Digital Forensics:Belkasoft Evidence Center X Challenge
Prerequisites:
1. Install Belkasoft Evidence Center X (request a trial version at https://belkasoft.com/get).
Make sure you chose to install sample data image during the product installation.
2. Create a new case
3. Add "samples.E01" as a an Image. The path to the file looks like "C:\Program
Files\Belkasoft Evidence Center x64 10.0\Sample Data".
4. Settings:
- Analysis type: everything except "Snapshots"
- Carving type: select "Carve free space"
- Artifacts: make sure all types are selected
- Media: select "Faces" and "Text (English)"
- Encryption: search for encrypted files and volumes
5. Enter passwords for iPhone backup, Chrome and weChat - find them in C:\Program
Files\Belkasoft Evidence Center x64 10.0\Sample Data\Passwords.
The challenge questions.
1. How did the picture “Gun_9mm.png” get into the data source?
2. How many Cookies records have been found for the “youtube.com” host?
3. What is the geolocation data (Latitude, Longitude) for the point “Aviaticka,
16108 Praha 6, Czech Republic”?
4. How many pictures are taken by iPhone 4? (Hint: use filters in List View)
5. What is “Date and time of original data generation” of “iphone_London.jpg”?
6. Which pictures contain guns? (Hint: if you have a full-featured license of
7. What types of files are found within the following data range: 01/01/2013-
8. What is the database size for “live%003a.cid.5240e092bf788b59” Skype
9. What is the complexity of decrypting the document “protected2.pdf”?
10. How long was the first sleeping period of Detective Blore on 11/15/2018
according to MiFit records?
4 hours 37 minutes
11. What famous composer is mentioned in the case key dictionary?
12. Look for an address containing “Westminster” in conversations. What is the
13. What Wi-Fi network was connected on 9/23/2016?
14. Who is the sender of an email, containing a California Zip code?
15. What phone numbers does Professor have in his iPhone WhatsApp address
book? (Hint: check it in ContactsV2.sqlite, using built-in SQLite Viewer. Find the
database using “Show in File System” option)
First steps with Belkasoft X
Ref: More useful information for you:1) Belkasoft tutorials at https://belkasoft.com/tutorials
2) Belkasoft User Reference in your Belkasoft product and at https://belkasoft.com/downloads/info/Evidence%20Center%20Help.pdf
หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น
* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ
#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics
#digitalforensics #investigation #cybercrime #fraud
No comments:
Post a Comment