Chapter 3 Digital Forensic investigation using Forensic Software -Autopsy
Chapter 3 Digital Forensic investigation using Forensic Software -Autopsy
FORENSIC
CHAPTER THREE: DIGITAL FORENSIC INVESTIGATION USING FORENSIC
SOFTWARE -AUTOPSY
INSTRUCTOR : SAMUEL TAMIRAT
PhD candidate
MAIN POINT
• Make clear understanding of what the digital investigation need or should answer
• Make sure the data or image that we copied is in a forensically sound way
• The data recovered or preprocessed should be seen
• What the date means for our investigation
• File time stamp
• Window registry entries
• File in download folder
• File in a temporary internet files
DATA LOCATION AND THE MEANING OF DATA
• File Timestamps
• Most file systems keep track of timestamp
• Created, Accessed, Modified
• Action that affect timestamp
• Moving, Copying, creating and editing the file
• Window Registry
• Contains windows and user settings information in windows system.
• Registry key contain information about setting
• E.g. TypedURLs
DATA LOCATION AND THE MEANING OF DATA
• There are many location for data storage and different type of data exists
• Each location and data type means different depending on the investigation context
DIGITAL FORENSIC INVESTIGATION WITH
AUTOPSY
CREATING A NEW CASE
• Extension Mismatch detector: This module flags a file that have a non standard file
extension
• E01 Verifier:Validate the integrity of E01 File.
• Interesting file extensions: Identify interesting item based on the rule defined as what
are the interesting items are.
• Photorec Carver: Run photorec curver against un allocated space in the dataset
• Virtual Machine extractor: extract virtual machine files
AUTOPSY OVERVIEW (CONT.…)
DATA RECOVERY WITH PHOTOREC
• PhotoRec
• Cross-platform tool, meaning it is compatible with various operating systems, including
Windows, macOS, Linux,
• Supports a wide range of file systems, including FAT, NTFS, exFAT, ext2/3/4, HFS+, and many
others
• It recover a variety of file types, including photos, videos, documents, and more.
• It can be used in a live environment, such as a bootable CD or USB drive, allowing users to
perform recovery operations without modifying the existing system.
DATA RECOVERY WITH PHOTOREC (CONT.…)
• Select the location where to store the recover data and it will store the recovered data in that location