span><\/h3>\n<ol>\n<li style=\"font-weight: 400\"><b>Write\u2011Blocking &amp; Imaging<\/b><span style=\"font-weight: 400\">\u00a0 Connected SSD via USB\u20113.0 to Tableau imager; created a bit\u2011for\u2011bit forensic image (E01) with SHA\u2011256 verification.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Verification<\/b><span style=\"font-weight: 400\">\u00a0 Compared hash of source and image; confirmed 0% mismatch.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Mounting &amp; Indexing<\/b><span style=\"font-weight: 400\">\u00a0 Mounted image read\u2011only in Autopsy; indexed all file systems (NTFS, FAT32 partitions).<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Email Extraction<\/b><span style=\"font-weight: 400\">\u00a0 Parsed Outlook PST files and local mail client SQLite databases; exported all inbound\/outbound messages.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Keyword Searches<\/b><span style=\"font-weight: 400\">\u00a0 Conducted Boolean searches for: (\u201cRed\u202fRalph\u201d OR \u201cRalph\u201d) AND (\u201cconsult*\u201d OR \u201cpayment\u201d OR \u201cfee\u201d).<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Deleted File Recovery<\/b><span style=\"font-weight: 400\">\u00a0 Employed Autopsy\u2019s \u201cFile Carving\u201d module (foremost) and \u201cSlack Space\u201d analysis to locate remnants of ZIP archives.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Metadata &amp; Hash Verification<\/b><span style=\"font-weight: 400\">\u00a0 Extracted EXIF, document properties, and computed SHA\u2011256 hashes for recovered files.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Web Log Correlation<\/b><span style=\"font-weight: 400\">\u00a0 Analyzed Chrome\/Edge browsing histories, DNS cache, and firewall logs; cross\u2011referenced timestamps with file\u2011upload timestamps from the file\u2011sharing service (see Section\u202f4).<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Financial Records<\/b><span style=\"font-weight: 400\">\u00a0 Imported PDF bank statements; performed OCR (Tesseract) to extract transaction dates, amounts, and counterparties.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400\">All actions were logged in a tamper\u2011proof chain\u2011of\u2011custody bags.<\/span><\/p>\n<h2><span style=\"font-weight: 400\">4. Findings<\/span><\/h2>\n<h3><span style=\"font-weight: 400\">4.1 Mobile Device Artifacts<\/span><\/h3>\n<table>\n<tbody>\n<tr>\n<td><b>Artifact<\/b><\/td>\n<td><b>Date\/Time (UTC)<\/b><\/td>\n<td><b>Details<\/b><\/td>\n<\/tr>\n<tr>\n<td><b>Contact Entry<\/b><\/td>\n<td><span style=\"font-weight: 400\">2015\u201112\u201103\u202f09:12\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">\u201cRed\u202fRalph\u201d\u00a0 Mobile #:\u202f +7(922)\u202f555\u20111543; label \u201cRussian liaison\u201d.<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>SMS Meeting Confirmation<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201102\u201114\u202f16:45\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">From:\u202f+7\u202f(922)\u202f555\u20111543 \u2192 Subject\u2019s number. &lt;br&gt;Message: \u201cLet\u2019s meet at Chili\u2019s on Main Street for lunch tomorrow at 12:00\u202fPM.\u201d<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>SMS Follow\u2011up<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201102\u201115\u202f08:02\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">\u201cLooking forward to our lunch at 12\u202fPM. Bring the documents.\u201d<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Deleted SMS (Recovered)<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201102\u201113\u202f22:30\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">\u201cDid you receive the files I sent?\u201d (sent by Subject).<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Cloud Backup Retrieval<\/b><\/td>\n<td><span style=\"font-weight: 400\">2023\u201112\u201108\u202f14:21\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">OneDrive sync log shows upload of \u201cmeeting_notes.docx\u201d (size\u202f42\u202fKB) on 2016\u201102\u201114.<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>App Data Messaging<\/b><\/td>\n<td><span style=\"font-weight: 400\">Various (2015\u2011202)<\/span><\/td>\n<td><span style=\"font-weight: 400\">WhatsApp logs contain encrypted blobs referencing \u201cRalph\u201d but no readable content after decryption failure (no key).<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3><span style=\"font-weight: 400\">4.2 Laptop Artifacts<\/span><\/h3>\n<table>\n<tbody>\n<tr>\n<td><b>Artifact<\/b><\/td>\n<td><b>Date\/Time (UTC)<\/b><\/td>\n<td><b>Summary<\/b><\/td>\n<\/tr>\n<tr>\n<td><b>Email Initial Contact<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201101\u201127\u202f13:04\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">From:\u202fofficial@state.gov \u2192 To:\u202fRedRalph@gmail.com &lt;br&gt;Subject: \u201cIntro &amp; Potential Collaboration\u201d.<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Email Consulting Agreement<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201102\u201102\u202f09:57\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">Attachment: \u201cConsult_Agreement.pdf\u201d (SHA\u2011256:\u202f3a1f\u2026e9c). Terms: $150,000 per month for \u201cstrategic advisory\u201d.<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Email Payment Confirmation<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201102\u201110\u202f18:22\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">From:\u202fofficial@state.gov \u2192 To:\u202fRedRalph@gmail.com &lt;br&gt;Body: \u201cWire transfer of $150,000 completed. Ref:\u202fTX\u201120260210\u2011US\u2011RUS.\u201d<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Email Follow\u2011up<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201102\u201114\u202f11:31\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">\u201cPlease confirm receipt of the documents before lunch tomorrow.\u201d<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Deleted ZIP Archives (Recovered)<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201102\u201113\u202f02:14\u202fUTC (carved)<\/span><\/td>\n<td><span style=\"font-weight: 400\">Two ZIP files (\u2248\u202f3.2\u202fMB total) containing: &lt;br&gt;\u2022 \u201cClassified_Documents\/Project_Sunscreen\u2011Report.pdf\u201d &lt;br&gt;\u2022 \u201cClassified_Documents\/Strategic_Plan.docx\u201d &lt;br&gt;Hashes:\u202fZIP\u20111\u202fSHA\u2011256\u202f=\u202fd4b2\u2026;\u202fZIP\u20112\u202fSHA\u2011256\u202f=\u202f9f73\u2026<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Web Upload Log<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201102\u201113\u202f02:20\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">Browser POST to \u201cfileshare.io\/upload\u201d\u00a0 filename \u201cProject_Sunscreen\u2011Report.zip\u201d; response code\u202f200; IP\u202f185.23.44.77 (Russia\u2011based CDN).<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Network Capture (Wireshak)<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201102\u201113\u202f02:18\u201102:22\u202fUTC<\/span><\/td>\n<td><span style=\"font-weight: 400\">TLS handshake to fileshare.io; encrypted payload size matches ZIP archive size.<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Bank Statements<\/b><\/td>\n<td><span style=\"font-weight: 400\">2015\u201112\u201101\u202f\u202f2016\u201103\u201101<\/span><\/td>\n<td><span style=\"font-weight: 400\">Multiple outbound ACH transfers to \u201cRedRalph LLC\u201d (Account\u202f#\u202f987654321, Routing\u202f021000021). Total transferred:\u202f$450,000.<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Windows Registry\u00a0 Run Keys<\/b><\/td>\n<td><span style=\"font-weight: 400\">2016\u201102\u201114\u202f07:45\u202fUtC<\/span><\/td>\n<td><span style=\"font-weight: 400\">Persistence entry for \u201csvchost.exe\u201d pointing to a renamed copy of \u201crussian_helper.dll\u201d in %APPDATA%.<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3><span style=\"font-weight: 400\">4.3 Corroborating Timeline<\/span><\/h3>\n<table>\n<tbody>\n<tr>\n<td><b>UTC Time<\/b><\/td>\n<td><b>Event<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400\">2016\u201102\u201113\u202f02:14<\/span><\/td>\n<td><span style=\"font-weight: 400\">Carved ZIP archives recovered from unallocated space.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400\">2016\u201102\u201113\u202f02:18<\/span><\/td>\n<td><span style=\"font-weight: 400\">Network traffic captured uploading the ZIPs to a foreign file\u2011sharing service.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400\">2016\u201102\u201114\u202f09:12<\/span><\/td>\n<td><span style=\"font-weight: 400\">Subject receives confirmation email from Red\u202fRalph (payment received).<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400\">2016\u201102\u201114\u202f16:45<\/span><\/td>\n<td><span style=\"font-weight: 400\">SMS confirming lunch meeting for next day.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400\">2016\u201102\u201115\u202f12:00<\/span><\/td>\n<td><span style=\"font-weight: 400\">Scheduled lunch at Chili\u2019s (verified via calendar entry on phone).<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400\">2016\u201102\u201115\u202f13:05<\/span><\/td>\n<td><span style=\"font-weight: 400\">Subject\u2019s phone logs show GPS coordinates matching Chili\u2019s location.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400\">2016\u201102\u201115\u202f13:30<\/span><\/td>\n<td><span style=\"font-weight: 400\">Subject\u2019s device disconnects from-network (possible post\u2011meeting data wipe).<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><span style=\"font-weight: 400\">5. Conclusions<\/span><\/h2>\n<ol>\n<li style=\"font-weight: 400\"><b>Existence of Direct Communications<\/b><span style=\"font-weight: 400\">\u00a0 Both the mobile device and laptop contain evidence of communication between the subject and an individual identified as \u201cRed\u202fRalph,\u201d a Russian contact (phone prefix\u202f+7). The messages clearly arrange a face\u2011to\u2011face meeting on February\u202f15,\u202f2016.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Financial Transactions<\/b><span style=\"font-weight: 400\">\u00a0 Bank records demonstrate three separate ACH transfers totaling $450,000 to an entity linked to the Red\u202fRalph email address, consistent with the \u201cconsulting services\u201d described in the recovered emails.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Transfer of Classified Material<\/b><span style=\"font-weight: 400\">\u00a0 Carved ZIP archives contain documents marked \u201cClassified\u00a0 Project\u202fSunscreen\u201d and \u201cStrategic Plan.\u201d Network logs confirm these files were uploaded to a foreign\u2011hosted file\u2011sharing service on February\u202f13,\u202f2016, two days before the scheduled meeting.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Intent to Conceal<\/b><span style=\"font-weight: 400\">\u00a0 Deletion of the ZIP archives, subsequent overwriting attempts, and the presence of a persistence mechanism (malicious DLL) indicate deliberate effort to hide the exchange.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Legal Relevance<\/b><span style=\"font-weight: 400\">\u00a0 The artifacts satisfy the evidentiary standards for relevance, authenticity, and chain\u2011of\u2011custody under Federal Rules of Evidence (Rule\u202f901\u2011902). The timestamps, hash values, and corroborating network logs provide a robust foundation for admissibility.<\/span><\/li>\n<\/ol>\n<p><i><span style=\"font-weight: 400\">End of Report<\/span><\/i><\/p>\n<\/div>\n<p class=\"p1\">\n","protected":false},"excerpt":{"rendered":"<p>Digital Forensics This course introduces the basic concepts and technologies of digital forensics. Students will learn the fundamental techniques and tools utilized for collecting, processing, and preserving digital evidence on computers, mobile devices, networks, and cloud computing environments. Students will also engage in oral and written communication to report digital forensic\u00a0findings and prepare court presentation&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/cyse-407\/\">Read More<\/a><\/div>\n","protected":false},"author":30543,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages\/127"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/users\/30543"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/comments?post=127"}],"version-history":[{"count":5,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages\/127\/revisions"}],"predecessor-version":[{"id":339,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages\/127\/revisions\/339"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/media?parent=127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}