Time
5 minutes
Difficulty
Intermediate

Video Transcription

00:05
hello and welcome to another episode of breaking stuff with Robert. Today we're going to be talking about the bulk extractor tool. So this is a forensics tool that allows you to extract information such as email addresses, credit card numbers, your ills, other types of information
00:23
through forensic images or system images.
00:27
So we're going to be doing a high level overview of that tool today through our demo and the target. Audiences for this particular tool are going to be like, if your network administrator trying to extract may be sensitive information from a system image that you have really here focused on forensic investigation,
00:44
cyber crime investigation, evidence collection, things of that nature.
00:48
So tool is going to typically be focused on my private investigators, law enforcement things of that nature.
00:56
Now you don't have to have any of the prerequisites is listed here, but it would be good to have a fundamental knowledge of forensic procedures and tools and how those things work and a fundamental knowledge of the Cali Lennox command line and how to utilize that. So, with those things in mind, let's go ahead and jump into our demo.
01:17
All right, everybody so today we're looking at bulk extractor, which is a tool again for forensics, and it distracts things from images such as email addresses, credit card numbers, Urals on bit puts it into, or it takes it from a digital evidence file. So in this case,
01:36
I'm gonna a menace playable,
01:38
Um
01:40
v m D K. Here. And I actually ran it through the bulk extractor previously. It's pretty simple. Now. I'm not a forensics. Ah, analyst by trade. I have some experience in forensics, and information is faras like incident response and chain of custody things of that nature. But I don't date today
01:59
delve into providing forensics, but
02:01
this is definitely advantageous. If you're trying to get information out of an image, you don't wanna have to load the system. Search through everything you know. This could be useful for network administrators, system administrators, technical support, definitely big for law enforcement, cyber crimes investigators, things of that nature.
02:21
So essentially what you can do is you can do both and then extractor here and hit enter, and it gives you a number off switches that you can use and things of that nature. Now, what I did earlier was just a simple
02:36
Dachau for the output. And this creates a directory. I did bulk out buk out, but I'm not gonna recreate that. I'm gonna do bulk in so that it doesn't override anything.
02:46
And then I went to the location of the V M d. K. So in this case, we're doing that menace playable v M v k on. Then it'll run. So I'll just hit Enter here. And it outputs
02:59
into that directory that we told it to output into. Now this is going to run. It took a few minutes last time. It was relatively quick. This is a smaller file, but for the sake of time, I'm going to stop this. It will give you an output.
03:14
And as I said, um, in this case, it created a broke out directory, says you can see here with that bulk out, which was the previous run. This is broke in as I was demonstrating. And so when I go into bulk out,
03:30
as you can see, it pulled all of this information from that image without me ever having to mount or boot the image.
03:39
So if I do a nano, uh, e mail, let's see t x t.
03:46
Then it shows me all of the e mail addresses that it was able to pull
03:53
from the system. So this is just what natively lives on medicine. Plausible.
04:00
So this could be very, very useful. If you're trying to collect some information off of an image, maybe you're looking for email. Address is evidence of like going to certain domains. So, you know, in this case, we can do a domain, not t X t
04:15
actually shows some domains that we're in here,
04:21
which,
04:23
you know, your imagination is kind of the limit to this, but there's plenty of that. It does right out of the box. And there's additional, uh,
04:30
like keyword searches that you can do with respect to the tool so you can use it to extract again sensitive information. It looks for things like credit card numbers, telephone numbers. You are elves visited and stored passwords from that image,
04:45
another information of interest that you can define by word or rejects or some kind of custom parameter that you want to pull from that.
04:51
So that's pretty much it in a nutshell, you know, get you an image from maybe, uh, Callie, Or are you know, some image that maybe you've backed up your system or server or something of that nature, and you just want to do some testing with something that's not in production? Did you see what kind of data can pull and maybe promotes and you can use cases from there? So
05:12
with that in mind, let's jump back over to our slides.
05:16
Well, I hope you enjoy that demo of the bulk extractor tool as we discussed. It's a forensic tool allows you to collect email addresses, credit card numbers, your l's other types of information from both digital evidence files as well. A system images
05:31
eso again. I hope you enjoyed the demo. There is definitely a use case, even if you're not in law. Enforcements are very fluent in forensic techniques. On with those things in mind, I want to thank you for your time today, and I look forward to seeing you again soon.

How to Use Bulk Extractor (BSWR)

This tutorial covers how Bulk Extractor can be used as a forensic tool to extract features such as email addresses, credit card numbers, URLs, and other types of information from digital evidence files. It is useful in analyzing image files, password cracking, processing compressed data and incomplete or partially corrupted data.

Instructed By

Instructor Profile Image
Robert Smith
Director of Security Services at Corsica
Instructor