
- #PRODISCOVER BASIC IOLOGERRORS PRO#
- #PRODISCOVER BASIC IOLOGERRORS PLUS#
Voila! All of the files that were ever on the hacker’s flash drive are now available for you to see in the ProDiscver window…EVEN THE DELETED ONES!ĭeleted files will have a red X beside their names with all details about creation, modification and deleted dates. Click on path to file “Camp Mystery Case” ending in. #PRODISCOVER BASIC IOLOGERRORS PLUS#
Under the Content View Folder Click the Plus Sign (+) beside the word “Images”. In left menu of the main ProDiscover screen:. Eject the Flash Drive from the computer. Once the Capture successfully completes you should see this message on your screen. This is what the screen should look like: Wait a while as the image of the hacker’s flash drive is captured. Add a brief Description in the description field if you wish. Add your team name in the field for Technician Name. Leave all other fields as defaults for this window. Enter File Name for the image such as “Camp Mystery Case”. Click “ Choose Local Path” from the menu that pops up. Click the Double Arrows beside Destination field. Select the Source Drive to Be F:\3.738… …(flash drive). Click on the Action Tab in the top left corner of the screen. Enter Brief Description such as: Finding evidence to solve the summer camp hacking mystery.
Enter a Project Name such as: Camp Mystery.
#PRODISCOVER BASIC IOLOGERRORS PRO#
Click on the Pro Discover6 Basic Icon on your desktop to open ProDiscover.
Using the ProDiscover Tool to retrieve deleted evidence
Close all windows once you finish making your notes. Make a note of what you see (the file names and what they contain). View/ Open each of the files or folders that are on the flash drive. Double Click to Open Removable Disk F (The Flash Drive). Click on Removable Disk F.(or I or J…it may be different depending on which USB port you used on your computer). Insert the flash drive given to each team leader into one of the USB Ports on the computer. It is the flash drive of suspected hacker………………….We seized the flash drive from him/her to carry out a simple forensics check to see if we can find any evidence that links him to the cybercrime that he is suspected of. Each team has been given a flash drive to use for this exercise. COMPUTER FORENSICS ACTIVITY – ProDiscover