IY467 Lab 5 - Introduction To Autopsy
IY467 Lab 5 - Introduction To Autopsy
Contents
1 Aim and Objectives.....................................................................3
Objectives........................................................................................................3
2 Introduction...............................................................................3
5 Conclusions...............................................................................12
Page 2
UWEBIC IY467 Digital Evidence
Objectives
2 Introduction
Please note that the “Hunter XP for Dongled v6” E01 evidence file you are
working on (that contains the Hunter Case image) is the one you are using to
complete your coursework. You should already have opened this with EnCase. If you
still do not know how to access this file and how to copy it onto your VM, please go
back to the previous lab sessions and complete them first.
This week we are looking at Autopsy, which is an alternative forensic tool, and using
it to perform dual verification. Why is dual verification important? Remember that
software is written by human beings – mistakes are possible. If we get a different
result by two different tools, we will spot the error.
It has been observed that when tools make errors, the same error is not made
by different tools. When comparing the outcome of two tools, errors are
revealed and the item in question will have to be examined in more detail.
(Friheim, 2016)
If you have dual verified the key pieces of evidence that your case depends on,
you make it much harder for a defence team to discredit them.
Note: Remember that dual verification is an important step, and you should
document it in your contemporaneous notes for the Hunter XP Case.
Page 3
UWEBIC IY467 Digital Evidence
3 Task 1: Introduction to Autopsy
Download the Autopsy software from Autopsy - Download
(https://www.autopsy.com/download/)
For this task you will use an image acquired from a USB drive. If you still
have it, you can also use the USB image you created with FTK Imager in
the Lab 2 practical session. Alternatively, you can use either of the USB
images here:
https://kaplanint-my.sharepoint.com/:f:/g/personal/
eleanor_combley_aspectworld_com/
ErGfSIRi93RLoVDF6mGLGhEBt7NTFZrl6J13AYtEzdvu0A?e=7FAXyL
When you start Autopsy you will see the Autopsy Welcome screen (Figure
21).
Page 4
UWEBIC IY467 Digital Evidence
Click on the Create New Case button and provide the Case Name and the
Base Directory, which is the place where relevant data will be stored. I chose
my Desktop as the Base directory for this demonstration (see Figure 22).
Page 5
UWEBIC IY467 Digital Evidence
Hit Next and provide additional information for the case. Hit Finish when
you are done (Figure 23).
Autopsy will create the case. Be patient as it needs some time to do that.
Then you will see a pop- up window asking you to add the evidence file
(just like EnCase). Choose “Disk Image or VM file” and then browse to the
USB image file when prompted to “Select Data Source”; it should be the
USBimage.001 file you just downloaded, or the one you created during the
previous week. The provided file is 492 MB (see Figure 24).
Page 6
UWEBIC IY467 Digital Evidence
Ensure that the timezone is GMT (+0:00) Europe/London and click Next
as figure 25 shows.
Then Autopsy loads the evidence and a pop up window presents the options
for the evidence processing. There is no need to go through these options
now in details. You can do that in your own time if you are interested.
Uncheck the Android Analyzer option. Although there might be a possibility
that the USB contained an image from an Android device, we will skip this
step now. Ensure that the Process Unallocated Space field is checked and
hit Next (see figure 26) and then Finish.
Page 7
UWEBIC IY467 Digital Evidence
Autopsy will start analysing files from the imported image as you can see in
Figure 27. When it is done you can see a report clicking on the yellow tri-
angular shape (indicated in black in Figure 28). Note that the user interface
might have changed a bit since the screenshot (figure 26) was taken...
Autopsy launches the evidence processor when we start a new case. Note
that the USB image file was very small. You should expect longer
processing times when you are dealing with real evidence.
Page 8
UWEBIC IY467 Digital Evidence
Clicked on the Exif Metadata (under the Results section) from the Tree
structure. You will see similarities with EnCase, although Autopsy has less
functionality, as seen in Figure 29.
Page 9
UWEBIC IY467 Digital Evidence
Page 10
UWEBIC IY467 Digital Evidence
Page 11
UWEBIC IY467 Digital Evidence
5 Conclusions
Today you carried out your best practices by verifying your evidence
acquisition and setting the proper time zone offset to your evidence. You
learned how to use the Evidence Processor and you did your first analysis on
Email and Internet artifacts. You should also understand that dual
verification is important and it must be performed regularly to ensure data
integrity and maintain best standards. Additionally, you have started taking
detailed contemporaneous notes of your investigation that would ensure its
repeatability.
References
Page 12