Analysis and Evaluation of the Windows Event Log - Bill Buchanan
Analysis and Evaluation of the Windows Event Log - Bill Buchanan
Analysis and Evaluation of the Windows Event Log - Bill Buchanan
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
NAPIER UNIVERSITY<br />
SCHOOL OF COMPUTING<br />
PROJECT DIARY<br />
Student: Barrie Codona<br />
Supervisor: <strong>Bill</strong> <strong>Buchanan</strong><br />
Date: 2 nd November 2007 Last diary date: 26 th October 2007<br />
Objectives:<br />
1. Fur<strong>the</strong>r investigation into how <strong>the</strong> event log stores <strong>the</strong> time & date.<br />
2. Automate <strong>the</strong> function <strong>of</strong> copying a ‘modified’ log file.<br />
3. Fur<strong>the</strong>r investigation into Dr Harold Shipman.<br />
4. Begin investigation into current <strong>and</strong> previous research (literature review).<br />
Progress:<br />
1. It was discovered that <strong>the</strong> time is a count <strong>of</strong> <strong>the</strong> number <strong>of</strong> seconds that have passed since<br />
00:00:00 01/01/1970<br />
2. A console application has been developed that will prevent <strong>the</strong> event service from starting after <strong>the</strong><br />
computer has been reset, thus allowing <strong>the</strong> log file to be replaced. More work is required to try <strong>and</strong><br />
restart <strong>the</strong> service automatically.<br />
3. Greater details <strong>of</strong> <strong>the</strong> actions <strong>of</strong> Dr Shipman have been discovered; this includes <strong>the</strong> database<br />
application that he was using (MicroDoc), <strong>and</strong> also, <strong>the</strong> company that did <strong>the</strong> digital forensic<br />
investigation (Vogon).<br />
4. Work In Progress<br />
Supervisor’s Comments:<br />
Version 2<br />
Napier University