0% found this document useful (0 votes)
12 views

Chapter 3 Digital Forensic investigation using Forensic Software -Autopsy

This document outlines the process of digital forensic investigation using forensic software, specifically Autopsy. It details the requirements for conducting a digital investigation, the significance of data locations and timestamps, and the steps for creating a case and configuring analysis modules within Autopsy. Additionally, it discusses data recovery techniques using PhotoRec, a tool designed for recovering lost files from various storage media.

Uploaded by

Liyat Tesfaye
Copyright
© © All Rights Reserved
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views

Chapter 3 Digital Forensic investigation using Forensic Software -Autopsy

This document outlines the process of digital forensic investigation using forensic software, specifically Autopsy. It details the requirements for conducting a digital investigation, the significance of data locations and timestamps, and the steps for creating a case and configuring analysis modules within Autopsy. Additionally, it discusses data recovery techniques using PhotoRec, a tool designed for recovering lost files from various storage media.

Uploaded by

Liyat Tesfaye
Copyright
© © All Rights Reserved
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 17

COMPUTER CRIME & DIGITAL

FORENSIC
CHAPTER THREE: DIGITAL FORENSIC INVESTIGATION USING FORENSIC
SOFTWARE -AUTOPSY
INSTRUCTOR : SAMUEL TAMIRAT
PhD candidate
MAIN POINT

• Digital Forensic Investigation Requirements


• Data location and the meaning of data
• Digital Forensic investigation With Autopsy
• Data recovery using PhotoRec
DIGITAL FORENSIC INVESTIGATION REQUIREMENT

• Make clear understanding of what the digital investigation need or should answer
• Make sure the data or image that we copied is in a forensically sound way
• The data recovered or preprocessed should be seen
• What the date means for our investigation
• File time stamp
• Window registry entries
• File in download folder
• File in a temporary internet files
DATA LOCATION AND THE MEANING OF DATA

• File Timestamps
• Most file systems keep track of timestamp
• Created, Accessed, Modified
• Action that affect timestamp
• Moving, Copying, creating and editing the file

• Window Registry
• Contains windows and user settings information in windows system.
• Registry key contain information about setting
• E.g. TypedURLs
DATA LOCATION AND THE MEANING OF DATA

• File in download folder


• Default location for browser downloads.

• File in internet cache (Temp internet files, INetCache)


• Temporary storage for browsers when downloading webpages

• There are many location for data storage and different type of data exists
• Each location and data type means different depending on the investigation context
DIGITAL FORENSIC INVESTIGATION WITH
AUTOPSY
CREATING A NEW CASE

• Case Name: CaseNo-CaseType-Name of Investigator-Name of victim-Year


• Eg. (001-F-Sam-2016)
AUTOPSY OVERVIEW

1. New Case Creation


AUTOPSY OVERVIEW (CONT.…)

2. Adding Data source


AUTOPSY OVERVIEW (CONT.…)

3. Selecting Data source


CONFIGURE INGEST MODULE

• This is where the actual analysis of the disk is performed


• Recent Activity: Extract recent user activity such as a web browsing, recently access files.
• Hashlookup: identify known and notable files using supplied hash database.
• File type identification: Match file types based on binary signatures
• Embedded File Extractor: Extract embedded files (docx, ppts, xlsx, …)
• ExIF Extractor: Ingest JPEG files and retrieves the ExIF metadata.
• Keyword Search: Perform file indexing and periodic search using keywords.
• Email Parser : This module detects and parses mbox and pst/ost files
CONFIGURE INGEST MODULE (CONT.,,,)

• Extension Mismatch detector: This module flags a file that have a non standard file
extension
• E01 Verifier:Validate the integrity of E01 File.
• Interesting file extensions: Identify interesting item based on the rule defined as what
are the interesting items are.
• Photorec Carver: Run photorec curver against un allocated space in the dataset
• Virtual Machine extractor: extract virtual machine files
AUTOPSY OVERVIEW (CONT.…)
DATA RECOVERY WITH PHOTOREC

• PhotoRec is a free and open-source file recovery


software designed to recover lost files, including
videos, documents, and archives, from hard disks,
CD-ROMs, and lost pictures from camera
memory.
• It is a buddy program to TestDisk, another
popular data recovery tool.
DATA RECOVERY WITH PHOTOREC (CONT.…)

• PhotoRec
• Cross-platform tool, meaning it is compatible with various operating systems, including
Windows, macOS, Linux,
• Supports a wide range of file systems, including FAT, NTFS, exFAT, ext2/3/4, HFS+, and many
others
• It recover a variety of file types, including photos, videos, documents, and more.
• It can be used in a live environment, such as a bootable CD or USB drive, allowing users to
perform recovery operations without modifying the existing system.
DATA RECOVERY WITH PHOTOREC (CONT.…)

• Navigate the folder that the disk image exists

• Select the disk image and click proceed


DATA RECOVERY WITH PHOTOREC (CONT.…)

• Select which file to recover

• Select the location where to store the recover data and it will store the recovered data in that location

You might also like