Scope of the Project
This project goal is to prepare the digital forensic report for Exotic Mountain Tour Services Organization. The digital forensic report is used to investigate the probable intellectual property which is stolen by the Bob Aspen who is working as a contract employee of the EMTS (Exotic Mountain Tour Services). The EMTS organization has the completed analysis and very expansive marketing process on the customer services and it is provided by the superior bicycle LLC Company.
The EMTS organization requires the new data recovery, because the current data recovery process does not provide the effective data recovery from hard drives. And, it also plans to do the effective and efficient advertisement for joining the product deal of superior bicycles which is their tour service. Generally, this organization is used to ensure the promoting effort material under the concurrence of disclosure with superior bicycle. The EMTS organization lost and deleted the important information from hard drive. So, the EMTS chief has decided to recover the intriguing data and it is handled by web server executive that is Bob Aspen. The web server executive is ensuring the deleted data and also recovers the data by using the digital forensic tools. The EMTS organization has web based email activity through the organization system and distinguishes the suspicious connection. So, here the suspicious data is deleted and it needs to be recovered from an organization.
1.1 Scope
The scope of this project is to prepare the digital forensic report for an EMTS organization. Because, this organization lost the suspicious data and it needs to be recovered by using the digital forensic tools. We will recover the deleted or lost file which is suspicious data that is related to the provided case scenarios. The EMTS organization chief has decided to recover the deleted data from USB by using the appropriate digital forensic tool. In the provided the case scenarios, we are going to use the stenography tool to recover the hidden text in the image, Winhex tool is used to recover the deleted image from USB and the pro discover tool is used to recover the delete file from USB. The forensics tools are needed to analysis before finding the evidence for an EMTS organization.
1.2 Forensic Tools
The EMTS organization is decided to use the below forensic tool to recover the data from USB. These are,
- Winhex tool
- Pro Discover Tool
- Stenography Tool
2. Analysis
2.1 Winhex Tool
The Winhex forensic tool is the most common editor for universe hex editor and it is very useful for an EMTS organization. The Winhex tool is also useful for data recovery from USB, hard drive and etc. It is helpful for realm of low level data editing, computer forensic and data recovery. This tools are used to edit and recovery the following aspects like CD-ROM, hard disks, DVD, compute flash, floppy disks, computer RAM, all types of drive and all kinds of file.
Tools Used for Digital Forensics
The Winhex tool supports the FAT12, FAT16, FAT32 and NTFS to provide the effective data recovery and it is very useful for inspects and also editing the recovered lost files, data files and all kinds of the files from corrupted file system and hard drive. It especially supports the domain of the IT security, low level preparing, PC legal science and information recuperation. It investigates and utilizes the wide range of lost information, erased document and documents from hard drive and USB with degenerate the document frameworks from advanced camera cards.Many organizations are using this tool to provide the effective data recovery, because it is generally fast.
2.2 Pro Discover Tool
The pro discover tool is used to recover the data from hard drive, USE and more. It provides the cutting edge feature in the industry standards for proactive computer forensics. It is the powerful computer security tool that enables the computer professionals to locate the all data on a computer disk and it protects the evidence. It creates the quality evidentiary reports for used in legal proceedings. It uses the least destructive methodology to allow the examination of files without altering the valuable Meta data such as last time accessed file. The pro discover forensic tool is used to recover the deleted files, access windows alternate data streams, examine the slack space and dynamically allows preview, image and search the hardware protected area of the disk to utilizing the files by using the pioneered technology. It allows the users to search the entire disk for keywords, phrases, regular expression and also uses Boolean search capability to determine the necessary data.
2.3 Stenography Tool
The steganography tool is used to hide the secret information which is invisible in an image and audio file by using the steganography techniques. It modifies the least significant bits of the pixels in images and adds the noise to the audio samples to hide the information. It is used to provide the best way to protect the privacy of EMTS organization and it makes to hard to determine that any private communications are taking place. It uses the steghide program to perform the steganography and the files are generated to fully compatible with steghide. The tool is used to hide a message with the function normally and the user will not suspect just by looking the file. It has various conditions to hide the information and it needs the secure transmission of files. It reduces the chance of data leakage.This tool has the various ways of achieving the steganography in digital communication. It does not need to perform the coding to achieve this. This tool can be used to hide your secret text behind the HTML file, Docx file, image files and any other kind of file.
3. Findings
3.1 Recover the deleted image in the usb Using Winhex
The Winhex recovery tool is used to recover deleted image from USB. This is very popular data recovery tool and it is very useful this organization. It also recovers the corrupted images. The below screenshots is used to show the corrupted images and it needs to be recovered by using the Winhex recovery tool (AG, 2018).
3 Conclusion
This project is prepared the digital forensic report for an EMTS organization by using the provided case study. So, we are recovered the deleted file from USB by using the appropriate digital forensic tools and it is used to accomplish the recover process. In the provided case study, the deleted file from USB is recovered by using the pro discover tool, the hidden images from USB is also recovered by using the steganography tool and the deleted image from USB is recovered by using the Winhex tool. These are analyzed in detail.
References
AG, X. (2018).WinHex: Hex Editor & Disk Editor, Computer Forensics & Data Recovery Software.
Best Tools to Perform Steganography. (2018).
How to use ProDiscover, ProDiscover Forensics,. (2018).
Kolla, A. (2018). 10 Best Steganography Tools/Software which are Free to Use.
ProDiscover Forensic Data Recovery. (2018).
ProDiscover Forensics – Software – Products. (2018).