Write a report for Case 3. Details in the instructions box.

Your organization has become aware of external attempts to gain access to sensitive proprietary information on its computer systems and has stepped up its monitoring in response. Data from this monitoring, in addition to interviews with employees, has focused attention on a single user, who is suspected of collaborating with an outside party.

When escalated monitoring of the user identified suspicious network and system activity, your organization’s security team responded. They copied the contents of the user’s home directory (this was a Linux desktop system), made a full dump of system memory, and preserved a packet capture of network traffic from the system. It’s your task to analyze this data and determine what can be established about the activity of the user.

SHA-1 of raw file: 52014e22c843ece2736bce59f652f43e96035825
Your organization wants to answer the following questions:

What relevant user activity can be reconstructed from the data and what does it show?
Is there evidence of inappropriate or suspicious activity on the system related to the user?
Is there evidence of collaboration with an outside party? If so, what can be determined about the identity of the outside party? How was any collaboration conducted?
Is there evidence that sensitive data was copied? If so, what can be determined about that data and the manner of transfer?
Case 3 File in the link below:

Last Completed Projects

topic title academic level Writer delivered