Law & Order: Cyber Unit
Tool Time
Hidden in Plain Sight
You've Got Mail (and Logs)
Bits & Bytes of Evidence
100

This act requires websites to obtain parental consent before collecting info from children under 13.

What is COPPA?

100

This tool is known for cracking passwords and scanning the Windows Registry.

What is FTK (Forensic Toolkit)?

100

The message hidden within a carrier in steganography is called this.

What is the payload?

100

This Outlook file stores emails and calendar data locally.

What is a .pst file?

100

Windows stores hashed passwords in this file.

What is the SAM (Security Accounts Manager)?

200

This act created the Electronic Crimes Task Force (ECTF).

What is the USA PATRIOT Act?

200

This tool calculates an MD5 hash to verify evidence integrity.

What is EnCase?

200

This method hides data in the least noticeable bit of a file.

What is the Least Significant Bit (LSB) method?

200

This file format is used for offline copies of Exchange mailboxes.

What is a .ost file?

200

This log in Windows contains forwarded events from remote computers.

What is the ForwardedEvents Log?
300

This act mandates telecommunication providers support lawful surveillance.

What is CALEA?

300

This tool can bruteforce an iPhone passcode.

What is XRY?
300

The file used to hide information is called this in steganography.

What is the carrier?

300

This older email format was used by Outlook Express.

What is .dbx or .mbx?

300

This command shows the history of shell commands in macOS.

What is .bash_history?

400

This act governs how stored data can be obtained from service providers.

What is the Stored Communications Act (SCA)?

400

This open-source tool detects hidden data in images.

What is StegExpose?

400

This kind of hash is used by systems like Windows to store passwords.

What is cryptographic hash?

400

This format stores forensic disk images and is supported by Sleuth Kit.

What is AFF(Advanced Forensic Format)?

400

This memory tech is used in SSDs and retains data without power.

What is NAND Flash Memory?

500

This act allows collection of GPS and non-text communications.

What is the Wireless Communications and Public Safety Act of 1999?

500

This software recovers Inbox/Outbox and contact data with a trial version.

What is Data Doctor?

500

This macOS partition system is used on Intel-based Macs.

What is the GUID Partition Table?

500

This file format stores entire Exchange mail databases.

What is .edb?

500

macOS uses this command-line shell.

What is BASH?

M
e
n
u