Starting a New Digital Forensic Investigation Case in Autopsy 4.19+

Starting a New Digital Forensic Investigation Case in Autopsy 4.19+

DFIRScience

2 года назад

126,092 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

Eltoruan
Eltoruan - 27.09.2023 11:48

cool

Ответить
DThorn
DThorn - 17.09.2023 20:20

Very interesting material for someone starting in the IR team. Great video!

Ответить
Margalocaris
Margalocaris - 19.08.2023 19:14

Very thorough explanation! Your videos have been pointed to by one of my college professors.

Ответить
Filza Akhlaq
Filza Akhlaq - 04.05.2023 02:20

The link in your description for sample data doesn't contain the hash file that is in the video. it only has an image .dd file. How do I proceed ?

Ответить
Thomas Howard, 4th Duke of Norfolk
Thomas Howard, 4th Duke of Norfolk - 29.04.2023 00:49

How can I do the parts using linux? I'm using a windows vm on mac

Ответить
Malem Mutum
Malem Mutum - 22.04.2023 22:56

I thoroughly enjoyed it! Thanks for the great tutorial.

Ответить
Kyle Myers
Kyle Myers - 11.04.2023 05:51

Thank you so much for this! Do you happen to have a video or guide on how to upload an iPhone or Apple device into FTK imager to create a readable format for autopsy?

Ответить
Rekha Jadhav
Rekha Jadhav - 10.03.2023 05:16

Thank you for the best video. I have one doubt, though. During the case creation, we can add M5. However, we cannot add SHA512. there is only the option of adding SHA256.

Ответить
maxi röll
maxi röll - 12.02.2023 15:50

Awesome tutorial, thanks a lot <3

Ответить
Jordan Ryan
Jordan Ryan - 16.12.2022 03:18

how do i create a disk image, i want to practise on my own machine and recover things ive deleted from it but cant find anything on how to create a disk image that i can use for autopsy

Ответить
michal sedlacek
michal sedlacek - 07.12.2022 18:28

This is amazing video with great works very well

Ответить
Butrus Cypriano oturo onyong
Butrus Cypriano oturo onyong - 26.11.2022 22:50

thank you master for the basic introduction of using autospy in digital forensic. i have watch the video is very interesting. my gratitude and wish you all the best

Ответить
高畑栞奈
高畑栞奈 - 20.11.2022 03:59

cannot able forensic about encript ios buck up

Ответить
Billboard
Billboard - 14.11.2022 03:43

Great explanation, thanks

Ответить
Aniket Amdekar
Aniket Amdekar - 20.10.2022 10:38

awesome tutorial for learning the Autopsy tool! Can you also share some good sources for getting forensic images for data recovery challenges?

Ответить
Miejoe
Miejoe - 11.10.2022 06:10

Thanks for the tutorial! I'm a criminal law student so Digital Forensic Investigation is really interesting. I've always wondered how gathering digital evidence works. I learned a lot from your tutorial!

Ответить
Mallah Ata
Mallah Ata - 22.09.2022 14:44

hi is it possible to use autopsy to repair corrupted video file ?

Ответить
Courtney Kanopka
Courtney Kanopka - 17.09.2022 03:47

I have an image file on an external HD I run autopsy and it parses through and says finished but it will never load the image in.

Ответить
Sahil Patel
Sahil Patel - 06.09.2022 07:32

everytNice tutorialng. It was still interesting. Wish I had tNice tutorials video when I started out

Ответить
Rahul Yadav
Rahul Yadav - 02.09.2022 09:00

TNice tutorials was very helpful thankyou.

Ответить
Simranjit Singh
Simranjit Singh - 02.08.2022 20:32

where to get hash values and other data shown in video, only dd file is downloadable in the given link

Ответить
Tomás Montenovi
Tomás Montenovi - 25.07.2022 01:35

Thank you for this well made tutorial!

Ответить
Steven Jeansonne
Steven Jeansonne - 18.07.2022 07:19

If you have a partition that is encrypted and have the key /password how do you ingest it or import it?

Ответить
Citizen Z Reincarnated
Citizen Z Reincarnated - 07.07.2022 06:09

Thank you so much for this, you are very thorough and provide a high level overview in this video of the various ingest modules which is very helpful. I do have one question though and perhaps this comes later in the video or another video on your channel. When is the best time to configure the settings of Autopsy outside of a case? I would assume it would be prior to starting the first case on my machine. My question really applies to configuring things like the temporary directory of autopsy, changing the central repository, etc etc.

Ответить
Shade Williams
Shade Williams - 16.06.2022 05:41

Hi I am new to all of this. I downloaded the practice data and I think I don't have the right format as it does not look the same as what you are showing. I have a windows 11 machine. What should I open the file with? Thanks.

Ответить
Bruno
Bruno - 05.06.2022 03:18

Now we know that the evil cat abused the dog... The dog, curiously named jack, was the victim.

Ответить
Adibuzz08
Adibuzz08 - 29.05.2022 05:12

Hi can this be used to view video aswell

Ответить
VONcheshire
VONcheshire - 03.05.2022 19:28

wow

Ответить
Zidane Tribal
Zidane Tribal - 12.04.2022 04:52

Found a new DFIR channel gem <3

Ответить
J. S.
J. S. - 02.04.2022 06:27

Seriously the best introductory/basic-workflow Autopsy video I've watched. I absolutely love that you give additional detail about the modules, and that you explained your workflow.

Ответить
Michael Paul
Michael Paul - 23.02.2022 04:29

Thanks for overview, how well does Autopsy do with video?

Ответить
Tammy Rhodes
Tammy Rhodes - 19.02.2022 02:14

How do you view emails? I don’t see an option for it because I keep getting a “read error”

Ответить
- 18.02.2022 08:36

Love it, thank you for the content

Ответить
Sreeraj K
Sreeraj K - 17.02.2022 11:11

can I do with android images?

Ответить
Alayegun Adewale ojo
Alayegun Adewale ojo - 12.02.2022 18:20

Great video!

What other steps can be taken to be able to view content of a carved deleted file which was unallocated and not viewable using the application feature in Autopsy?

Is it possible to rebuild those kinda files to view the contents? Thanks.

Ответить
Batman
Batman - 11.02.2022 03:03

Love the video! I'm 15 and I wanna getting to dfir any advices for learning. Should I go college etc?

Ответить
BlueMonkey 4n6
BlueMonkey 4n6 - 10.02.2022 17:36

Excellent content as always!

Ответить
M.•.C
M.•.C - 09.02.2022 17:07

Amazing video! Nevertheless, it would have been better to use the dd/ISO files that NIST put at disposal to see all the functionalities of the software

Ответить
testuc3
testuc3 - 09.02.2022 16:10

good stuff

Ответить
NightShooter Web Development
NightShooter Web Development - 09.02.2022 13:39

FTK and Autopsy are the one's I always use. Great vid.

Ответить
Thanh Phương Lê
Thanh Phương Lê - 09.02.2022 12:15

after trying around 5-11 videos this is the only one that i found working

Ответить
lai yitming
lai yitming - 09.02.2022 04:11

Great tool for forensic .

Ответить
Adm OConnors
Adm OConnors - 09.02.2022 03:32

This is good. Thanks for this.

Ответить
Chinz
Chinz - 08.02.2022 19:58

How to quickly paste timestamp for documentation in linux?

Ответить
dyarizadeh3
dyarizadeh3 - 08.02.2022 19:47

Fantastic!

Ответить
FA
FA - 08.02.2022 19:04

Glad that I found your channel 👍🏽👍🏽

Ответить
Pack Leader
Pack Leader - 08.02.2022 18:41

Thank you

Ответить