多国籍企業のフォレンジックチームが、データ漏洩の疑いについて調査を行っています。システムログを徹底的に調査した結果、チームは内部システムからダークウェブ活動に関連する疑わしいIPアドレスへの一貫したアウトバウンドトラフィックを発見しました。該当システムを調査したところ、ユーザーが許可されていない活動にTORを使用していたことが判明しました。TORの使用に関するさらなる証拠を収集するために、次のうち、実質的な成果が得られる可能性が最も低い手法はどれでしょうか?
正解:D
Option D is the best answer because it is the technique least likely to produce substantial evidence of TOR usage in a typical enterprise workstation investigation. CHFI v11 includes Dark Web Forensics , Windows artifact analysis , registry analysis , prefetch analysis , and network traffic analysis as relevant forensic areas. In that context, investigators are expected to prioritize artifacts that commonly record application execution, persistence, and network behavior.
Prefetch files can show whether the TOR executable was launched on a Windows system. The Windows Registry may contain installation traces, user activity references, or other application-related entries. Real- time or captured network traffic can also reveal communications with TOR entry nodes, relays, or patterns consistent with anonymized traffic. These are all recognized and productive artifact sources in a CHFI-style investigation.
By contrast, Command Prompt history is much less reliable because TOR is commonly used through the TOR Browser GUI , not through command-line execution. Unless the user specifically launched TOR- related commands manually, command history may contain nothing useful. Therefore, from a forensic- efficiency standpoint, this is the weakest option.