The brief
You are a junior digital forensics investigator on Case M57-Patents. M57 is a small patent research company, and it suspects that an employee took patent material out of the company. In Lab 3 you received the image of Charlie’s work USB drive and proved it unchanged. In this lab you examine what is on it.
The drive holds two kinds of records. A computer-stored record is content a person wrote and a computer saved, such as an email. A computer-generated record is data the operating system or an application wrote by itself: file timestamps, document metadata, download marks. A stored record can raise a hearsay objection unless it is a party’s own statement offered against that party; a generated record is not hearsay but must still be authenticated. The manual edition has you type every Sleuth Kit command yourself. Here Claude Code runs them, and you check what it reports.
Date: header and call it the file’s creation time. Asked for timestamps, it will often drop -z UTC and report local time without saying so, or “convert” between time zones in its head. And asked whether a record is hearsay, it will give a confident legal answer as if it were a reading off the image. Keep the three apart: a value from a command, the record it came from, and the rule you apply to it.The image is charlie-work-usb-2009-12-11.E01 from the M57-Patents scenario of the Digital Corpora project, the same image you verified in Lab 3. The hash file on this portal was computed when the course acquired the image. All times on this page are UTC.
0 — Claude Code and evidence
You need Claude Code installed and signed in. If it is not, work through the setup guide first. Check with claude --version; a version number means you are ready. You also need The Sleuth Kit and unzip, which Claude will run on your behalf (sudo apt-get install -y sleuthkit unzip, or brew install sleuthkit on macOS). Install them yourself; do not ask Claude to run sudo.
Download the image and the hash file yourself, into a folder of their own, before you start Claude. The evidence is placed by you, not fetched by the tool.
mkdir LAB-05-M57
cd LAB-05-M57
wget https://digitalcorpora.s3.amazonaws.com/corpora/scenarios/2009-m57-patents/usb/charlie-work-usb-2009-12-11.E01
wget https://courses.karbab.net/mscs630/charlie-work-usb-2009-12-11.E01.sha256
claudeLAB-05-M57. Windows PowerShell: mkdir $env:USERPROFILE\LAB-05-M57, then cd into it; the Sleuth Kit commands on this page are for Linux, WSL and macOS.Check charlie-work-usb-2009-12-11.E01 against charlie-work-usb-2009-12-11.E01.sha256 with sha256sum -c. Show me the exact command you ran and its full output. Do not open or change any file.What Claude should do: run one sha256sum -c and print one line ending in OK.
Check its work:
sha256sum charlie-work-usb-2009-12-11.E01
cat charlie-work-usb-2009-12-11.E01.sha2567a998c556b22f5dc9426a33dcaceadd21a14c9cfb22957edce461d58a14fb40aCheckpoint 0
All three must be right to complete this step.
-
What is the SHA-256 hash of your copy of
charlie-work-usb-2009-12-11.E01? -
What did
sha256sum -cprint after the filename? -
Claude replies “The hash matches the expected value.” and shows no command. What do you do?
A claim of a match is not a match. Printing the expected value proves nothing about the file on your disk; only a computed hash does.
1 — Create a case and ingest the image
If you use Autopsy, create the case by hand as the handout describes (Case Name M57-Charlie-Records, Case Number LAB-05-M57, time zone GMT/UTC). Claude works on the command line beside it.
Run mmls on charlie-work-usb-2009-12-11.E01. Show me the exact command and its full output, then tell me the start sector of the NTFS partition and which line you read it from.What Claude should do: one mmls, the table, and a start sector that matches the Start column of the NTFS / exFAT line.
Check its work:
mmls charlie-work-usb-2009-12-11.E01Using that start sector as the -o offset, list the root directory of the file system with fls. Show me the exact command and its full output. Then tell me the MFT entry number of the Email folder, quoting the line you read it from.What Claude should do: an fls -o 1 command and a listing of about 27 lines, including $MFT, Email, Nitroba work.odt and three Zone.Identifier streams.
Check its work:
fls -o 1 charlie-work-usb-2009-12-11.E01-o, fls looks for a file system at sector 0, finds the partition table instead, and fails. A model sometimes reads that error as “the image has no file system”. The error is a missing offset, not a finding.Checkpoint 1
All three must be right to complete this step.
-
At which sector does the NTFS partition start?
-
What is the MFT entry number of the
Emailfolder? -
Claude runs
flswithout-o, gets an error, and concludes that the image holds no file system. What do you do?The partition starts at sector 1. A command aimed at the wrong place returns an error about the place, not about the evidence.
2 — A computer-stored record
Charlie saved copies of his emails as text files in the Email folder. The body of each email is text that Charlie typed.
List the Email folder (MFT entry 43) with fls -o 1 and find the entry number of Charlie_2009-11-16_1326_Sent.txt. Then print that file's content with icat. Show me both commands and their exact output.What Claude should do: an fls ... 43, the line r/r 105-128-1: Charlie_2009-11-16_1326_Sent.txt, then an icat ... 105 printing the email with its Subject:, From:, Date: and To: lines and a short body.
Check its work:
fls -o 1 charlie-work-usb-2009-12-11.E01 43 | grep 1326
icat -o 1 charlie-work-usb-2009-12-11.E01 105Show the NTFS timestamps of entry 105 in UTC with istat -o 1 -z UTC, keeping only the four $STANDARD_INFORMATION time lines. Show me the exact command and the lines it printed. Do not convert or interpret the times.What Claude should do: an istat with -z UTC and four lines ending in (UTC).
Check its work:
istat -o 1 -z UTC charlie-work-usb-2009-12-11.E01 105 | sed -n 12,15pDate: header the email program wrote. The NTFS Created time is a different record, written by the file system when the copy landed on the drive.Checkpoint 2
All four must be right to complete this step.
-
What is the MFT entry number of
Charlie_2009-11-16_1326_Sent.txt? -
On what date (UTC,
YYYY-MM-DD) was the email file created on the drive?4 December 2009, more than two weeks after the email’s own date. The file is a later copy of the email.
-
Claude says the email file “was created on 16 November 2009”. What is wrong, and what do you ask for?
The header is part of the stored email; the NTFS time is a generated record of the copy. Ask for the command that reads the record you need, and never let the model do time arithmetic for you.
-
The prosecution offers the email body against Charlie, to show he had started at a new company. How do the rules treat it?
A party’s own statement offered against that party is excluded from hearsay. Authorship still has to be shown. This is your legal reasoning, not a value Claude can read off the image.
3 — A computer-generated record
Nitroba work.odt (MFT entry 41) is an OpenDocument text file. Its typed table is a stored record; NTFS wrote its timestamps and OpenOffice wrote its document metadata, both generated records. Windows wrote a third kind, the Zone.Identifier streams, on three other files. Ask one question per prompt.
Show the NTFS timestamps of MFT entry 41 in UTC with istat -o 1 -z UTC, keeping only the four $STANDARD_INFORMATION time lines. Show me the exact command and the lines it printed.What Claude should do: four lines ending in (UTC), with File Modified on 19 November 2009 and Created on 24 November 2009.
Check its work:
istat -o 1 -z UTC charlie-work-usb-2009-12-11.E01 41 | sed -n 12,15pExtract MFT entry 41 with icat into a file called nitroba.odt, compute its SHA-256 with sha256sum, then print the meta: and dc: fields of meta.xml inside it with unzip -p and grep. Show me every command and its exact output.Count the author fields (initial-creator or dc:creator) in meta.xml inside nitroba.odt with grep -c. Show me the command and the number it printed.What Claude should do: a hash line, five metadata lines (creation-date, editing-duration, editing-cycles, generator, dc:date), and a count of 0.
Check its work:
icat -o 1 charlie-work-usb-2009-12-11.E01 41 > nitroba.odt
sha256sum nitroba.odt
unzip -p nitroba.odt meta.xml | grep -oE '<(meta|dc):[a-z-]+>[^<]+'
unzip -p nitroba.odt meta.xml | grep -cE 'initial-creator|dc:creator'Print the alternate data stream 37-128-4 (astronaut.jpg:Zone.Identifier) with icat -o 1, removing zero bytes with tr. Show me the exact command and its output.Build a body file of all timestamps with fls -o 1 -r -m / into body.txt, then sort it with mactime -b body.txt -z UTC and show only the lines for Nitroba work. Show me both commands and the exact lines.Check its work:
icat -o 1 charlie-work-usb-2009-12-11.E01 37-128-4 | tr -d '\0'; echo
fls -o 1 -r -m / charlie-work-usb-2009-12-11.E01 > body.txt
mactime -b body.txt -z UTC 2>/dev/null | grep 'Nitroba work'-z UTC or read dc:date, which is local time. Re-run with -z UTC rather than accepting a converted value.Checkpoint 3
All five must be right to complete this step.
-
What is the SHA-256 of your extracted
nitroba.odt? -
How many times was the document saved, according to
editing-cycles? -
What
ZoneIddoes theZone.Identifierstream ofastronaut.jpgcarry? -
Claude reports the document’s File Modified time as 13:26:42. Your own
istat -z UTCshows 21:26:42. What do you do?The report states every time in UTC, read from a command that prints UTC. A value converted in the model’s head, or printed in an unstated zone, is not one you can reproduce.
-
The document has no author field and a
creation-datein April 2009. What can its generated metadata establish?Generated metadata is a record of what the software did. Authorship and the start of the work are separate questions that need other evidence.
Write the report
The checkpoints establish the facts. The graded deliverable is the preliminary report you write from them, using the template in the PDF handout. It has four parts:
- Evidence details — the filename, the output of
sha256sum -c, and the file system and partition offset frommmls. - Executive summary — two or three sentences: which image you examined, which stored record and which generated records you found, and what the generated records show about
Nitroba work.odt. - Key findings — the stored record (path and MFT entry, the sentence you rely on, its NTFS Created time, and how the hearsay rules treat it); the generated records (the NTFS times of
Nitroba work.odt, the SHA-256 of the extracted file,editing-cycles,editing-duration,dc:date, the author field, theZone.Identifierfiles and theirZoneId, and how these would be authenticated under FRE 901(b)(9) or 902(13)). - Admissibility analysis — compare the two kinds of record, and use
Nitroba work.odtto explain one limit of generated metadata.