Professional Documents
Culture Documents
ASSIGNMENT TITLE:
PROGRAM:
COURSE NAME:
COURSE ID:
BLOCK:
III
NAME:
ASSIGNMENT
Edward simon
#:3
Question
The suspect that you are investigating is so good that he/she left no tracks. However, you have
established that the suspect has two behaviors.
-He/she often uses same USB external drive which you have already confiscated
-He/she often visit a particular website
In an attempt to identify the suspect, design a scheduled task which does the following
-Make backup of the windows log that records external device setup events
-Notifies you by email when the suspects device us connected to a computer
Solution
I.
The physical serial number of the confiscated USB external device can be obtained using the
windows command line and scripting interface known as Windows Management
Instrumentation Command line (WMIC). To get the physical serial number can be captured
using the following steps.
1. Connect the confiscated device into the computer and then type the following command
as shown in the captured screen short below
2. The output of above command will show all the physical serial numbers (Manufacture
serial numbers ) of the connected devices as show in the screen shot below.
3. Then note the physical serial number of the device (i.e from the above screen shot we
got 057B0D35C030)
II.
2. Compare each serial number with the serial number of the confiscated one
(057B0D35C030)
3. If the one of the serial numbers is the same with the 057B0D35C030 then
notify me through the email address (kilindoaa@ardhi.go.tz) and do registry
backup to the specified path (E:\Backup) and exit the script.
4. If the no serial number is the same with the 057B0D35C030 wait for the 3
seconds and then go to step 1.
III.
IV.
V.
1.
2.
3.
4.
5. Click on Triggers tab and then click on New Choose At Startup from the
drop down menu, click Enabled and hit OK
6. Click on the Actions tab and then click on New If you are running a .bat file
use cmd as the program the put /c .bat In the Add arguments field
7. Click on OK then on OK on the create task panel and it will now be
scheduled.
Add the .bat script to the place specified in your task event.