Erin D.rar -
: If an Outlook PST file is present, investigators look for communications with "competitors" or external email addresses where company secrets might have been sent. Common Solutions (Flags)
: Analysis of .lnk files in the Recent folder shows Erin accessed sensitive documents and external storage devices. Erin D.rar
: Registry keys (like USBSTOR ) reveal that a specific Kingston USB drive was plugged into the machine shortly before the "data leak" occurred. : If an Outlook PST file is present,
: Browser history from Google Chrome and Internet Explorer often reveals searches for "how to hide files" or "industrial espionage," indicating intent. : Browser history from Google Chrome and Internet
The challenge involves investigating a Windows 7 workstation image to determine if the user, Erin, was involved in corporate espionage or data theft.
: These artifacts confirm that Erin executed specific programs, such as CCleaner or Eraser , to attempt to wipe evidence of her activity.
: Frequently found using Steganography tools or by checking alternate data streams (ADS).