Autopsy
Autopsy provides the tools you need to perform a detailed investigation in Mobile Forensics. It is an open-source digital forensics platform used to investigate a compromised system or conducting a forensic analysis of device. It contains various tools which can help throughout the process:-
STEP 1: DOWNLOAD AND INSTALLATION
a. Visit this link below to download Autopsy for any system (Windows/Linux/MacOS)
https://www.autopsy.com/download/
b. Install Autopsy via following installation wizard and open the software once installed on your system
STEP 2: CREATING NEW CASES
a. Once installation is completed, we need to click on "Create New Case" on the main screen
b. Enter case details such as Case Name and directory where you want to store it
c. Further, provide the case number and Examiner name so your investigation remains organized
d. Lastly, click on "Finish" and your case is ready for investigation
STEP 3: ADDING A DATA SOURCE
a. You have to add a data source to investigate the data
b. Your choices for data source can be disk image, local disk, logical file, or unallocated space image
c. Click "Next" to configure any additional settings
STEP 4: CONFIGURE INGEST MODULES
a. Ingest modules automate tasks like identifying file types, keyword searching and checking for unknown malicious files
b. Select relevant ingest modules
c. Keyword search: Automatically search the data for specific terms
d. File type identification: Sort files by their type for easier navigation
e. Hash Lookup: Compare life hashes against databases of known good or bad files
f. Email Parser: Extract and analyze email if applicable
g. Once you have clicked "Next" and then "Finish". Autopsy will begin processing your data source based on the modules you've chosen
STEP 5: ANALYZE THE DATA
a. File system viewer: Navigate through the directory structure of the analyzed device
b. Results Viewer: View results from the various ingest modules, such as identified documents, images, or logs
c. Timeline Analysis: Create a timeline of events (file creation,modification etc) to visualize the sequence of actions on the device
d. Bookmarks: Bookmark important files or findings for easy reference. This feature is especially useful for building your case
STEP 6: PERFORM KEYWORD SEARCHES
a. You can search for specific terms across all the evidence via keyword searches
b. Head to "Keyword search" tab
c. Enter the keyword and phrase you are looking for (eg: username or password)
d. Autopsy will search for entire dataset for your keywords and present the results for further analysis
STEP 7: GENERATING A REPORT
a. After completing your analysis, you need to create a report to present your findings
b. Click the "Generate Report" button located in toolbar
c. Select the report type: You can choose from HTML,PDF,EXCEL,CSV and other formats depending on your needs
d. Select the data to include: Specify which part of analysis should be included in the report
e. Click "Generate" and Autopsy will create the report. The report will be saved into your specific case directory, ready for sharing or documentation
STEP 8: ADDITIONAL TIPS
a. Right click on any file or folder and choose "Export" to save it in your local machine
b. Document findings is for keeping a thorough notes on your investigations and results for your future references
c. Autopsy supports third-party plugins and modules which allows you to perform special tasks
d. If you are working in a team then Autopsy supports multi-user environments, enabling multiple investigators to perform case simultaneously
e. Always maintain detailed notes and recordings of your findings, particularly if you anticipate using this evidence for legal work
f. Autopsy is a very versatile and powerful tool for digital forensics. Whether you are investigating compromised computer, analyzing a mobile device or conducting a forensic investigation, Autopsy offers the tools you need to uncover the truth
Comments
Post a Comment