l
l
Introduction:
Investigating digital evidence is time-intensive due to the large storage capacity of
modern hard drives. Autopsy for Windows consolidates numerous digital forensics
tools into a single suite, allowing investigators to analyze storage devices, recover
deleted files, and search for evidence like emails and documents. It also generates
unique hash values for file integrity and supports importing known file sets for
identification, such as the NSRL. Installing Autopsy is key to starting digital
investigations effectively.
1- I opened https://sourceforge.net/projects/autopsy/files/autopsy/4.3.0/
and installed the target file autopsy-4.3.0-64bit.msi .
2- Open Autopsy file and go to autopsy4.3.0 bit.msi , click right and click on install .
3- Then click next on setup page and locate where you want to install file.
4- Then click install .
5- In the Completing the Autopsy Setup Wizard window, click Finish, and then exit
Autopsy.
Review
2. Autopsy can search for which of the following types of files? (Choose all that apply.)
a. E-mail
b. Graphics
c. Deleted files
d. Registry files
b. File hashes can verify that the chain of custody has been maintained.
c. File hashes can indicate that software has been purchased legally.
5. Autopsy can’t recover deleted or corrupted files and display their contents. True or
False? False
1.2 FTK Imager Lite:
Introduction
Forensic investigators must ensure the integrity of digital evidence from seizure to trial
by maintaining the chain of custody and using bit-stream imaging to create exact copies
of storage devices. This process preserves files and unpartitioned space, allowing safe
examination and generating hash values to verify data integrity.
FTK Imager Lite is a compact tool that runs from small storage devices or Windows
computers. It previews files to check for evidence and can duplicate storage devices if
evidence is found. It supports various file systems and produces several image formats.
While it copies encrypted files, it cannot decrypt them. In this lab, you will download
FTK Imager Lite, with installation covered in Chapter 3 of the textbook.
1. FTK Imager can be used to search all the following except what?
a. Deleted files
b. Documents
c. Graphics
d. Encrypted files
b. Forensic evidence
d. DNA evidence
a. Image files are smaller than the actual hard disk files.
d. The original storage device can’t be analyzed without the original computer.
4. FTK Imager can detect and view encrypted files. True or False? False
Introduction :
Forensic investigators often use WinHex alongside other tools to analyze and
manipulate data stored on disks. It offers advanced data interpretation and
manipulation features, despite not being designed specifically as a digital forensics
tool. In this lab, you will download and install WinHex as outlined in Chapter 5 of the
textbook.
The licensed version of WinHex supports FAT, NTFS, Ext2 to Ext4, Next3, CDFS, and UDF
file systems, while the evaluation version reads FAT12, FAT16, FAT32, exFAT, and NTFS.
It includes a RAM editor, data interpreter, editing functions, file hashing, data recovery,
and search capabilities for text and hexadecimal values. The program and its files can
be stored on a USB drive for portable use on any Windows OS.
1. The evaluation version of WinHex can be used to search all the following file
systems
a. FAT16
b. HFS+
c. NTFS
d. exFAT
2. The evaluation version of WinHex can write up to how many bytes of data?
a. 200 KB
b. 200 MB
c. 2 TB
Introduction : Digital forensics tools can seem daunting, even with clear
instructions. Autopsy for Windows aims to simplify this with a user-friendly
interface, though some features may still be complex, especially for newcomers to
digital forensics.
3- After finish the last step , the screen will devide to three parts as show in this
figure .
4- As we see , the image have a files inside it like tables and images , we can see the
images when change to thumbnail
5- In below we can see the way that we view the data in the photo , data maybe
hexa, string, file metadata and media.
6- And additional feature is timeline , timeline can show data on details , counts ,
and lists
Review
a. File contents
2. What type of information is displayed under the Data Sources item in the Tree
Viewer?
a. .atp
b. .aup
c. .apy
d. .aut
5. The Keyword Lists feature offers which of the following search parameters? (Choose
all
that apply.)
a. Phone numbers
b. IP addresses
c. Street addresses