Digital Forensics Investigation: USB, Memory and Windows Registry Analysis
This Digital Forensics Investigation Report presents a multi-source forensic examination involving removable media, volatile memory and a Windows disk image. The work is undertaken within an MSc Cyber Security context and demonstrates the application of forensic procedures, specialist analysis tools and evidential reasoning to investigate suspected criminal and malicious activity. The report places particular emphasis on maintaining evidence integrity, reconstructing activity across different forensic sources and correlating artefacts to produce defensible investigative findings. DF_Report_Sathiyaprakash The first part investigates a FAT32 USB forensic image associated with suspected video piracy and other potentially criminal activity. The examination uses tools including FTK Imager, Autopsy, Sleuth Kit, ewfmount, cryptographic hashing utilities and VeraCrypt. The methodology includes pre- and post-examination hash verification, read-only mounting, filesystem enumeration, deleted-file analysis and low-level sector examination. The investigation identifies deleted artefacts, portable anti-forensic utilities, browser evidence and an encrypted VeraCrypt container concealed within unallocated disk space. DF_Report_Sathiyaprakash The USB investigation also demonstrates the importance of evidence integrity and chain of custody. MD5 and SHA-256 hashes are used to establish and later confirm the integrity of forensic copies, while analysis is conducted without modifying the original evidence. The report examines filesystem structures, deleted files, anti-forensic tooling and encrypted data and records evidence handling through a formal chain-of-custody process. DF_Report_Sathiyaprakash DF_Report_Sathiyaprakash The second part focuses on volatile-memory forensics using a Windows memory image. Volatility 3 is used to identify the operating-system profile, reconstruct process hierarchies, inspect process ownership and security identifiers, and extract suspicious process memory. Particular attention is given to AtomicService.exe, which is observed running with SYSTEM privileges and associated with the Atomic Red Team framework and MITRE ATT&CK technique T1543.003 – Windows Service. The investigation also considers PowerShell activity, process execution timelines and indicators of suspicious behaviour. DF_Report_Sathiyaprakash DF_Report_Sathiyaprakash The third part conducts Windows Registry forensic analysis on the WinRegEvidenceP3.vhd image. Registry artefacts are examined using RegRipper, with analysis covering SYSTEM, SOFTWARE, SAM and NTUSER.DAT hives. The investigation evaluates system configuration, user accounts, application execution and persistence evidence using artefacts such as Run keys, BAM, Prefetch and scheduled tasks. These findings are then correlated with evidence recovered from volatile memory to reconstruct the sequence of suspicious activity. DF_Report_Sathiyaprakash Across the report, evidence from disk, memory and the Windows Registry is combined to reconstruct malicious activity and identify persistence mechanisms, elevated processes, suspicious user accounts and adversary-simulation tools. The analysis maps relevant behaviour to the MITRE ATT&CK framework and considers both technical findings and their evidential significance. The report therefore demonstrates practical competence in forensic acquisition principles, artefact analysis, timeline reconstruction, malware and process investigation, evidence correlation and professional reporting. Important for the Reference Library: this upload contains an actual student name on the cover page and detailed case evidence. Since your Reference Library says there is no student record behind uploaded past work, I would use the generic title and overview above rather than copying the student-identifying cover-page information into the public metadata. DF_Report_Sathiyaprakash
Read Model Answer →