Automated Forensic Artifacts Collection Solution

Cyber attackers can sometimes compromise endpoint machines. They may perform malicious actions that will damage the company. As a result, it is necessary to collect forensics artifacts (Information from the endpoint machine that can be used to trace the attackers’ behaviors) from the compromised machine for investigation. With the information we have, we may reconstruct malicious files, determine the goal of these attacks, or know how and when this attack happened. This project aims to automatically collect these forensics artifacts from endpoint machines and upload them to a secure portal. The reason for developing this automation tool is that it can collect artifacts more efficiently compared to manual collections—the quicker for collecting artifacts, the less chance for attackers to hide their tracks.

Faculty Supervisor:

Xiaodong Lin

Student:

Partner:

KPMG LLP (Toronto, ON)

Discipline:

Computer science

Sector:

Professional, scientific and technical services

University:

University of Guelph

Program:

Accelerate

Current openings

Find the perfect opportunity to put your academic skills and knowledge into practice!

Find Projects