You have been hired by Acme Corporation to conduct a Computer Forensic examination of the computer workstation of a recently terminated employee, Wile E. Coyote. It is suspected that Coyote, prior to his termination, stole intellectual property for several patent pending destructive devices being developed by the R & D division of Acme Corp. It is suspected that while employed as an accountant for Acme Corporation, Wile E. Coyote stole secret plans, blue print, and product sketches for the purpose of starting his own Destructive Devices company and developing his own products based on the Acme pending patents.
In the performance of his accounting duties at Acme, Coyote was not involved in R&D at any time, nor had any connection to the R&D department, and should not have been in possession of any plans, sketches, or other intellectual property for any products.
You have been provided a 4G zipped (16 unzipped) “dd” forensic image of the hard drive Coyote’s Windows 7 computer workstation. It is your job to try to find digital evidence of the suspected theft. The evidence may include a variety of Windows 7 OS artifacts and/or actual computer files containing product sketches, blue prints, materials lists, or any other related digital evidence supporting the allegations that Coyote stole sensitive Acme Corporation intellectual property. You will be expected to use the tools and techniques you learned in CSF410 and CSF412/512 to conduct a thorough forensic examination of the hard drive image and answer the questions in the final based on your examination findings.


0 comments