Contemporaneous Notes
Exam
Examiner Bibek Pandeya
24th November 2024
commenced
Other Software used,
relevant Any relevant information? versions and 1.
information licensing
Note: If you decide to omit a process, then you should provide your reasons for doing so. You may add additional rows, as appropriate.
Action Done? Date Time Notes
Load case and verify image Yes 24th November 1:26 PM 1.
2024
Action Done? Date Time Notes
Action Done? Date Time Notes
Action Done? Date Time Notes
Load Case into second forensic tool for dual Yes 24th November 2024 2:45 PM
verification of at least 2 key artefacts,
evidence items
Action Done? Date Time Notes
Action Done? Date Time Notes
Action Done? Date Time Notes
Action Done? Date Time Notes
Action Done? Date Time Notes
Action Done? Date Time Notes
Time Zone Adjusted? Yes 25th November 2024
Report Time Zone used for Analysis.
Action Done? Date Time Notes
Action Done? Date Time Notes
Action Done? Date Time Notes
Action Done? Date Time Notes
.
Action Done? Date Time Notes
Action Done? Date Time Notes
Action Done? Date Time Notes
Recover lost folders
(NTFS, FAT16&32).
Mount archives;
zip, thumbs.db, etc.
Action Done? Date Time Notes
Action Done? Date Time Notes
Action Done? Date Time Notes
File signature analysis (any interesting file
mismatch?);
Compute hash values (enable entropy
computation)
Action Done? Date Time Notes
Internet History, favourites, etc.
Other browsers?
Action Done? Date Time Notes
Emails, local and web-based.
Retrieve operating system information,
accounts information, software, time zone
information etc.).
Timeline analysis-
Note date of last activity on the computer.
System profiling.
Registry analysis and
Registry protected area
Link files and Recycle Bin
Instant Messaging clients
Clean-up/Wiping utilities. Check log files.
Anything used?
External drives; Network connections
Perform data carving
Action Done? Date Time Notes
Run relevant keyword searches;
Did you index the evidence file?
Recover Log-on passwords –
use SAMInside/Ophcrack/Encase
Examine different file types:
Export doc/office and exe files; look at
Metadata if required
Encryption, Steganalysis (any indications?
Entropy or Autopsy can be used)
Print artefacts
CD/DVD burning apps; check log files
Validate evidence integrity at the end of the
examination
Additional Notes/Artefacts Examined:
Colour-coding
Tasks
Legend
Fundamental
Basic
Elementary
Secondary
Advanced
Exceptional