| Course | ACC 693 Investigating with Computers |
|---|---|
| Module | Module 6 |
| Paper type | graduate milestone analyzing email, document metadata and system artifacts |
| Length | About 1,040 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | MS Accounting |
| Updated | October 2026 |
Free sample paper for ACC 693 Module 6
Analysis of Email, Documents and System Records
[Student Name]
Southern New Hampshire University
ACC 693: Investigating with Computers
Milestone Two
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Analysis of Email, Documents and System Records
Introduction
Milestone One planned the preservation of nine sources of digital evidence, and the company now holds the project manager's mailbox and OneDrive, a verified image of his laptop, the payables system's logs, job folders and badge and VPN logs. This milestone asks one question: did the flashing subcontractor's invoices originate with the project manager who approved them? It analyzes six categories of evidence, describes the method for each, identifies corroboration and states limits. Analysis was performed on verified copies, with original hashes checked before each session.
Invoice File Metadata
The payables system stores each vendor invoice as a PDF attachment. All seventy-four invoices from the subcontractor were extracted and their document properties examined with a metadata viewer. Each listed a word processor's built-in PDF export as the producing application and showed an author field identical to the project manager's Windows user name. Creation times fell between 6:40 p.m. and 11:15 p.m. on the day before each invoice was emailed. The modification times matched the creation times to the minute, indicating the files were saved once and not edited afterward, which is consistent with a document produced from a template and exported directly. By comparison, invoices from the company's three legitimate sheet-metal subcontractors were produced by accounting software and carried those companies' names in the author field. Author fields are set by the software from the computer's user profile, so they identify the account that saved the file, not necessarily the person typing.
Laptop Artifacts
The laptop image contained a word processing template named for the subcontractor in a folder labeled "Personal," with the same layout, fonts and logo as the invoices. Garfinkel (2006) describes how artifacts scattered across a drive can be extracted and correlated to reconstruct activity, and the operating system's recent-file records here showed the template opened seventy-four times between March 2023 and May 2025, each time on a date when an invoice was created. Shortcut files pointed to PDFs with the invoice numbers 1001 through 1074 saved to the same folder; most of those PDFs had been deleted and, because of the solid-state drive, could not be recovered, but the shortcuts survived. Copies of eleven of the PDFs remained in his OneDrive recycle bin, collected on day three, and their hash values matched the attachments in the payables system exactly. A hash match means the files are bit-for-bit identical: the invoices that payables received are the same files that were saved on his account. The template itself was last modified in May 2025, when the subcontractor's logo was changed, and the logo image file was found in his Downloads folder with a browser history entry showing it came from a free logo generator website the same evening.
Email Headers and Badge Records
The invoices reached payables from an email address on a domain registered to the subcontractor. The full headers of the seventy-four messages were exported, and the first external server line in each was read to identify the internet address from which the message entered the mail system. Forty-one of the seventy-four entered from the company's own public internet address, meaning they were sent from a device on the company's network. For each of those forty-one, badge records place the project manager in the office at the time, and in thirty-six the company's network logs show his laptop connected. The remaining thirty-three entered from residential internet addresses that the company cannot attribute without legal process. Casey (2011) cautions that headers can be forged above the receiving server, so only the lines added by the company's own mail system were relied on.
Invoice emails by origin
| Origin | Messages | Corroboration |
|---|---|---|
| Company network | 41 | Badge in office for all 41; laptop on network for 36 |
| Residential addresses | 33 | Not attributed; subpoena needed |
Mailbox Search
Keyword searches of his mailbox for the subcontractor's name, its domain and its owner's name returned 312 messages. Most were routine forwards of invoices and change orders. The searches were run with the examination software's indexing, the terms and their hit counts were logged, and every hit was reviewed by two people, so the review can be described and repeated. Messages that were plainly personal and unrelated were set aside without further reading. Nine are significant: in each, he asked a payables clerk to "expedite" a subcontractor invoice, and in two he told the clerk that the invoice should go through "under my number," a reference to his approval limit. A search of recoverable deleted items found four further messages he had deleted, including one from his personal email to his work account attaching a draft invoice in March 2023, before the subcontractor existed in the vendor master.
Vendor Setup and Site Records
The vendor master change log shows the subcontractor was created on March 2, 2023, by a payables clerk acting on a vendor request form submitted from the project manager's account. The form listed the relative's phone number, matching the emergency contact on his personnel record. Daily job logs for the fourteen projects record each crew on site by company. The subcontractor never appears. Photographs in the job folders, whose embedded times match the log dates, show flashing installed by the company's own sheet-metal crew on dates for which the subcontractor billed. The site superintendent's timesheets for the same days record the company crew's hours on flashing, so the company paid twice for the same work: once in its own payroll and once through the subcontractor's invoices.
Limits of the Findings
Metadata can be edited, author fields reflect an account rather than a person and the residential emails cannot yet be attributed. Kent et al. (2006) advise that conclusions be stated with their limits and supporting sources. The strength here lies in agreement among independent records: file properties, laptop artifacts, network logs, badge entries, the vendor request and site logs were created by different systems for different purposes, and altering all of them consistently would be far harder than the scheme itself.
Conclusion
Six independent categories of evidence indicate that the subcontractor's invoices were created on the project manager's account and laptop, many sent from the company's network while he was present, for work the site records show the subcontractor did not perform. Milestone Three will place these findings on a single timeline.
References
Casey, E. (2011). Digital evidence and computer crime: Forensic science, computers, and the Internet (3rd ed.). Academic Press.
Garfinkel, S. L. (2006). Forensic feature extraction and cross-drive analysis. Digital Investigation, 3, 71-81. https://doi.org/10.1016/j.diin.2006.06.007
Kent, K., Chevalier, S., Grance, T., & Dang, H. (2006). Guide to integrating forensic techniques into incident response (NIST Special Publication 800-86). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-86
What the ACC 693 Module 6 instructions ask for
Milestone Two in ACC 693 asks you to analyze the digital evidence collected in your case and explain what it shows. Guidelines usually call for analysis of email, documents and their metadata, computer artifacts and system logs, the methods and tools used, the findings with supporting detail, how findings were corroborated and their limitations. You are expected to go beyond what a document says to what its digital properties reveal: who created it, on what device, when and how it traveled. Graders reward findings that are confirmed by more than one source and honest statements of what metadata can and cannot establish, since metadata can be changed.
How this ACC 693 Module 6 milestone two example is built
The paper starts with the seventy-four invoice PDFs. Their metadata show they were produced by a word processor's save-as-PDF function and carry an author field matching the project manager's Windows user name. The laptop image contains an invoice template in a personal folder, and recent-file traces show it opened seventy-four times on dates matching the invoices. Of the invoice emails sent to payables, forty-one passed through the company's own internet address while badge records place him in the office. Keyword searches return 312 messages mentioning the subcontractor. The vendor setup request came from his account. Daily job logs and photographs never show the subcontractor's crew, and the paper closes by noting which findings metadata alone cannot prove.
Where the ACC 693 Module 6 rubric puts the points
The Milestone Two rubric commonly scores analysis of email and headers, document metadata, computer artifacts and logs, corroboration across sources, methodology, limitations and organization. Strong papers explain what each metadata field means and how it was read, connect artifacts to times recorded independently, such as badge or VPN logs, and present findings in a way that a nontechnical reader can follow. They also acknowledge that metadata can be edited and show why the combination of sources makes alteration unlikely. Papers lose credit for presenting tool output without interpretation, for relying on a single artifact, for overstating what metadata prove and for failing to describe the method.
ACC 693 Module 6 help: the mistakes that cost points
A common weakness is reporting metadata as if it were self-explanatory; explain what an author field or a header line is, how it is created and why it matters in this case. Another is stopping at one source; the strongest findings combine a file artifact with an independent record, such as matching invoice creation times with badge entries. Be careful with claims: an author field shows which account saved a file, not who was typing, and email headers show network paths, not people. State those limits and show how other evidence closes the gap. Finally, organize findings so each one cites its source and the corroborating record, which makes the timeline in Milestone Three far easier to build.
Get ACC 693 Module 6 written to your instructions
Send the ACC 693 Milestone Two guidelines with your preserved evidence. The paper will analyze metadata, headers, artifacts and logs, show where sources confirm each other and state the limits of each finding. Expect roughly two days; we write the first milestone at no cost. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More ACC 693 papers and related MS Accounting samples
- ACC 693 Module 1 Discussion: What Computers Changed About Fraud Investigation
- ACC 693 Module 2 Data Analytics Assignment: Testing Three Years of Payables
- ACC 693 Module 3 Milestone One: The Digital Evidence Plan
- ACC 693 Module 4 Discussion: Personal Phones, Private Email and the Employer's Reach
- ACC 693 Module 5 Forensic Imaging Assignment: Acquiring the Laptop and the Phone
- ACC 660 Module 4 Discussion: Which EBITDA Add-Backs Should a Controller Sign?
- ACC 646 Module 6 Milestone Two: Following the Money From the Shell Company
- ACC 550 Module 6 Joint Cost Assignment: Halves, Pieces, Meal and Shells From One Pound
- ACC 610 Module 6 Milestone Two: Impairment of a Service Center and of Goodwill
ACC 693 Module 6 questions, answered
Where can I find a free ACC 693 Module 6 Milestone Two sample?
The full ACC 693 Milestone Two paper is here, analyzing invoice metadata, email headers and laptop artifacts in a roofing contractor case.
What can document metadata reveal in a fraud investigation?
Fields such as author, creating application and creation and modification times can show which account and software produced a file and when, though they can be altered and need corroboration.
What do email headers show?
The path a message took between servers, including timestamps and the internet addresses of the systems that handled it, which can indicate the network from which a message was sent.
What are recent-file artifacts?
Records kept by the operating system and applications, such as shortcut files and jump lists, that show which files a user opened and when, often surviving after the files are deleted.
Why corroborate digital findings with other records?
Because any single artifact can be explained away or altered, while agreement among independent sources, such as metadata, badge logs and site records, is far harder to dispute.