Physical and Digital Evidence
- Describe the volatile live acquisition process to collect evidence related to system memory and registry changes and analysis methods conducted over this evidence.
- Describe the non-volatile acquisition process of evidence collection over powered down systems and devices, and the related analysis methods used over non-volatile evidence.
- Describe the exact investigative techniques that you would use to analyze the users’ information, habits, and history for each program. Explain the reasons for your selected techniques.
Remember to address forensic evidence you might find relating to the ransomware attack. You should be making references to specific directories, files, file types, registry entries and log files which point to sources of the incident forensic evidence.
The 16-18 slide PowerPoint presentation should include the following:
- Title Slide (1)
- Topics of Discussion Slide (1)
- Windows 10 Operating System (3 slides)
- Registry and Memory (2 slides)
- Internet Explorer (3 slides)
- Outlook e-mail (2 slides)
- Photoshop (2 slides)
- Office (3 slides)
- References Slide (1)
Please add your file.
For assistance with your assignment, please use your text, Web resources, and all course materials.
Previous answers to this question
This is a preview of an assignment submitted on our website by a student. If you need help with this question or any assignment help, click on the order button below and get started. We guarantee authentic, quality, 100% plagiarism free work or your money back.