Digital Forensics Investigation of a USB Device: Evidence Acquisition, Analysis and Reporting

University:
Coventry University
Subject:
Digital Forensics / Cyber Security
Module:
Digital Forensics
Level:
Masters / Postgraduate
Assignment Type:
MS Technical and scientific writing
Word Count:
3,000 words
Academic Year:
2025–2026

Assignment Overview

This Digital Forensics assessment requires students to undertake a simulated professional investigation of a USB storage device while acting as a digital forensic trainee for a fictional forensic-services organisation. The nature of the suspected wrongdoing is initially unknown, requiring the investigator to apply appropriate forensic methodologies, tools and analytical techniques to identify suspicious activity, recover relevant artefacts and determine whether evidence of malicious or unauthorised behaviour exists. 7070SCN_Assessment Brief_2526MA… The investigation begins with authorisation, evidence handling and chain of custody. Students must demonstrate secure receipt and management of the USB device, operate within the authorised scope of the investigation and maintain records covering each stage of the evidence lifecycle. Forensic acquisition requires use and validation of a software write blocker, creation of bit-for-bit forensic images and cryptographic hashing to demonstrate that working and evidential copies maintain integrity. 7070SCN_Assessment Brief_2526MA… The analytical stage involves examination of the working forensic image using appropriate digital-forensic tools. Students investigate file-signature mismatches, password-protected files, registry artefacts, USB history, user activity, metadata and timeline relationships. Where suspicious executable files are discovered, static and/or dynamic malware analysis may be undertaken. The investigation can therefore span documents, images, applications, executables and registry hives. 7070SCN_Assessment Brief_2526MA… Students must maintain objective and chronological forensic case notes documenting evidence acquisition, preservation, analysis and interpretation. These records should support reproducibility and potential evidential admissibility. The final forensic report summarises findings, explains and justifies the tools and methodologies used, records integrity-verification results, discusses relevant legal, ethical and professional principles and provides appropriate recommendations for further action. 7070SCN_Assessment Brief_2526MA… The assessment also encourages advanced forensic analysis where relevant, including OSINT, password recovery or decryption, data carving, regular-expression searching, advanced registry analysis and static or dynamic malware investigation. Professional practice is assessed through adherence to recognised forensic methodologies, industry best practice, legal and ethical obligations, chain-of-custody records and evidence-handling procedures. 7070SCN_Assessment Brief_2526MA… Overall, the coursework integrates forensic acquisition, evidence preservation, artefact analysis, advanced investigation techniques, professional documentation and legally defensible reporting within a realistic digital-forensics case-study environment. Important for your public Reference Library: this brief explicitly states that it is for Coventry University Group students' own use and must not be passed to third parties or posted on any website. 7070SCN_Assessment Brief_2526MA… So use the metadata and an original high-level overview like the one above, but do not upload or publicly reproduce the assessment brief itself.

Megaminds Experience

Megaminds has supported academic requirements in digital forensics / cyber security, digital forensics and related disciplines.