NUST Institutional Repository

FERRET Active forensic analysis of Windows-based computers

Show simple item record

dc.contributor.author Abeer Khan
dc.date.accessioned 2020-11-11T11:14:15Z
dc.date.available 2020-11-11T11:14:15Z
dc.date.issued 2008
dc.identifier.uri http://10.250.8.41:8080/xmlui/handle/123456789/11492
dc.description Supervisor: Dr. Fauzan Mirza en_US
dc.description.abstract In today’s world, the use of computers is increasing. Where on one hand the use of technology has created many miracles, on the other hand it has given rise to cybercrime (computer-related crime) such as hacking, phishing, identity theft, child pornography, online gambling, securities fraud, etc. Digital Forensics is all about acquisition of data from digital information systems (e.g., computers, mobile phones, MP3 Players, digital cameras, etc) and then analyzing this data for investigations related to a particular event. This project proposes the research of digital evidence aspects of the Windows operating system and applications and development of a Windows-based digital evidence investigation toolkit. This collection of tools enables an investigator to quickly and easily extract detailed information about the use of a Windows-based computer system. The project caters four basic modules of the forensic analysis; system data, browser data, passwords and file related data. System data extractor extracts information about USBs attached to system, system restore points and open windows. Password Recovery tools extracts windows messenger passwords. File data extraction parses Office files and image files to retrieve file properties. The last tool, the browser data extractor retrieves browser history, favorite links and searched strings. Such data is extremely valuable for both law-enforcement and corporate policy breach investigation. The limitations of this project are that it is limited to Windows XP operating system. Secondly, it parses only Office 2003 files and retrieves the history for only Internet Explorer 6.0. The toolkit has been tested on various system and files which ensures its reliability. en_US
dc.publisher SEECS, National University of Sciences and Technology, Islamabad en_US
dc.subject Information Technology en_US
dc.title FERRET Active forensic analysis of Windows-based computers en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

  • BS [440]

Show simple item record

Search DSpace


Advanced Search

Browse

My Account