首页 > 其他分享 >COM6016 Cyber Threat Hunting

COM6016 Cyber Threat Hunting

时间:2024-12-12 19:42:38浏览次数:2  
标签:Hunting company been 2024 forensics Cyber Threat Xaiver was

COM6016: Cyber Threat Hunting and Digital Forensics

Forensics Case Study Assessment , October 2024

Submission Deadline: 15:00 on Monday, 16th December 2024

This assignment is worth 60% of the module mark. This assignment is made up of  four different parts. You are required to answer all the questions below. All answers must be supported with adequate academic references.

The document should be formatted using 12 point font size. The maximum number of pages for this assignment should not exceed 12 pages.

PART 1 [20%]

Sarah, a long-time employee at Spark Toys, was recently passed over for a promotion, leading to a decline in her morale. Shortly after, a significant data breach occurred, compromising sensitive company and customer information.

Due to performance issues and suspected misconduct, Sarah was suspended and is currently under internal investigation for sending offensive messages. Her company-issued laptop has been seized and a memory image acquired as part of the investigation.

Recent news indicates that Sarah has resigned from Spark Toys and accepted a position at a direct competitor. It is suspected  she might have been involved with the data breach.

Using your knowledge of Digital Forensics and the Digital Forensics process, describe how you would approach this case. You should ensure to discuss relevant  information that could be retrieved from the memory of the device showing evidence of how this might be retrieved.

PART 2 [45%]

Xaiver is a staff member of CR BioTech, a company based in London at the forefront of cutting edge treatments for the flu.

Xaiver is suspected of stealing chemicals and customer data from CR BioTech. She has also recently become a person of interest in an ongoing INTERPOL case involving the international export and sale of counterfeit cat flu medication. The  counterfeit medication has been known to cause ‘gingivitis’ (inflammation of the mouth) and ulcers within three weeks of completing the suggested doses.

Yusuf, one of  Xaiver’s suspected accomplices 代写COM6016  Cyber Threat Hunting  who is now in custody, has suggested that the duo have made over £600,000 in sales of the counterfeit drug to more than 12 countries this year.

Xaiver has been arrested and two USB drives have been retrieved from her. The  disk images of the USB drives have been made available to you - USB1.E01 and USB2.E01 (attached on blackboard and also provided to you on the forensics laptop).

Assume you work for PRISM forensics, an organisation providing forensics, first respondents and incident response services to various regional Police units and INTERPOL.

You are required to write a maximum of a 5 page forensics report explaining how you went about your investigation and highlighting potential pieces of evidence that suggest that Xaiver was or was not involved in selling and exporting counterfeit drugs.

PART 3 [15%]

BridgePay, is a digital escrow payments service based in the UK. Their core application consists of a web application and SQL database hosted on various Ubuntu 18 servers.

From the web front-end, staff of BridgePay can access an administrator-only area where they can view transactions made by customers. The web-based front-end

and the mobile app can also be accessed by customers (buyers and sellers) using a web browser.

On the 3rd of June 2024, the company went through a security audit and it was identified that some of its applications are vulnerable to

● CWE-434: Unrestricted Upload of File with Dangerous Type

● CWE-78: Improper Neutralisation of Special Elements used in an OS Command ('OS Command Injection')

● CWE-918: Server-Side Request Forgery (SSRF)

On the 19th of October 2024, at 3pm, the company received an email from a third party claiming to have accessed its IT network and downloaded its customer's data requesting for a payment in bitcoin within three days to avoid public release of the data.

Assume, you work for BridgePay as an incident response and forensics analyst, explain how you would go about handling this incident to ensure digital evidence is captured,forensics integrity is maintained and the business operations suffer minimal impact.

PART 4 [20%]

Your colleague, an IT administrator, suspects there is some suspicious activity going on, you have been provided a network capture. Using your knowledge of cybersecurity and network forensics,  you are required to analyse the PCAP file 2024_part_4.pcapng and suggest what you think might be going on in the network packet sequence.

 

标签:Hunting,company,been,2024,forensics,Cyber,Threat,Xaiver,was
From: https://www.cnblogs.com/CSE2425/p/18600593

相关文章

  • V1 Cyberpunk Edgerunners
    \(“Whether\I've\let\you\down...my\love...”\)这是一个全新的时代,却也是一个悲剧的时代。It'sanewera,butatragicera.赛博朋克,1983年,一个名叫威廉吉布森的少年,在打字机前敲出霓虹灯与混沌的新世界。Cyberpunk,anewculturearisenfromayoungmannamed......
  • 【Unity 手枪模型和材质插件】Cyberpunk Handguns (Cyber, Guns) 高质量手枪模型及其
    CyberpunkHandguns(Cyber,Guns)是一款专为Unity开发的插件,提供一系列具有未来科技感的手枪模型和材质,适用于赛博朋克风格的游戏或场景。这个插件为开发者提供了高质量、细节丰富的武器资源,能够帮助游戏快速构建充满未来感的枪械系统。主要特点:高质量的赛博朋克风格手......
  • C++编程:通过简单实现理解CyberRT的DataVisitor和DataDispatcher
    文章目录0.引言1.定义DataVisitor接口2.实现DataDispatcher3.创建具体的DataVisitor4.类关系图5.测试示例6.编译和运行0.引言本文简单实现类似CyberRT的DataVisitor和DataDispatcher,使得数据能够被分发给多个订阅者(访客)。1.定义DataVisitor接......
  • ESP32 TWAI CAN Arduino库驱动小米电机(CyberGear微电机)
    前言鉴于项目要使用小米电机,并且要使用esp32上自带的CAN库来控制,但是没有找到合适的、能用的库,只能从现有STM32小米电机控制库的基础上进行修改。为了方便快速实现,采用Arduino的平台对esp32进行编程,对应需要修改成Arduino的库一、前置任务CAN通信基础ESP32自带CAN控制器—TW......
  • 全面了解CyberChef:一个强大的数据处理工具
    CyberChef是一个强大的网络工具,旨在处理和分析数据。它通过简单的拖放界面提供了各种功能,适用于安全研究人员、开发者和数据分析师。下面是关于CyberChef的全方面知识,包括其主要功能、使用场景和优势。1.功能编码与解码:支持多种编码格式,如Base64、Hex、URL编码等,可以方便地进行编......
  • Cisco Secure Firewall Threat Defense Virtual 7.6.0 发布下载,新增功能概览
    CiscoSecureFirewallThreatDefenseVirtual7.6.0-思科下一代防火墙虚拟设备(FTDv)FirepowerThreatDefense(FTD)SoftwareforESXi&KVM请访问原文链接:https://sysin.org/blog/cisco-firepower-7/,查看最新版。原创作品,转载请保留出处。作者主页:sysin.orgCiscoSe......
  • 48730-32548, Cyber Security
    48730-32548,CyberSecurityWeek-6LabdesignedbyAshishNanda,basedondocuments“SEEDLabs”providedbyWenliangDu,SyracuseUniversity1UnderstandingTCP/IPbasedAttacksContinuedLabEnvironmentSetupYouneedtofollowtheLab-4(Week5)virtu......
  • COMPSCI 316: Cyber Security
    Assignment1COMPSCI316:CyberSecurity,Semester2,2024Thisassignmentisworth100marks.Theweightofthisassignmentis10%ofthecourse.ThedeadlinetosubmitthisassignmentisFriday,September13,23:59hrsNZTime.Nolatesubmissionsarea......
  • 48730-32548, Cyber Security
    48730-32548,CyberSecurityWeek-5Thelabisbasedondocuments“SEEDLabs”providedbyWenliangDu,SyracuseUniversityUnderstandingTCP/IPbasedAttacksLabOverviewThelearningobjectiveofthislabistogainfirst-handexperienceonTCP/IPvuln......
  • 海外合规|新加坡网络安全认证计划简介(三)-Cyber Trust认证
      一、认证简介:     Cyber Trust标志是针对数字化业务运营更为广泛的组织的网络安全认证。该标志针对的是规模较大或数字化程度较高的组织,因为这些组织可能具有更高的风险水平,需要他们投资专业知识和资源来管理和保护其IT基础设施和系统。CyberTrust标志采用基......