{"id":336,"date":"2026-10-02T16:17:43","date_gmt":"2026-10-02T16:17:43","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/ycarp001\/?page_id=336"},"modified":"2026-10-05T15:57:57","modified_gmt":"2026-10-05T15:57:57","slug":"suspicious-login-incident-response","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/ycarp001\/suspicious-login-incident-response\/","title":{"rendered":"Suspicious Login &amp; Incident Response"},"content":{"rendered":"\n<p>Course: ITN 276 &#8211; Computer Forensics<\/p>\n\n\n\n<p>Artifact Type: Digital Forensics Investigation Lab<\/p>\n\n\n\n<p>Semester: Spring 2024<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p>This lab involved conduction a digital forensic investigation of a suspicious login attempt. Using Paraben E3, I examined digital evidence associated with the incident to identify information that could help retrace the activity that occurred. The investigation required me to look into multiple sources of evidence, document relevant findings, and prepare information that could be used in an incident response investigation<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">My Work<\/h2>\n\n\n\n<p>During the investigation, I identified evidence of suspicious activity. This included reviewing activity with an FTP connection, identifying files transferred through the connection, documenting the connection time, and identifying the source and destination IP addresses. I also found incriminating email evidence and bookmarked relevant information within the software. As I worked through it, I gathered my findings through screenshots to support the investigation. I also generated forensic reporting information and recorded evidence such as the MD5 hash associated with an identified file.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Artifact<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"592\" height=\"765\" src=\"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-content\/uploads\/sites\/38478\/2026\/10\/image.png.png\" alt=\"\" class=\"wp-image-372\" style=\"width:463px;height:auto\" \/><figcaption class=\"wp-element-caption\"><em>Figure 1. Examination of email evidence<\/em><\/figcaption><\/figure><\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"742\" height=\"802\" src=\"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-content\/uploads\/sites\/38478\/2026\/10\/image.png-1.png\" alt=\"\" class=\"wp-image-373\" style=\"width:632px;height:auto\" \/><figcaption class=\"wp-element-caption\"><em>Figure 2. Relevant file evidence<\/em><\/figcaption><\/figure><\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"826\" height=\"710\" src=\"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-content\/uploads\/sites\/38478\/2026\/10\/image.png-2.png\" alt=\"\" class=\"wp-image-374\" style=\"width:638px;height:auto\" \/><figcaption class=\"wp-element-caption\"><em>Figure 3. Documented forensic findings<\/em><\/figcaption><\/figure><\/div>\n\n\n<h2 class=\"wp-block-heading\">Skills Demonstrated<\/h2>\n\n\n\n<p>This lab strengthened my cybersecurity analysis and investigation skills by requiring me to examine multiples pieces of digital evidence and determine which information was relevant to an incident. Rather than looking at each piece separately, I had to connect details such as file activity, network information, timestamps, and email evidence to better understand the activity being investigated. <\/p>\n\n\n\n<p>The lab also have me hands-on experience documenting forensic findings in a structured manner. It reinforced the importance of carefully examining evidence and approaching digital investigations in a thorough and systematic way.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Course: ITN 276 &#8211; Computer Forensics Artifact Type: Digital Forensics Investigation Lab Semester: Spring 2024 Overview This lab involved conduction a digital forensic investigation of a suspicious login attempt. Using Paraben E3, I examined digital evidence associated with the incident to identify information that could help retrace the activity that occurred. The investigation required me&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/ycarp001\/suspicious-login-incident-response\/\">Read More<\/a><\/div>\n","protected":false},"author":30530,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-json\/wp\/v2\/pages\/336"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-json\/wp\/v2\/users\/30530"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-json\/wp\/v2\/comments?post=336"}],"version-history":[{"count":3,"href":"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-json\/wp\/v2\/pages\/336\/revisions"}],"predecessor-version":[{"id":375,"href":"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-json\/wp\/v2\/pages\/336\/revisions\/375"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/ycarp001\/wp-json\/wp\/v2\/media?parent=336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}