Starting a New Digital Forensic Investigation Case in Autopsy 4.2

Поделиться
HTML-код
  • Опубликовано: 3 ноя 2024

Комментарии • 66

  • @michaelwhitlow372
    @michaelwhitlow372 6 лет назад +16

    Autopsy is the best kept secret in digital forensics. Love the tool, and love this video. Thank you.

    • @annemarie9318
      @annemarie9318 3 года назад

      hello may I know how to identify bookmarks?

  • @nikeplayer90game
    @nikeplayer90game 5 лет назад +4

    A video that isn't boring. THANK YOU!! this was super informative and easy to understand

  • @fenimama
    @fenimama 5 лет назад +1

    Appreciation. But just Seven minutes dedicated on naming and storing your investigation. Thankyou for the video.

  • @abhijeetbhujbbal8667
    @abhijeetbhujbbal8667 3 года назад +2

    This is an amazing video. Easy and to the point explanation. Excellent work.

  • @Slinky
    @Slinky 7 лет назад +5

    This is so awesome! I'm super interested in digital forensic investigation and in the future I would love to work for The High Tech Crime Unit (HTCU) of Thames Valley Police (UK). I have just started looking in to digital forensic investigation and there's a lot to learn. I have a tiny bit of knowledge in penetration testing and general IT which helps quite a bit. Overall, awesome tutorial and have subscribed for future videos. Keep up the awesome work! :D

  • @zacstrick6133
    @zacstrick6133 6 лет назад +1

    Skip to 5:18 if youre confident in your ability to name a fucking file

  • @robertrobinson2641
    @robertrobinson2641 5 лет назад +8

    What is the monitoring system on the right side of your screen? Thank you

    • @newworld6190
      @newworld6190 4 года назад +1

      that's a widget rainmeter

    • @npyl
      @npyl 4 года назад

      it is probably conky

  • @hirakhan8015
    @hirakhan8015 Год назад

    9:41 sir how you got direct to select data source? Actually i am very new to this app and i have to use this app for my internship. I don't know which data source type i should select to get what you have. Can you please help me?

  • @RP-kz5zo
    @RP-kz5zo 4 года назад +1

    Hello. Can i know what u are running on the right side of your windows

  • @chrisr531
    @chrisr531 4 года назад

    Very clever making the binary in your description a divider as well as a watermark. "DFScience"

  • @blacflako98
    @blacflako98 3 года назад

    What is the information column on the right? It's called how and could you tell me the software reference please

  • @ahmadzaky3385
    @ahmadzaky3385 3 года назад

    I need more🔥🔥🔥. Thank you very much for the learning. Can you suggest me where else should I study this?

  • @hamadaldossary8911
    @hamadaldossary8911 4 года назад +2

    perfect presentation thank so much and good bless u

  • @Browza22
    @Browza22 3 года назад

    Hey! Apologies for the random question but just regarding an issue I’m having with autopsy as I’m new to using it.
    In the extracted content metadata section the results tab is showing a file created in 2017 while the file meta data tab shows 2020
    A bit confused which creation date I should be recording! Thanks for any help!

  • @j.n.y790
    @j.n.y790 3 года назад

    well done on your efforts, a fantastically presented video! . A must watch

  • @virajpatil5310
    @virajpatil5310 5 лет назад +2

    Do you Know how to install Autopsy on Mac??

  • @ahsan-li7sh
    @ahsan-li7sh 7 лет назад +1

    thanks for you videos. you videos are so easy to understand. love it. i'm starting to learn about forensic investigation topic. you videos are helping me a lot. could you make a video sometimes about how someone can start to learn about forensic topic. specially when they just started and where to start and maybe lab setup.. .keep up good work and looking for new videos every week if possible ;)

    • @DFIRScience
      @DFIRScience  7 лет назад +1

      Thanks a lot Ahsan. I think I can make a video about how to get started in forensics. Let me know if you need anything else.

  • @absurdj_
    @absurdj_ 3 года назад

    is steganography detected with autopsy?

  • @ahmedabdullah8348
    @ahmedabdullah8348 4 года назад

    Hello the video is great thank you for the explanation
    I have aquestion my file encrypted with the ransomeware can i fix them with the prog

  • @akhilowle1
    @akhilowle1 7 лет назад +1

    Thank you so much all your videos,

  • @ahsan-li7sh
    @ahsan-li7sh 7 лет назад +2

    and one more thing, could also record your video in high quality. i can only see it 360 not 720p. would be great

    • @DFIRScience
      @DFIRScience  7 лет назад +1

      Yeah - any newer videos should be up to 1080p. Let me know if you have any trouble.

  • @hasibavi7539
    @hasibavi7539 3 года назад

    How to find last OS shutdown time by a user in Autopsy?

  • @renx215
    @renx215 7 лет назад +1

    Hey Josh, can you suggest a good test disk image for someone learning DF, I went to Digital Corpora, but some were too advanced for my skill level (dealing with networks) and the one dealing with the terrorist attack in DC was not available.

    • @DFIRScience
      @DFIRScience  7 лет назад

      Hello. Check out dfir.training - he has a great list of resources: www.dfir.training/index.php/lists/test-images-and-challenges If you want something very basic with a guide I highly recommend Linux LEO: www.linuxleo.com/

  • @ProCipher
    @ProCipher Год назад

    Thank you

  • @FIDEL_CASHFLOW_
    @FIDEL_CASHFLOW_ 7 лет назад +1

    I can't get it to recognize my phone, even though my phone is visible under "This PC". Does Autopsy not recognize phones?

    • @DFIRScience
      @DFIRScience  7 лет назад

      If the phone was assigned a drive letter (like E:), it should show up when you try to add source type "Local Disk", then select the drive letter. In older phones you can set your phone to be a "USB Mass Storage Device." Newer phones use MTP. MTP will likely cause problems with Autopsy reading directly. If you are trying to 'do forensics' on the device, connecting directly is not recommended. Even with a write blocker, the device may still make changes to the data. It is better to make an image of the mobile device, and analyze the image with Autopsy.

    • @FIDEL_CASHFLOW_
      @FIDEL_CASHFLOW_ 7 лет назад +4

      Okay, which program should I use to make an image of the device? I'm completely brand new at this.

  • @johnricker7064
    @johnricker7064 7 лет назад +1

    Great video, would it be possible to get the links mentioned?

    • @DFIRScience
      @DFIRScience  7 лет назад +1

      Sorry about that. Here they are:
      Autopsy: sleuthkit.org/autopsy/download.php
      Digital Corpora (test images): digitalcorpora.org/
      NIST NSRL (known hash set): www.nsrl.nist.gov/
      Please let me know if I missed anything.

    • @e.nchapman6991
      @e.nchapman6991 3 года назад

      @@DFIRScience Do you have a guide on best practice for making a computer into an iso without tampering with the information?

  • @davidhegedues
    @davidhegedues 6 лет назад

    If the suspect changed the child exploitation video or image extensions to a totally random, non existing file extension (e.x P01.jpg to P01.aym) how would you be able to tell Autopsy to look for these file extensions? I mean if you do not know the file extension .aym just looking for file types that are not recognised by windows or any other OS?

    • @Zestypanda
      @Zestypanda 5 лет назад

      Neri Matrixx Meta data. There's a neat little tool that can dig into md5 hash and exif data as well as xmp. If you are actually looking into chil abuse look for contact sheets they are databases with md5 hashes of known files.

  • @mahenrathod5285
    @mahenrathod5285 3 года назад

    Good one. but background music is interrupting

  • @ahsan-li7sh
    @ahsan-li7sh 7 лет назад

    sorry, I just figured out the video problem. at home ICAN watch your videos with HD quality. but in my university lower quality.

  • @snederadi2014
    @snederadi2014 7 лет назад

    Can you help me ? I aopruciate your answer. While im trying to mount image i had error massage : cannot determine file system : offset 63. Thank you

    • @DFIRScience
      @DFIRScience  7 лет назад

      Bramantyo Adi first check that your offset is correct. Use mmls to list partition information and get the starting offset and verify the file system type. If the offset is correct, try adding -f and the fstype. For some reason sleutkit cannot auto detect the installed fs.

  • @annemarie9318
    @annemarie9318 3 года назад

    may I know how to identify bookmarks?

    • @DFIRScience
      @DFIRScience  3 года назад

      After processing a source file, Autopsy will show a directory tree view on the left-hand side. At the bottom of that view, you should see "Tags." Expand that, and if you have created bookmarks, you will see "Bookmarks." You must tag or bookmark at least one item before the category shows up in the menu.

    • @annemarie9318
      @annemarie9318 3 года назад

      @@DFIRScience its okay now. I have downloaded the wrong version of the tool. That's why it wont show up. Thank you anyway ❤️

  • @ademolaisijola5236
    @ademolaisijola5236 3 года назад

    please i need help with my assignment please i beg off you

  • @empostman9409
    @empostman9409 5 лет назад

    Awesome. Thank you.

  • @absurdj_
    @absurdj_ 3 года назад

    thanks!

  • @JN003
    @JN003 5 лет назад

    i guess u need a disk image for android phone ... how to image a phone... ?? thx

  • @praveenjeeva6182
    @praveenjeeva6182 3 года назад

    Bro, Disks were not detected .

    • @DFIRScience
      @DFIRScience  2 года назад

      If you're trying to add local disks (like C:) then you will have to start Autopsy with administrator privileges. If you are opening disk images you can open it as a normal user.

  • @paulcantshutup
    @paulcantshutup 2 года назад

    >Widnows 10
    Hmm.

    • @paulcantshutup
      @paulcantshutup 2 года назад

      (I mean I still subscribed it just made me giggle.)

  • @rosiemaldonado8309
    @rosiemaldonado8309 3 года назад +1

    Better without the music. The music is distracting from your speaking.

    • @DFIRScience
      @DFIRScience  3 года назад

      Thanks for the feedback!

    • @rosiemaldonado8309
      @rosiemaldonado8309 3 года назад

      @@DFIRScience you are in my digital forensics class as recommended watching.

    • @DFIRScience
      @DFIRScience  3 года назад

      @@rosiemaldonado8309 cool! Let me know if you have any questions. 😸

  • @apes2426
    @apes2426 2 года назад

    Where can I get free evidence files for testing

    • @DFIRScience
      @DFIRScience  2 года назад +1

      Various disk images can be found at the Digital Corpora: digitalcorpora.org/

  • @adrian8729
    @adrian8729 5 лет назад

    Uh...

  • @HallPh.D.
    @HallPh.D. 4 года назад

    Sweet Jesus, man! A 30-minute video and 5 minutes are spent on the case name?

    • @DFIRScience
      @DFIRScience  4 года назад +1

      Sure is. Most labs I've worked in have no naming standards. It's one of the easiest ways to organize across the team, but often overlooked.

  • @666og
    @666og 3 года назад

    5 minutes spent on the case name what a waste of time i wont even watch the rest