Highlights
1. PCAP Analysis
This task focuses on your knowledge of network forensics. As a forensic investigator, you are given a network traffic capture PCAP file to identify various malicious activities between an attacker's device and a server. You should follow the standard forensic procedure (e.g. examination and analysis) and use appropriate forensic tools (e.g. Wireshark) to locate potential evidence containers within the given PCAP file. In particular you need to:
1. Explain the type of incident and how it happened (Executive summary).
2. Identify details of the attacker and victim (e.g. IP address, MAC address).
3. Enumerate attacker's activities.
4. Provide recommendations on how the incident could be avoided.
2. Memory Forensics Analysis
This task focuses on your understanding of memory forensics. A memory dump was created after the user clicked on an unknown executable file. As a forensic investigator, you follow the standard forensic procedure (e.g. examination and analysis) and use appropriate forensic tools (e.g. Volatility) to tackle the supplied memory dump file and provide a report on your findings. A thorough analysis of the memory dump file is required. In particular you need to:
1. Explain the type of incident and how it happened (Executive summary).
2. Identify details of the victim's machine (e.g. user name, IP addresses, running applications etc.).
3. Identify both attacker's and victim's activities.
4. Provide recommendations on how the incident could be avoided.
This COMP6064 - IT Computer Science Assignment Help has been solved by our IT Computer Science Experts at My Uni Paper.
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.