Backtrack 4 R2 Digital Forensics Autopsy - Case Management

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
2,290
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Apr 1, 2011

This video is the first in a series of Autopsy videos. In this video I examine the Digital Forensics tool Autopsy found on the Backtrack operating system and setup a case. Autopsy is a graphical front-end for the Sleuth Kit tools. I create a case, host, and add an image to the host. In the video I had to create a symbolic link to my forensics hard drive because of the volume name containing a space. For more information visit http://lecturesnippets.com

The command I used for the link:
ln -s "/media/New Folder/winxpimage.dd" /media/Forensics/

Category:

Science & Technology

Tags:

License:

Standard YouTube License

  • likes, 0 dislikes

Link to this comment:

Share to:

Uploader Comments (lecturesnippets)

  • Hello, I apologize if I sound ignorant but I just stared using Caine 2.0 today and I am sort of teaching myself but my questions were ; How do you get your image? Mount drive and create an ISO or will just a mount work? If a mount will work, do you have to be online to use Autopsy? Instead of linking the folders can't you just rename the New Volume folder to get around the space problem or do you have to link the folders? A friend turned me onto Ubuntu and I am trying to learn. Thank you!

  • @polarbear35353

    To get an image of a partition or hard drive you can use the dcfldd command. You do not need to be online to use Autopsy. When you run the application it starts up a web server on the computer itself and you connect to it via your web browser. I several vids on my web site that are focused on using Backtrack, but you can substitute Ubuntu for many of the tasks as long as you have the software on it.

see all

All Comments (5)

Sign In or Sign Up now to post a comment!
  • I have a portable hard disk that's essentially unmountable (the Windows PC it was connected to crashed and I guess that destroyed the FAT structures on it). Will Autopsy allow me to recover the data on it?

  • @lecturesnippets Thank you very much!

  • Thanks so much!!

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more