Professional Documents
Culture Documents
Autopsy Sections 14-17
Autopsy Sections 14-17
Autopsy Sections 14-17
___
Notes
Terminology
Device account
● Special account created for each data source to represent the physical device when we
don’t have a better account ID
○ Often used to define a relationship for call logs and contact books on a phone; i.e
call log database defines only the other recipient
Using interface
Tabs
Messages Tab
● Shows all inbound and outbound calls associated with selected account
Contacts tab
● Shows contacts that contain the account/belong to the account (typically for a ‘device
account’ for latter)
Normal operations
● Within UI right click to have same options to view in timeline, tag, etc.
Conclusion
● Creating tags
● Adding comments
● Generating various report types to export results
● Creating a portable case with a subset of your data
Tagging
● What is it?
○ Can make a reference to a file or object and easily find it later; bookmarking
○ Comment on file/ highlight part of picture that is relevant
● use it to find files later to follow up on & identify “bad” files to report
Tag names
Tagging a result
Tagging a picture
● Tag specific region of a picture → application view, tags menu; choose create or whatever
you need
○ Save coordinates in database, not editing image; if want to actually draw box,
import
Viewing tags
Delete tag
● Tags are associated with the examiner who made them; can see who made them
● Hide tags that are not yours in options panel
C Repo Updating
● If central repo is enabled when you tag a file as “notable” → stores tagging
● Alerts can be generated in the future when that file is seen again if the Correlation
Engine ingest module is enabled
Comments
See comments
● Makes a report that you can send to others or use in other report formats
● Extensible framework; comes with:
○ HTML and Excel Results (focus on results and blackboard artifacts), Text file
(each file and metadata), KML File (Google Earth), Add tagged files to hash set,
Portable case
Specify header/footer
File reports
● Show what files are in the case; one line per file
● Columns for metadata; can choose which metadatas
KML report
● Add all of your final tagged files to a hash set; use “save tagged hashes” report module
(if C repo isn’t on)
Portable case
● Autopsy case that includes only a subset of the data form its original case
○ Only tagged files, interesting item hits
● Self contained
○ Has own SQlite database; all files are located in the case folder
● Can be shared with any users for review or assistance
Settings
● Choose what gets added to the case; compress/split into small chunks
● Default is to make folder, up to you to transport it
○ Allows CV/DVD chunks to communicate
Open
Using
● Portable case is just like a normal case; just a lot less data
● Can run ingest modules, tag files, generate reports, etc.
Accessing reports
Conclusion
● Tags are used to mark files for final reporting, follow up, other workflow stages
● Comments can be added to items and stored either at the case level or in the C repo
● Various forms or report formats that allow you to export results
● Portable cases are a small subset of you original case that can be opened by another user
Types of Modules
Finding modules
● Github repo exists to list publicly available modules (sleuthkit addon modules)
Module concepts
Java
Python
● If the module was shipped as a ZIP file, extract the contents to a folder
● Open the python modules folder → copy the module folder into the plugins folder
● Everything has to be kept in separate folders to prevent collisions
Conclusion
● Course:
○ Making a case and adding a data source
○ How to analyze the data source
○ Various UIs
○ Tagging Reporting
○ Installing 3rd party apps
● There’s a lot more to cover, but it takes more than 1 day
Typical workflow
1. Create a case
2. Add a data source
3. Configure keywords that are case relevant
4. Run ingest with all relevant modules
5. Start to review data as it comes in
6. Update keywords as you find more relevant terms
7. Tag files of interest
8. Generate report
Getting involved
OSDFCon is Digital Forensics tools conference; attend to learn about latest features and
modules, free to government employees