Spotlight | Reviews | Current Issue | Academy | Newsletter | Subscribe | Shop |
Departments

Partner Links
Make your own website
WinWeb OnlineOffice
Comparing prices of hardware is worth it.
Price Comparison
What:
Where:
Country:
vacatures Netherlands njobs Linux vacatures
arbeit Deutschland njobs Linux arbeit
work United Kingdom njobs Linux jobs
Lavoro Italia njobs Linux lavoro
Emploi France njobs Linux emploi
trabajo Espana njobs Linux trabajo

user friendly

Admin Magazine

ADMIN Network & Security

Subscribe now and save!

 ADMIN - Explore the new world of system administration! ADMIN is a smart, technical magazine for IT pros on heterogeneous networks. Each issue delivers technical solutions to the real-world problems you face every day. Learn the latest techniques for better:

  • network security
  • system management
  • troubleshooting
  • performance tuning
  • virtualization
  • cloud computing

 on Windows, Linux, Solaris, and popular varieties of Unix.

http://www.admin-magazine.com/

  linux-magazine.com » Issues » 2008 » 93 » BackTrack and Sleuth Kit  

Print this page. Recommend
Share

Sorting by File Type

In the Autopsy image analysis screen, you'll find several options. My favorite option is the File Type screen, but before clicking on Sort Files by Type, plan to wait a while.

This feature will scan the entire image file; extract files; sort them into various categories such as images, documents, executables, crypto-related files, etc.; and give you the option of copying the files out so you can further examine them.

An example of the output for crypto files is shown in Listing 3.

Listing 3

Crypto File Output

01 /home/secret/.pgp/secring.pgp
02   PGP key security ring
03   Image: /evidence/ddriveimage.dd Inode: 672945
04   Saved to: crypto/ddriveimage.dd-672945
05
06 /home/secret/.pgp/pubring.pgp
07   PGP key public ring
08   Image: /evidence/ddriveimage.dd Inode: 672959
09   Saved to: crypto/ddriveimage.dd-672959.pgp

Keyword Search

Another benefit of Autopsy is the keyword search screen. Not only does the search handle regular expressions, with a link to a cheat sheet, it also offers a number of pre-configured searches such as credit card numbers, social security numbers, IP addresses, and dates. Search results are cached, so once you have done a search and waited for the results, you never have to wait again.

Conclusion

Sleuth Kit offers an incredibly powerful -- and free โ€“ set of utilities for electronic forensics, working not only on Linux but also on Windows and other forms of Unix. With the addition of the Autopsy web interface, the software is extremely easy to use, and getting results with it shouldn't take too long.

In my testing โ€“ using older testing machines with hard drives that have seen it all โ€“ I found information spanning several years, from old installations of Windows to documents I hadn't seen in ages. Sleuth Kit definitely deserves a place in any system administrator's or auditor's toolkit.

Read full article as PDF ยป 026-028_sleuthkit.pdf 1.28 MB


Comments


Print this page. Recommend
Share
Related Articles
November 2011: DVD Inlay Issue #132
Tracing Intruders Intro Examining the art of computer forensics
BackTrack Looking for security holes with BackTrack
Special Linux Magazine 3 for 1 Offer

Get 3 Issues + 3 DVDs for the price of a single issue!

Let Linux Magazine's hands-on, technical articles guide you in your daily Linux use. Check out bonus DVDs like Ubuntu, SUSE, or Fedora and save the download.

Only available for a limited time. Don't miss out!

more...