Time
5 hours 56 minutes
Difficulty
Intermediate
CEU/CPE
6

Video Transcription

00:01
Hey, everybody, welcome back to the course. So in the last video, we downloaded and extracted R us be folder and file that we're gonna be using for the rest of the lab
00:10
in this video, we're gonna go ahead and continue on with the lab and analyze the information in that folder.
00:16
Let's go back to our lab document here. So on the desktop, what we're gonna do is we're gonna double click on the Pro Discover. Ah, shortcut, icon.
00:23
And then we're gonna get a little pop up box. As soon as it opens up regarding the launch dialogue, We're just going to say, cancel to that pop up box. So let's go ahead and do that. No.
00:31
So it's gonna be this pro discover basic 64 icon here. So it looks like a guy with a little magnifying glass and a hat.
00:37
Just go ahead and double click on that
00:39
is gonna take a moment of soda launch for you, and then you're gonna see this launch dialogue box here. Just go ahead and click on the cancel button at the bottom.
00:48
All right, let's go back to our lab document. So now what? We're gonna do? We're gonna select a new project button. That's after how the top left of this window.
00:56
So it's gonna be this little piece of blank, paper looking icon, so you'll see if I hover my mouse over it. It says new project. So then click on that.
01:03
It's gonna give us a new project Popular box here.
01:07
So here is Step for the papa box is opened. And now we're just gonna in step five and step six under the project number. And also the project file name in those boxes were gonna type the same things we're gonna type C 08 i n c h p Let's go and do that now.
01:23
So C 08 i n c h p
01:30
All right, so C 08 i n c h p.
01:34
We'll do the same thing for this one. Here is Well,
01:40
okay, let's go back to our lab documents. So we've typed those in down steps 55 and six. So in step seven, word is gonna select, okay?
01:48
And then we're gonna be back at the tool where we'll choose some other options here.
01:52
All right? We're just gonna say okay to that.
01:53
So now we're gonna go to the top. Were to select action from the very top menu there were to select add and then were to select image file. And then what we'll see is a pop up box will open for us. So let's go ahead and do that now.
02:07
So we're gonna select action
02:09
were to select add and then we're in a select image file.
02:13
Okay, You'll see we have a pop up box here.
02:17
So now what we're gonna do, we're gonna navigate to this location. So if you notice it's gonna be where we saved that USB file, it. So the sea work data data files Chapter eight and then all the way to our USB folder.
02:31
So let's go ahead and do that now.
02:34
So we're to scroll down. We're gonna select our see Dr Weir to select work by double clicking on it. Same with data files will double clicked open that
02:42
we're gonna double click on Chapter eight and then double click on our USB folder.
02:46
So in there, you see several files. So let's go back to our lab document.
02:53
Okay, so we see a step 11 here. We want to select the file of this labeled as Joe Dash Favorites Desk USB Dash two zero 0 9-12 dash 11 dot e 01 So let's go ahead. Look for that one.
03:08
All right, so we're looking for a Joe Dash favorites, and you'll see there's only one that's labeled like that. So, Joe Dash Favorites Dash us B Dash 2009-12 dash 11 dot easier one. Okay, we're gonna select that and then just say open.
03:24
All right, so now we're a step 12 over lab documents.
03:27
Now we're going to go back to the top of our screen there in step 13 in select action and then select search.
03:35
So let's go ahead and do that. Now we're gonna select action at the top,
03:38
and then we're gonna select this search option just about 1/4 of the way down here.
03:43
It's gonna give us his pop up box here, so let's go back to our lab document.
03:47
So in step 14 we want to make sure we select a cluster tab.
03:52
So the cluster search tab
03:54
and then we're gonna mark the case sensitive checkbox. So let's go ahead and do that.
03:59
So here We want to make sure we click on the cluster search tab.
04:03
And then down here the left. We want to select the case sensitive checkbox. So just go ahead and click in there and it'll check the check box for us.
04:11
Let's go back to our lab document.
04:14
All right, So now, in the search for patterns checkbox, we want a type F i f. All in capitals. So let's go and do that. So the search for patterns we're gonna type f i f all in capital letters. All right,
04:28
let's move on to the lab document again.
04:30
So here in stepped 17 under the selected disc images, you want to search in box, we're gonna select this option, so it's gonna be this one that ends in Joe Dash. Favorites Dash USB 2009 etcetera, etcetera. Easier one.
04:45
So you'll see it's gonna be this top one here. Now, we don't want to select this one. You'll see. It ends in the C drive. We just want to like that top one there,
04:53
Okay? And then our next step here is just click on the okay button, and what that's gonna do is the search is going to start for us and it's gonna take a minute or two. Probably about 30 seconds is probably what it will take. We'll take a look here, and so just go ahead and say, OK, here, you'll see at the bottom. It starts initiating that search for us. You'll see the little taskbar going there.
05:13
No one is gonna let that run.
05:15
And you see, it didn't take too long to pull up the results for us.
05:18
All right, So the first thing we're gonna do here in step 20 once we're done with the search and again, it might take 30 minutes or maybe even a couple minutes, depending on your system,
05:28
we're gonna click on the very first search results,
05:30
and then what we're gonna see it's weird to see the hex of that particular file or item in the bottom window.
05:38
All right, so we're just gonna select this top one here. Let's go ahead and click on that. You'll see all the hex here. Now what we want to do is we want to scroll down to look for the Fife s. Remember, if we search for F i f. So we want to scroll down a look where we see that highlighted. So here is step number 22. We're gonna use a scroll bar on the right side
05:54
to scrawled on a two. We see the f f and see where it's highlighted in blue.
05:59
All right, so let's go ahead and do that now.
06:01
So let's use the scroll bar on the right side here. I'm gonna scroll down a little bit here,
06:05
and we're just looking for F I f in blue. So you'll see right there. We see the blue highlighting and we see here that we have the f i f.
06:15
All right, so let's go back to our lab document.
06:18
So now what we want to do in step 23 on the left side of the page, we're gonna expand the images. Options will cook the little plus sign
06:26
under the cluster of you. We're gonna do that again by clicking the plus sign to the left of it. So let's go ahead and do that now.
06:33
So on the left side, here, under cluster of you,
06:38
we're gonna expand the images. So this little plus sign right here, go ahead and click on that.
06:43
Let's go back to our lab document here. So now we're gonna expand the sea work data files chapter eight by also cooking the small plus sign to the left of it.
06:53
Let's go ahead and do that. So this one right here, just click the little plus sign to the left, and then you'll see we have the c drive. So grand. Just click on the sea.
07:01
You'll see all sorts of pretty colors. Airs, go back to our lab document.
07:05
All right, so now what we're gonna do is we'll see a text box, it's gonna be on the right side, and then we're gonna type in a C four. So all capital letters. So a capital A Capital C, and then the number four here in step 26 then we're gonna select the go option.
07:20
So let's go ahead and do that now. So we're gonna want to scroll over to the right side here. This little text box right here,
07:27
we're just gonna type in a C four
07:30
and then just click on Go.
07:31
What? That's gonna do a search for the A C four box in all of this. You'll see. We've got the number four right here on. And we've got the A c there as well.
07:41
Let's go back to our lab document.
07:44
So we see that the instep 28 we see that the A C four is highlighted in red for us. So now we're going to right click on that red square and select find file.
07:55
So let's go ahead and do that.
07:56
So this right click on this little square right here,
08:00
I just select. We find file option.
08:07
All right, take a moment or so you'll see a pop up box opens up for us.
08:11
So we should see that a C 4 27 56 should be selected. Do we see that? Yes, we do. So it's already selected for us, okay?
08:20
And we also see that the indicated file path shows the name D S C 00018 So if you notice here on the top of right D s, C 00018
08:31
Okay,
08:33
Go back to our lab document here.
08:35
So in step 32 were to click the show file button,
08:39
So let's go ahead and do that. Now you notice that the view in the background there changed for us,
08:45
right? So it's showing us under the content to you now. So let's look back under the lab document. So instead, 33. It's just a notification that hey, the view has changed to the content view folder.
08:54
All right, Now we're gonna click close on the Papa box there,
08:58
and then we see that we have all these files to start in D s C 000 you know, 1213140000800009 et cetera, et cetera.
09:11
All right, so Step 35. Yes, we do see that we have files starting in all that, we're gonna instead, 36 we're gonna look for the file that's labeled as D S. C 00018 and then we're gonna right Click on it and select copy.
09:26
All right, so this one right here, this d s c 00018 Go and click on that right click and say copy file.
09:35
Okay, Little papa box. Come up for us. So we get to save Ask Papa box. We're gonna change this
09:41
name to recovery one, and then we'll click the save button.
09:46
So let's go ahead. Do that. Now we're just gonna type in recovery one.
09:50
My keyboard cooperates. There we go.
09:52
All right, so Recovery one and then just click on the save button there.
09:56
Okay, let's go back to our lab document.
10:00
So we've already saved it here with Click the Save Button and renamed it.
10:03
So next we're gonna go ahead and just close the pro discover tool for this portion of the lab, and we're gonna select exit at the top menu. It's gonna ask us, do you want to say this? We're just gonna say yes when were prompted on and then we'll click the save button and then it should close out the tool for us. And then in the next video, we'll go ahead and continue on with lab.
10:22
So let's go ahead and do that. Now.
10:22
Were to come to the very top here, select file that exit.
10:26
It's gonna ask this Do you want to save the project before quitting? Will say yes to that.
10:31
It's gonna give us the default path and everything. Just click on the save button here
10:35
and then infected moment. So but you'll see that pro discover guys goes ahead and closes for us.
10:41
All right, So in this lab, we just went ahead through analysing that USB folder Excuse me? File that we had to download it and extracted in the next video. We'll go ahead and continue on with our analysis of that file.

Up Next

Computer Hacking and Forensics

Love the idea of digital forensics investigation? That is what computer forensics is all about. You will learn how to; determine potential online criminal activity at its inception, legally gather evidence, search and investigate wireless attacks.

Instructed By

Instructor Profile Image
Ken Underhill
Master Instructor at Cybrary
Master Instructor