move case to core
intermediate changes
|
After Width: | Height: | Size: 65 KiB |
|
After Width: | Height: | Size: 55 KiB |
|
After Width: | Height: | Size: 58 KiB |
|
After Width: | Height: | Size: 143 KiB |
|
After Width: | Height: | Size: 48 KiB |
|
After Width: | Height: | Size: 57 KiB |
@@ -0,0 +1,30 @@
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
||||
<html>
|
||||
<head>
|
||||
<title>Disk Image Basics</title>
|
||||
<link rel="stylesheet" href="nbdocs:/org/netbeans/modules/usersguide/ide.css" type="text/css">
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
|
||||
</head>
|
||||
<body>
|
||||
<h2>About Disk Images</h2>
|
||||
<p>
|
||||
In Autopsy, an "image" refers to a byte-for-byte copy of a hard drive or other storage media. To analyze an image, you must use the <a href="nbdocs:/org/sleuthkit/autopsy/casemodule/docs/addImage.html">Add Image Wizard</a>to add it to a <a href="nbdocs:/org/sleuthkit/autopsy/casemodule/docs/casemodule-about.html">case</a>.
|
||||
</p>
|
||||
<p>Autopsy populates an embedded database for each image that it imports. This database is a SQLite database and it contains all of the file system metadata from the image. The database is stored in the case directory, but the image will stay in its original location. The image must remain accessible for the duration of the anlaysis because the database contains only basic file system information. The image is needed to retrieve file content.</p>
|
||||
|
||||
<h2>Supported Formats</h2>
|
||||
<p>
|
||||
Currently, Autopsy supports these image formats:
|
||||
<ul type="circle">
|
||||
<li>Raw Single (For example: *.img, *.dd, etc)</li>
|
||||
<li>Raw Split (For example: *.001, *.002, *.aa, *.ab, etc)</li>
|
||||
<li>EnCase (For example: *.e01, *e02, etc)</li>
|
||||
</ul>
|
||||
|
||||
<h2>Removing an Image</h2>
|
||||
<p>
|
||||
You cannot currently remove an image from a case.
|
||||
</p>
|
||||
|
||||
</body>
|
||||
</html>
|
||||
|
After Width: | Height: | Size: 1.6 KiB |
@@ -0,0 +1,30 @@
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
||||
<html>
|
||||
<head>
|
||||
<title>Adding Image Wizard</title>
|
||||
<link rel="stylesheet" href="nbdocs:/org/netbeans/modules/usersguide/ide.css" type="text/css">
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
|
||||
</head>
|
||||
<body>
|
||||
<h2>Adding An Image</h2>
|
||||
<p>
|
||||
There are two ways to add an image to the currently opened case:
|
||||
<ul type="circle">
|
||||
<li>Go to "File" and select "Add Image..." </li>
|
||||
<li>Select the <img src="addImage-icon.png" alt="Add Image Icon" /> icon on the toolbar</li>
|
||||
</ul>
|
||||
|
||||
<p>
|
||||
This will bring up the Add Image wizard. It will guide you through the process. Here are some notes on what is going on during the process:</p>
|
||||
<ul>
|
||||
<li>The first panel will ask for the location and type of the disk image to add. You will also need to specify the timezone that the disk image came from so that the dates and times can be properly displayed and converted. <br><br>
|
||||
<img src="AddImageWizard1_Help.png" alt="Add Image Wizard Panel 1 Help" /> </li>
|
||||
<li>The second panel is when Autopsy is analyzing the disk image and populating the database with basic information. This can take a few minutes for large images. <br>
|
||||
<img src="AddImageWizard2_Help.png" alt="Add Image Wizard Panel 2 Help" /> </li>
|
||||
<li>The third panel allows you to choose which ingest modules to run on the image. Refer to the <a href="nbdocs:/org/sleuthkit/autopsy/ingest/docs/ingest-about.html">Image Ingest</a> part of the help guide for more details. </li>
|
||||
<img src="AddImageWizard3_Help.png" alt="Add Image Wizard Panel 3 Help" /> </li>
|
||||
<li>Once you select the ingest modules that you want to use, they will run in the background. You can choose to add another image or exit the Add Image wizard. </li>
|
||||
</ul>
|
||||
<p>Note that Autopsy will store the path to the image in its configuration file. If the image moves, then Autopsy will give an error because it can't find the image file.
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,48 @@
|
||||
<!--
|
||||
To change this template, choose Tools | Templates
|
||||
and open the template in the editor.
|
||||
-->
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
||||
<html>
|
||||
<head>
|
||||
<title>Case Properties Window</title>
|
||||
<link rel="stylesheet" href="nbdocs:/org/netbeans/modules/usersguide/ide.css" type="text/css">
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
|
||||
</head>
|
||||
<body>
|
||||
<h2>Case Properties Window</h2>
|
||||
<p>
|
||||
Case Properties Window is the window where you can check some information about the currently opened case (case name, case creation date, case directory, and images in this case.
|
||||
<br><br>
|
||||
In this window, you can also do the following things:
|
||||
<ul>
|
||||
<li>Change/update the case name</li>
|
||||
<li>Delete the current case</li>
|
||||
<li>Remove image(s) from the current case</li>
|
||||
</ul>
|
||||
|
||||
</p>
|
||||
<h2>How to Open Case Properties Window</h2>
|
||||
<p>
|
||||
To open the "Case Properties" window, go to "File" and then select "Case Properties..." <br><br>
|
||||
</p>
|
||||
|
||||
<h2>Example</h2>
|
||||
<p>
|
||||
Here's an example of the "Case Properties" window: <br>
|
||||
<img src="CasePropertiesHelp.png" alt="Case Properties Help" />
|
||||
</p>
|
||||
</body>
|
||||
</html>
|
||||
<!--
|
||||
Tip: to create a link which will open in an external web browser, try:
|
||||
<object classid="java:org.netbeans.modules.javahelp.BrowserDisplayer">
|
||||
<param name="content" value="http://www.netbeans.org/">
|
||||
<param name="text" value="<html><u>http://www.netbeans.org/</u></html>">
|
||||
<param name="textFontSize" value="medium">
|
||||
<param name="textColor" value="blue">
|
||||
</object>
|
||||
To create a link to a help set from another module, you need to know the code name base and path, e.g.:
|
||||
<a href="nbdocs://org.netbeans.modules.usersguide/org/netbeans/modules/usersguide/configure/configure_options.html">Using the Options Window</a>
|
||||
(This link will behave sanely if that module is disabled or missing.)
|
||||
-->
|
||||
@@ -0,0 +1,26 @@
|
||||
<html>
|
||||
<head>
|
||||
<title>About Cases</title>
|
||||
<link rel="stylesheet" href="nbdocs:/org/netbeans/modules/usersguide/ide.css" type="text/css">
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
|
||||
</head>
|
||||
<body>
|
||||
<h2>About Cases</h2>
|
||||
<p>
|
||||
In Autopsy, a "case" is a container concept for a set of <a href="nbdocs:/org/sleuthkit/autopsy/casemodule/docs/aboutImage.html">images</a>. The set of images could be from multiple drives in a single computer or from multiple computers. When you make a case, it will create a directory to hold all of the information. The directory will contain a configuration file, some databases, and some other information. The configuration file as a .aut extension.
|
||||
</p>
|
||||
|
||||
<p>If you want to view case details or edit some case information, use the <a href="nbdocs:/org/sleuthkit/autopsy/casemodule/docs/caseProperties.html">Case Properties</a> window.
|
||||
|
||||
<h2>Creating a Case</h2>
|
||||
<p>
|
||||
Refer to the <a href="nbdocs:/org/sleuthkit/autopsy/casemodule/docs/createNewCase.html">Creating a Case</a> page for more details.
|
||||
</p>
|
||||
|
||||
<h2>Opening a Case</h2>
|
||||
<p>
|
||||
To open a case, choose "Open Case" from the File menu or use the "Ctrl + O" keyboard short cut.
|
||||
Navigate to the case directory and select the ".aut" file.
|
||||
</p>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,31 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!--
|
||||
To change this template, choose Tools | Templates
|
||||
and open the template in the editor.
|
||||
-->
|
||||
<!DOCTYPE helpset PUBLIC "-//Sun Microsystems Inc.//DTD JavaHelp HelpSet Version 2.0//EN" "http://java.sun.com/products/javahelp/helpset_2_0.dtd">
|
||||
<helpset version="2.0">
|
||||
<title>Case Help</title>
|
||||
<maps>
|
||||
<homeID>org.sleuthkit.autopsy.casemodule.about</homeID>
|
||||
<mapref location="casemodule-map.xml"/>
|
||||
</maps>
|
||||
<view mergetype="javax.help.AppendMerge">
|
||||
<name>TOC</name>
|
||||
<label>Table of Contents</label>
|
||||
<type>javax.help.TOCView</type>
|
||||
<data>casemodule-toc.xml</data>
|
||||
</view>
|
||||
<view mergetype="javax.help.AppendMerge">
|
||||
<name>Index</name>
|
||||
<label>Index</label>
|
||||
<type>javax.help.IndexView</type>
|
||||
<data>casemodule-idx.xml</data>
|
||||
</view>
|
||||
<view>
|
||||
<name>Search</name>
|
||||
<label>Search</label>
|
||||
<type>javax.help.SearchView</type>
|
||||
<data engine="com.sun.java.help.search.DefaultSearchEngine">JavaHelpSearch</data>
|
||||
</view>
|
||||
</helpset>
|
||||
@@ -0,0 +1,15 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!--
|
||||
To change this template, choose Tools | Templates
|
||||
and open the template in the editor.
|
||||
-->
|
||||
<!DOCTYPE index PUBLIC "-//Sun Microsystems Inc.//DTD JavaHelp Index Version 2.0//EN" "http://java.sun.com/products/javahelp/index_2_0.dtd">
|
||||
<index version="2.0">
|
||||
<indexitem text="Overview" target="org.sleuthkit.autopsy.casemodule.overview"/>
|
||||
<indexitem text="About Cases" target="org.sleuthkit.autopsy.casemodule.about"/>
|
||||
<indexitem text="Creating a Case" target="org.sleuthkit.autopsy.casemodule.how-to-create-case"/>
|
||||
<indexitem text="About Images" target="org.sleuthkit.autopsy.casemodule.image-about"/>
|
||||
<indexitem text="Adding an Image" target="org.sleuthkit.autopsy.casemodule.add-image"/>
|
||||
<indexitem text="Case Properties Window" target="org.sleuthkit.autopsy.casemodule.caseproperties"/>
|
||||
<indexitem text="Hash Database Management" target="org.sleuthkit.autopsy.casemodule.hashdbmgmt"/>
|
||||
</index>
|
||||
@@ -0,0 +1,15 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!--
|
||||
To change this template, choose Tools | Templates
|
||||
and open the template in the editor.
|
||||
-->
|
||||
<!DOCTYPE map PUBLIC "-//Sun Microsystems Inc.//DTD JavaHelp Map Version 2.0//EN" "http://java.sun.com/products/javahelp/map_2_0.dtd">
|
||||
<map version="2.0">
|
||||
<mapID target="org.sleuthkit.autopsy.casemodule.overview" url="overview.html"/>
|
||||
<mapID target="org.sleuthkit.autopsy.casemodule.about" url="casemodule-about.html"/>
|
||||
<mapID target="org.sleuthkit.autopsy.casemodule.how-to-create-case" url="createNewCase.html"/>
|
||||
<mapID target="org.sleuthkit.autopsy.casemodule.image-about" url="aboutImage.html"/>
|
||||
<mapID target="org.sleuthkit.autopsy.casemodule.add-image" url="addImage.html"/>
|
||||
<mapID target="org.sleuthkit.autopsy.casemodule.caseproperties" url="caseProperties.html"/>
|
||||
<mapID target="org.sleuthkit.autopsy.casemodule.hashdbmgmt" url="hashDbMgmt.html"/>
|
||||
</map>
|
||||
@@ -0,0 +1,21 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!--
|
||||
To change this template, choose Tools | Templates
|
||||
and open the template in the editor.
|
||||
-->
|
||||
<!DOCTYPE toc PUBLIC "-//Sun Microsystems Inc.//DTD JavaHelp TOC Version 2.0//EN" "http://java.sun.com/products/javahelp/toc_2_0.dtd">
|
||||
<toc version="2.0">
|
||||
<tocitem text="Overview" target="org.sleuthkit.autopsy.casemodule.overview"/>
|
||||
<tocitem text="Case Management">
|
||||
<tocitem text="Case">
|
||||
<tocitem text="About Cases" target="org.sleuthkit.autopsy.casemodule.about"/>
|
||||
<tocitem text="Creating a Case" target="org.sleuthkit.autopsy.casemodule.how-to-create-case"/>
|
||||
</tocitem>
|
||||
<tocitem text="Image">
|
||||
<tocitem text="About Images" target="org.sleuthkit.autopsy.casemodule.image-about"/>
|
||||
<tocitem text="Adding an Image" target="org.sleuthkit.autopsy.casemodule.add-image"/>
|
||||
</tocitem>
|
||||
<tocitem text="Case Properties Window" target="org.sleuthkit.autopsy.casemodule.caseproperties"/>
|
||||
<tocitem text="Hash Database Management Window" target="org.sleuthkit.autopsy.casemodule.hashdbmgmt"/>
|
||||
</tocitem>
|
||||
</toc>
|
||||
@@ -0,0 +1,43 @@
|
||||
<!--
|
||||
To change this template, choose Tools | Templates
|
||||
and open the template in the editor.
|
||||
-->
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
||||
<html>
|
||||
<head>
|
||||
<title>Creating A Case</title>
|
||||
<link rel="stylesheet" href="nbdocs:/org/netbeans/modules/usersguide/ide.css" type="text/css">
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
|
||||
</head>
|
||||
<body>
|
||||
<h2>Creating a Case</h2>
|
||||
<p>
|
||||
There are several ways to create a new case:
|
||||
<ul type="circle">
|
||||
<li>Go to "File" and select "New Case..." </li>
|
||||
<li>Select the <img src="new-icon.png" alt="New Case Icon" /> icon on the toolbar</li>
|
||||
<li>Press "Ctrl + N" on the keyboard</li>
|
||||
</ul>
|
||||
</p>
|
||||
|
||||
<p>The "New Case" wizard dialog will open and you will need to enter the case name and base directory. Each case will have its own directory and the path of the directory is created by combining the "base directory" with the "case name". If the directory already exists, you will need to either delete the existing directory or choose a different combination of names.
|
||||
</p>
|
||||
<h2>Example:</h2>
|
||||
<p>
|
||||
Here's an example of the "New Case" wizard dialog: <br>
|
||||
<img src="NewCaseWizardHelp.png" alt="New Case Wizard Help" />
|
||||
</p>
|
||||
</body>
|
||||
</html>
|
||||
<!--
|
||||
Tip: to create a link which will open in an external web browser, try:
|
||||
<object classid="java:org.netbeans.modules.javahelp.BrowserDisplayer">
|
||||
<param name="content" value="http://www.netbeans.org/">
|
||||
<param name="text" value="<html><u>http://www.netbeans.org/</u></html>">
|
||||
<param name="textFontSize" value="medium">
|
||||
<param name="textColor" value="blue">
|
||||
</object>
|
||||
To create a link to a help set from another module, you need to know the code name base and path, e.g.:
|
||||
<a href="nbdocs://org.netbeans.modules.usersguide/org/netbeans/modules/usersguide/configure/configure_options.html">Using the Options Window</a>
|
||||
(This link will behave sanely if that module is disabled or missing.)
|
||||
-->
|
||||
@@ -0,0 +1,48 @@
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
||||
<html>
|
||||
<head>
|
||||
<title>Hash Database Management</title>
|
||||
<link rel="stylesheet" href="nbdocs:/org/netbeans/modules/usersguide/ide.css" type="text/css">
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
|
||||
</head>
|
||||
<body>
|
||||
<h2>Hash Database Management Window</h2>
|
||||
<p>
|
||||
The Hash Database Management window is where you can set and update your hash database information. Hash databases are used to identify files that are 'known'.
|
||||
<ul>
|
||||
<li>Known good files are those that can be safely ignored. This set of files frequently includes standard OS and application files. </li>
|
||||
<li>Known bad (also called notable) files are those that should raise awareness. This set will vary depending on the type of investigation, but common examples include contraband images and malware.</li>
|
||||
</ul>
|
||||
</p>
|
||||
|
||||
<h2>Notable / Known Bad Hashsets</h2>
|
||||
<p>Autopsy allows for multiple known bad hash databases to be set. Autopsy supports three formats:
|
||||
<ul>
|
||||
<li>EnCase: An EnCase hashset file. </li>
|
||||
<li>MD5sum: Output from running the md5, md5sum, or md5deep program on a set of files.</li>
|
||||
<li>NSRL: The format of the NSRL database </li>
|
||||
</ul>
|
||||
|
||||
<h2>NIST NSRL</h2>
|
||||
<p>Autopsy can use the <a href="http://www.nsrl.nist.gov">NIST NSRL</a> to detect 'known files'. Note that the NSRL contains hashes of 'known files' that may be good or bad depending on your perspective and investigation type. For example, the existence of a piece of financial software
|
||||
may be interesting to your investigation and that software could be in the NSRL. Therefore, Autopsy treats files that are found in the NSRL as simply 'known' and does not specify good or bad. Ingest modules have the option of ignoring files that were found in the NSRL.</p>
|
||||
|
||||
<p>To use the NSRL, you must concatenate all of the NSRLFile.txt files together. You can use 'cat' on a Unix system or from within Cygwin to do this.</p>
|
||||
|
||||
<h2>Adding Hashsets</h2>
|
||||
<p>Autopsy needs an index of the hashset. It can make one if you import only the hashset. When you select the database from within this window, it will tell you if the index needs to be created. Autopsy
|
||||
uses the hash database management system from The Sleuth Kit. You can manually create an index using the 'hfind' command line tool.</p>
|
||||
|
||||
<p>You can also specify only the index file and not use the full hashset. This can save space. To do this, specify the .idx file from the Hash Database Management window. </p>
|
||||
|
||||
<h2>Using Hashsets</h2>
|
||||
<p>There is an <a href="nbdocs:/org/sleuthkit/autopsy/ingest/docs/ingest-about.html">ingest module</a> that will hash the files and look them up in the hashsets. It will flag files that were in the notable hashset and those results will be shown in the Results tree of the <a href="nbdocs:/org/sleuthkit/autopsy/directorytree/docs/directorytree-about.html">Data Explorer</a>.
|
||||
|
||||
<p>Other ingest modules are able to use the known status of a file to decide if they should ignore the file or process it.</a>
|
||||
|
||||
<p>You can also see the results in the <a href="nbdocs:/org/sleuthkit/autopsy/filesearch/docs/open-filesearch.html">File Search</a> window. There is an option to choose the 'known status'. From here, you can do a search to see all 'known bad' files.
|
||||
From here, you can also choose to ignore all 'known' files that were found in the NSRL. You can also see the status of the file in a column when the file is listed. </p>
|
||||
|
||||
<img src="hashdb.PNG" alt="Hash Database Configuration" />
|
||||
</body>
|
||||
</html>
|
||||
|
After Width: | Height: | Size: 29 KiB |
|
After Width: | Height: | Size: 1.3 KiB |
|
After Width: | Height: | Size: 1.0 KiB |
@@ -0,0 +1,45 @@
|
||||
<!--
|
||||
To change this template, choose Tools | Templates
|
||||
and open the template in the editor.
|
||||
-->
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
||||
<html>
|
||||
<head>
|
||||
<title>Overview</title>
|
||||
<link rel="stylesheet" href="nbdocs:/org/netbeans/modules/usersguide/ide.css" type="text/css">
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
|
||||
</head>
|
||||
<body>
|
||||
<h2>Overview</h2>
|
||||
<p>
|
||||
Autopsy allows you to conduct a digital forensic investigation. It is a graphical interface to The Sleuth Kit and other open source tools. This page outlines the basic concepts of the program. The remainder of the help guide is organized around these concepts.
|
||||
</p>
|
||||
|
||||
<p>All data is organized around the concept of a <a href="nbdocs:/org/sleuthkit/autopsy/casemodule/docs/casemodule-about.html">case</a>. A case can have one or more disk <a href="nbdocs:/org/sleuthkit/autopsy/casemodule/docs/aboutImage.html">images</a> loaded into it.</p>
|
||||
|
||||
<p>The main window has three major areas:
|
||||
<ul>
|
||||
<li><a href="nbdocs:/org/sleuthkit/autopsy/corecomponents/docs/dataexplorer-about.html">Data Explorer Tree</a>: This area is where you go find major analysis functionality. It allows you to start finding the relevant files quickly.</li>
|
||||
<li><a href="nbdocs:/org/sleuthkit/autopsy/corecomponents/docs/dataresult-about.html">Result Viewers</a>: This area is where the files and directories that were found from the explorer window can be viewed. There are different formatting options for the files.</li>
|
||||
<li><a href="nbdocs:/org/sleuthkit/autopsy/corecomponents/docs/datacontent-about.html">Content Viewers</a>: This area is where file content can be viewed after they are selected from the Result Viewer area.</li>
|
||||
</ul>
|
||||
</p>
|
||||
<p>The main take away from this should be that analysis techniques and result categories can be found on the left-hand side, the results from choosing something on the left are always listed in the upper right, and the file contents are displayed in the lower left.
|
||||
|
||||
<p>
|
||||
<img src="Autopsy_overview.png" alt="Autopsy Overview Window" />
|
||||
</p>
|
||||
</body>
|
||||
</html>
|
||||
<!--
|
||||
Tip: to create a link which will open in an external web browser, try:
|
||||
<object classid="java:org.netbeans.modules.javahelp.BrowserDisplayer">
|
||||
<param name="content" value="http://www.netbeans.org/">
|
||||
<param name="text" value="<html><u>http://www.netbeans.org/</u></html>">
|
||||
<param name="textFontSize" value="medium">
|
||||
<param name="textColor" value="blue">
|
||||
</object>
|
||||
To create a link to a help set from another module, you need to know the code name base and path, e.g.:
|
||||
<a href="nbdocs://org.netbeans.modules.usersguide/org/netbeans/modules/usersguide/configure/configure_options.html">Using the Options Window</a>
|
||||
(This link will behave sanely if that module is disabled or missing.)
|
||||
-->
|
||||