Backtrack 4 R2 Digital Forensics Autopsy - Case Management

preview_player
Показать описание

The command I used for the link:
Рекомендации по теме
Комментарии
Автор

I will actually have a new series posted on forensics within the next two weeks. I am using Ubuntu, which is what Backtrack is based off of. I will be discussing autopsy, sleuthkit, as well as a several other tools found in the open source community. The series will offer a more methodical approach to computer forensics.

MatthewPenning
Автор

@polarbear35353
To get an image of a partition or hard drive you can use the dcfldd command. You do not need to be online to use Autopsy. When you run the application it starts up a web server on the computer itself and you connect to it via your web browser. I several vids on my web site that are focused on using Backtrack, but you can substitute Ubuntu for many of the tasks as long as you have the software on it.

lecturesnippets
Автор

In one of your other videos I thought you created an image in /mnt/data in your DCFLDD video. So I'm a bit confused, is there a different video I should have watched? I really want to learn more about this topic.

alexhosch
Автор

I have a portable hard disk that's essentially unmountable (the Windows PC it was connected to crashed and I guess that destroyed the FAT structures on it). Will Autopsy allow me to recover the data on it?

anuragsingh