Starting a New Digital Forensic Investigation Case in Autopsy 4.2

  Рет қаралды 100,307

DFIRScience

DFIRScience

Күн бұрын

Пікірлер: 66
@michaelwhitlow372
@michaelwhitlow372 6 жыл бұрын
Autopsy is the best kept secret in digital forensics. Love the tool, and love this video. Thank you.
@annemarie9318
@annemarie9318 2 жыл бұрын
hello may I know how to identify bookmarks?
@nikeplayer90game
@nikeplayer90game 5 жыл бұрын
A video that isn't boring. THANK YOU!! this was super informative and easy to understand
@abhijeetbhujbbal8667
@abhijeetbhujbbal8667 3 жыл бұрын
This is an amazing video. Easy and to the point explanation. Excellent work.
@fenimama
@fenimama 5 жыл бұрын
Appreciation. But just Seven minutes dedicated on naming and storing your investigation. Thankyou for the video.
@Slinky
@Slinky 7 жыл бұрын
This is so awesome! I'm super interested in digital forensic investigation and in the future I would love to work for The High Tech Crime Unit (HTCU) of Thames Valley Police (UK). I have just started looking in to digital forensic investigation and there's a lot to learn. I have a tiny bit of knowledge in penetration testing and general IT which helps quite a bit. Overall, awesome tutorial and have subscribed for future videos. Keep up the awesome work! :D
@hamadaldossary8911
@hamadaldossary8911 4 жыл бұрын
perfect presentation thank so much and good bless u
@j.n.y790
@j.n.y790 3 жыл бұрын
well done on your efforts, a fantastically presented video! . A must watch
@robertrobinson2641
@robertrobinson2641 5 жыл бұрын
What is the monitoring system on the right side of your screen? Thank you
@newworld6190
@newworld6190 4 жыл бұрын
that's a widget rainmeter
@npyl
@npyl 4 жыл бұрын
it is probably conky
@ahsan-li7sh
@ahsan-li7sh 7 жыл бұрын
thanks for you videos. you videos are so easy to understand. love it. i'm starting to learn about forensic investigation topic. you videos are helping me a lot. could you make a video sometimes about how someone can start to learn about forensic topic. specially when they just started and where to start and maybe lab setup.. .keep up good work and looking for new videos every week if possible ;)
@DFIRScience
@DFIRScience 7 жыл бұрын
Thanks a lot Ahsan. I think I can make a video about how to get started in forensics. Let me know if you need anything else.
@chrisr531
@chrisr531 4 жыл бұрын
Very clever making the binary in your description a divider as well as a watermark. "DFScience"
@akhilowle1
@akhilowle1 7 жыл бұрын
Thank you so much all your videos,
@ahmadzaky3385
@ahmadzaky3385 3 жыл бұрын
I need more🔥🔥🔥. Thank you very much for the learning. Can you suggest me where else should I study this?
@ProCipher
@ProCipher Жыл бұрын
Thank you
@RP-kz5zo
@RP-kz5zo 4 жыл бұрын
Hello. Can i know what u are running on the right side of your windows
@virajpatil5310
@virajpatil5310 5 жыл бұрын
Do you Know how to install Autopsy on Mac??
@ahsan-li7sh
@ahsan-li7sh 7 жыл бұрын
and one more thing, could also record your video in high quality. i can only see it 360 not 720p. would be great
@DFIRScience
@DFIRScience 7 жыл бұрын
Yeah - any newer videos should be up to 1080p. Let me know if you have any trouble.
@blacflako98
@blacflako98 3 жыл бұрын
What is the information column on the right? It's called how and could you tell me the software reference please
@hirakhan8015
@hirakhan8015 Жыл бұрын
9:41 sir how you got direct to select data source? Actually i am very new to this app and i have to use this app for my internship. I don't know which data source type i should select to get what you have. Can you please help me?
@mahenrathod5285
@mahenrathod5285 3 жыл бұрын
Good one. but background music is interrupting
@ahmedabdullah8348
@ahmedabdullah8348 4 жыл бұрын
Hello the video is great thank you for the explanation I have aquestion my file encrypted with the ransomeware can i fix them with the prog
@renx215
@renx215 7 жыл бұрын
Hey Josh, can you suggest a good test disk image for someone learning DF, I went to Digital Corpora, but some were too advanced for my skill level (dealing with networks) and the one dealing with the terrorist attack in DC was not available.
@DFIRScience
@DFIRScience 7 жыл бұрын
Hello. Check out dfir.training - he has a great list of resources: www.dfir.training/index.php/lists/test-images-and-challenges If you want something very basic with a guide I highly recommend Linux LEO: www.linuxleo.com/
@empostman9409
@empostman9409 5 жыл бұрын
Awesome. Thank you.
@hasibavi7539
@hasibavi7539 3 жыл бұрын
How to find last OS shutdown time by a user in Autopsy?
@absurdj_
@absurdj_ 3 жыл бұрын
is steganography detected with autopsy?
@johnricker7064
@johnricker7064 7 жыл бұрын
Great video, would it be possible to get the links mentioned?
@DFIRScience
@DFIRScience 7 жыл бұрын
Sorry about that. Here they are: Autopsy: sleuthkit.org/autopsy/download.php Digital Corpora (test images): digitalcorpora.org/ NIST NSRL (known hash set): www.nsrl.nist.gov/ Please let me know if I missed anything.
@e.nchapman6991
@e.nchapman6991 3 жыл бұрын
@@DFIRScience Do you have a guide on best practice for making a computer into an iso without tampering with the information?
@Browza22
@Browza22 3 жыл бұрын
Hey! Apologies for the random question but just regarding an issue I’m having with autopsy as I’m new to using it. In the extracted content metadata section the results tab is showing a file created in 2017 while the file meta data tab shows 2020 A bit confused which creation date I should be recording! Thanks for any help!
@absurdj_
@absurdj_ 3 жыл бұрын
thanks!
@JN003
@JN003 5 жыл бұрын
i guess u need a disk image for android phone ... how to image a phone... ?? thx
@FIDEL_CASHFLOW_
@FIDEL_CASHFLOW_ 7 жыл бұрын
I can't get it to recognize my phone, even though my phone is visible under "This PC". Does Autopsy not recognize phones?
@DFIRScience
@DFIRScience 7 жыл бұрын
If the phone was assigned a drive letter (like E:), it should show up when you try to add source type "Local Disk", then select the drive letter. In older phones you can set your phone to be a "USB Mass Storage Device." Newer phones use MTP. MTP will likely cause problems with Autopsy reading directly. If you are trying to 'do forensics' on the device, connecting directly is not recommended. Even with a write blocker, the device may still make changes to the data. It is better to make an image of the mobile device, and analyze the image with Autopsy.
@FIDEL_CASHFLOW_
@FIDEL_CASHFLOW_ 7 жыл бұрын
Okay, which program should I use to make an image of the device? I'm completely brand new at this.
@ahsan-li7sh
@ahsan-li7sh 7 жыл бұрын
sorry, I just figured out the video problem. at home ICAN watch your videos with HD quality. but in my university lower quality.
@ademolaisijola5236
@ademolaisijola5236 3 жыл бұрын
please i need help with my assignment please i beg off you
@davidhegedues
@davidhegedues 5 жыл бұрын
If the suspect changed the child exploitation video or image extensions to a totally random, non existing file extension (e.x P01.jpg to P01.aym) how would you be able to tell Autopsy to look for these file extensions? I mean if you do not know the file extension .aym just looking for file types that are not recognised by windows or any other OS?
@Zestypanda
@Zestypanda 5 жыл бұрын
Neri Matrixx Meta data. There's a neat little tool that can dig into md5 hash and exif data as well as xmp. If you are actually looking into chil abuse look for contact sheets they are databases with md5 hashes of known files.
@snederadi2014
@snederadi2014 6 жыл бұрын
Can you help me ? I aopruciate your answer. While im trying to mount image i had error massage : cannot determine file system : offset 63. Thank you
@DFIRScience
@DFIRScience 6 жыл бұрын
Bramantyo Adi first check that your offset is correct. Use mmls to list partition information and get the starting offset and verify the file system type. If the offset is correct, try adding -f and the fstype. For some reason sleutkit cannot auto detect the installed fs.
@annemarie9318
@annemarie9318 2 жыл бұрын
may I know how to identify bookmarks?
@DFIRScience
@DFIRScience 2 жыл бұрын
After processing a source file, Autopsy will show a directory tree view on the left-hand side. At the bottom of that view, you should see "Tags." Expand that, and if you have created bookmarks, you will see "Bookmarks." You must tag or bookmark at least one item before the category shows up in the menu.
@annemarie9318
@annemarie9318 2 жыл бұрын
@@DFIRScience its okay now. I have downloaded the wrong version of the tool. That's why it wont show up. Thank you anyway ❤️
@praveenjeeva6182
@praveenjeeva6182 3 жыл бұрын
Bro, Disks were not detected .
@DFIRScience
@DFIRScience 2 жыл бұрын
If you're trying to add local disks (like C:) then you will have to start Autopsy with administrator privileges. If you are opening disk images you can open it as a normal user.
@zacstrick6133
@zacstrick6133 5 жыл бұрын
Skip to 5:18 if youre confident in your ability to name a fucking file
@rosiemaldonado8309
@rosiemaldonado8309 3 жыл бұрын
Better without the music. The music is distracting from your speaking.
@DFIRScience
@DFIRScience 2 жыл бұрын
Thanks for the feedback!
@rosiemaldonado8309
@rosiemaldonado8309 2 жыл бұрын
@@DFIRScience you are in my digital forensics class as recommended watching.
@DFIRScience
@DFIRScience 2 жыл бұрын
@@rosiemaldonado8309 cool! Let me know if you have any questions. 😸
@paulcantshutup
@paulcantshutup 2 жыл бұрын
>Widnows 10 Hmm.
@paulcantshutup
@paulcantshutup 2 жыл бұрын
(I mean I still subscribed it just made me giggle.)
@apes2426
@apes2426 2 жыл бұрын
Where can I get free evidence files for testing
@DFIRScience
@DFIRScience 2 жыл бұрын
Various disk images can be found at the Digital Corpora: digitalcorpora.org/
@adrian8729
@adrian8729 5 жыл бұрын
Uh...
@HallPh.D.
@HallPh.D. 3 жыл бұрын
Sweet Jesus, man! A 30-minute video and 5 minutes are spent on the case name?
@DFIRScience
@DFIRScience 3 жыл бұрын
Sure is. Most labs I've worked in have no naming standards. It's one of the easiest ways to organize across the team, but often overlooked.
@666og
@666og 3 жыл бұрын
5 minutes spent on the case name what a waste of time i wont even watch the rest
Starting a New Digital Forensic Investigation Case in Autopsy 4.19+
38:59
Is your PC hacked? RAM Forensics with Volatility
14:29
The PC Security Channel
Рет қаралды 910 М.
At the end of the video, deadpool did this #harleyquinn #deadpool3 #wolverin #shorts
00:15
Anastasyia Prichinina. Actress. Cosplayer.
Рет қаралды 19 МЛН
Will A Guitar Boat Hold My Weight?
00:20
MrBeast
Рет қаралды 188 МЛН
Mr. EVIL Hacking Case Investigation with Autopsy
34:14
Kumar Priyanshu
Рет қаралды 2,8 М.
Autopsy - Forensic Acquisition Tool  | Digital Forensics Investigation | Autopsy Tutorial
23:17
Free Education Academy - FreeEduHub
Рет қаралды 89 М.
Cyber Forensics
40:53
Sheenam Arora
Рет қаралды 148 М.
RECOVERING FILES with Autopsy (PicoCTF 2022 #47 'operation-oni')
14:00
Forensic Acquisition in Windows - FTK Imager
29:03
DFIRScience
Рет қаралды 162 М.
Disk Analysis with Autopsy | HackerSploit Blue Team Training
52:45
Akamai Developer
Рет қаралды 16 М.
DFS101: 1.1 Introduction to digital forensics
21:41
DFIRScience
Рет қаралды 142 М.
Data Artifacts, Analysis Results and Reporting in Autopsy 4.19+
33:54
At the end of the video, deadpool did this #harleyquinn #deadpool3 #wolverin #shorts
00:15
Anastasyia Prichinina. Actress. Cosplayer.
Рет қаралды 19 МЛН