Welcome back to the several recourse in building you're in for a sec lap. I'm your host and instructor Kevin Hernandez, Our last lesson win stall. Next suppose within our Windows Server 2016 operating system.
Next pose is a vulnerability assessment, all which will help us
keep the integrity and security off our network.
In today's lesson, we'll actually go over to more forensic applications,
unlike our previous insulation, this unknown operating system but applications you can run within Windows itself.
when searching for autopsy. Make sure you acts lookit
as part of the search. Otherwise you'll come over more biological like
autopsies, right? That one of the good things about Google, it said. It will also show you right here the right corner. People also search for right, and you can see that F decay. It's one of those options are actually gonna take a look into that tool swollen this lesson.
So let's go ahead first and go to Autopsy,
You have a little screen of how looks
it was clicked. Download now,
and let's download the 64 bit version.
And let's wait for it to finish
all it's doing that.
Let's go ahead and go back.
I look down. Look after Kay Imager.
If you're gonna see it's right here.
So so after Kate Imager.
27 teams to release date for this particular Russian.
Let's go ahead and downloaded A swell
so you can see after came in your dust, require you to sign up.
So let's go ahead and fill this up. I'm gonna possibility while I complete this, as you can see once you've finally completed, it says that it will provide you
15 minutes to download
after King Imager to the email impact in the form
and this year's give or take what you'll see. Frantic E. Now let's go ahead and click on that link was Click. You'll see that it will start downloading.
Now we have actually downloaded. Both of the tools were looking over in this lesson.
Let's start with all topsy.
pretty basic, right?
Let's give it a minute or two for it to complete insulation.
No additional prompts have been required from us. Now. These tools are slightly different than sift, um,
imager itself. It's more towards creating images,
and it's very efficient, and it kind of puts the right block when you're doing them right. It's a software level, but it's still pretty good,
not a dance install. That school hadn't also take care of decay imager. Install it as well.
Then we wouldn't have to go back and forward.
You see, it's starting to extract the data.
It's pretty much very similar insulation.
Let's give it a minute. You can see it actually completed.
Um, since we're here,
and let me treat this for a second. And here you have F decay. Image looks pretty simple.
and a team protective files. So the way this works is
if you, for example, ad evidence item right here you will, for example, copy of physical drive. You could add a logical drive. For example, image you already drawn are like, um,
virtual disc right. We have logical drives, a swell image, files and content of a folder.
So let's do content of a folder real quick. So Let's go ahead.
Click Next Les Brown's from the folder.
This case I'm gonna go to my desktop and Tyra Forensics
You can see now here in the left side.
the folder. Let me go ahead and turn on my mouth corner for this. Listen,
no, you can probably see Went miles. Let's expand,
and you can see that there's a test folder in it.
It was. You click on it, you can actually see the test file,
and here it's a content out the file.
It's very basic tool. And what you can actually capture RAM and other things right and click here kept the whole room.
They cook a autopsy.
It's loading right now,
and this is a little bit slower loading. Then after chaos, you can see.
But they do have a cool logo.
For some reason, it reminds me of John Wick. I don't know why, but it does,
and here it goes, fully loaded. So let's create a new case,
and actually this looks
like encase competitors
type approach. So far,
and let's put the face directory as
and this is gonna be a single user, so let's click next.
You can see you're gonna have more information. So let's do the date right type of non case number,
right? And then could you have more than one case per day? Well, at three numbers and ex, you know, Examiner Information.
55555 Like in the movies My email
and now it's creating our case.
That's taken care off. Let me actually shrink the screen so it could fit the recording window.
Now you can see you can actually do it. This image like previously
local dis right and unallocated space image file.
Let's click on this one so we can do a similar type of approach.
Let's search of 40 file
this case. I actually added the file itself. You can see you can break
into three gigabyte shrunk
This case. It's a very small flat, so we don't need to do that.
Sit. Next, you can see it's already pulled the file in the background. Um, like after Kate, you do have a lot of tools in here like hashes file type identification. All those different parameters
listen next, so we process the data,
and in the bottom right corner, you should see a processing progress bar. Sadly, I
didn't have enough time to shrink this by the time it was done.
So here you can see the sector size type of image
device I d. You can see the Valley is
all right. He received a text content
that was earlier. So
and the basic difference between these and after Kate image or F decay itself. It's more who guarding the capturing or creating images while this for examples, more of a full blown forensic tool.
It is really good. And if you're into for insects or like to discover more towards for insects, I will highly recommend it. It's very interesting field, especially if you're half that detective or investigation type of feeling in your career.
I highly recommend it.
This lesson will actually installed all topsy auto sign and after Kate imager,
which are free to use for personal usage.
These are great alternative if you want to do very light forensics or at least capture content without the requirements of having a fully deployed operating system as it was. What a previous option
in our next lesson will actually go over model for connecting and configuring our laps.
Hoped the season. Have a date date?