Autopsy
Autopsy
24
Page 325 from Guide to Computer Forensics and Investigations 4th edition
Sleuth Kit base program for Unix investigations. Uses a command-line interface. Autopsy Graphical User Interface (GUI) that sits on top of Sleuth Kit commandline interface. Allows access to Sleuth Kit functions via a GUI.
Select number 2 on your KVM Switch Press the power button on the MAC Login in to the student account Password: $tudent1
Starting Autopsy
At Terminal change the working directory by typing cd /autopsy-2.24/ without the quotes Now type sudo ./autopsy and enter the Student password Be sure to add spaces after cd and sudo Right-click on http://localhost:9999/autopsy and select Open URL
Case name: GCFI-CH8 Description: Superior Bicycle Investigation Investigator Names: a. Your Name Click New Case
Adding an Image
CaSe SeNsItIvE Location: /Forensics/CH8/ LX/GCFI* (entries are case sensitive) Type: Partiton
Click the Calculate the hash value for this image Click Add This will take a few minutesso dont keep clicking the Add button
Notice the blue bar in the URL, this means it is calculating the hash value Verify your hash value matches the value in the slide
Click Analyze
Keyword Search
Keywords
Note the Magnifying glass under key word search. This is where you currently are Type martha in the search box Click Search You will not see a status so be patient and dont mash buttons
Keyword Search
If case sensitive was selected typing Martha or martha would give you different results This search takes about 6 minutes Click link to results
Timelines
Click File Activity Time Lines button
Creating a Timeline
Select GCFI-LXbody
Creating a Timeline
The timeline will also take about 30 seconds to generate When the timeline is complete click OK
Viewing a Timeline
Use the navigation buttons under the menus to select the dates to view You can also navigate to the text file by opening CIS POD, Forensics, EvLocker, GCFICH8, sb10, output and selecting timeline.txt
You can then click the red x in the upper left corner to close Terminal