25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

NAPIER UNIVERSITY<br />

SCHOOL OF COMPUTING<br />

PROJECT DIARY<br />

Student: Barrie Codona<br />

Supervisor: <strong>Bill</strong> <strong>Buchanan</strong><br />

Date: 2 nd November 2007 Last diary date: 26 th October 2007<br />

Objectives:<br />

1. Fur<strong>the</strong>r investigation into how <strong>the</strong> event log stores <strong>the</strong> time & date.<br />

2. Automate <strong>the</strong> function <strong>of</strong> copying a ‘modified’ log file.<br />

3. Fur<strong>the</strong>r investigation into Dr Harold Shipman.<br />

4. Begin investigation into current <strong>and</strong> previous research (literature review).<br />

Progress:<br />

1. It was discovered that <strong>the</strong> time is a count <strong>of</strong> <strong>the</strong> number <strong>of</strong> seconds that have passed since<br />

00:00:00 01/01/1970<br />

2. A console application has been developed that will prevent <strong>the</strong> event service from starting after <strong>the</strong><br />

computer has been reset, thus allowing <strong>the</strong> log file to be replaced. More work is required to try <strong>and</strong><br />

restart <strong>the</strong> service automatically.<br />

3. Greater details <strong>of</strong> <strong>the</strong> actions <strong>of</strong> Dr Shipman have been discovered; this includes <strong>the</strong> database<br />

application that he was using (MicroDoc), <strong>and</strong> also, <strong>the</strong> company that did <strong>the</strong> digital forensic<br />

investigation (Vogon).<br />

4. Work In Progress<br />

Supervisor’s Comments:<br />

Version 2<br />

Napier University

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!