SCHOOL OF COMPUTER SCIENCE AND ENGINEERING
Fall Semester 2021
Course Code : CSE 4004
Programme : B.Tech CSE
Course: Digital Forensics (DF)
Slot: F1 +TF1
Faculty: Prof.Naresh K
Name:
• VEDANT DHAMIJA ( 17BCE0130)
• SAMARTH SINGH ( 17BCE004)
• APURV ADITYA ( 17BCE2302)
• ROHAN RAMAN ( 17BCE0266)
• PULKIT GUPTA ( 17BCE0631)
VIDEO LINK :
https://drive.google.com/file/d/1NMGjczfDyazcg2nNieZ9qPycKbB36FxA
/view?usp=sharing
OSForensics
OSForensics is a commercial computer forensics package for the Windows
operating system that reveals a plethora of information about the
underlying PC. The tool has been designed by its developers to aid
forensic specialists with the discovery of relevant forensic data, the
identification of suspicious files and activities, and the management of the
information. OSForensics lets you extract forensic evidence from
computers quickly with high performance file searches and indexing.
Identify suspicious files and activity with hash matching, drive signature
comparisons, e-mails, memory and binary data. Manage your digital
investigation and create reports from collected forensic data.
Demonstration of OS Forensics on Word File.
Step 1: Create a word file (Os Forensics Lab4).
Step 2: Open OsForensics trial version and select file and hex viewer
Step 3: Select the correct word file to be investigated from the dialog
box
Step 4 : After opening we get 5 tabs given the information about the
file .
File Viewer
File Info
Metadata
WinHex
WinHex is in its core a universal hexadecimal editor, particularly helpful
in the realm of computer forensics, data recovery, low-level data
processing, and IT security. An advanced tool for everyday and emergency
use: inspect and edit all kinds of files, recover deleted files or lost data
from hard drives with corrupt file systems or from digital camera cards.
Step 1: Create different files on USB drives
Step 2: Open WinHex and select open drives from tools
Step 3: We can see the file extension in Hexa Code and Tabular form