Basic Features - Hashing and Image Details

Any Autopsy specific discussions, events, module releases, that don't fall into the other categories.

Moderator: carrier

Basic Features - Hashing and Image Details

Postby mfanton » Mon Apr 13, 2015 9:38 pm

Hi,
I just wanted to make sure that I am not overlooking anything. I don't see the ability to do the following:

1. Compute hash value of dd image or physical devices. Only E01 images are hashed.
2. Explicitly state the file system type contained within partition-only images and logical drives (NTFS, EXT4, etc). Only physical disk partitions are identified with their file system type.

These basic forensic features were always available in older versions of Autopsy as well as TSK. Why were they removed in Autopsy v3?

Thanks in advance!
Mike
mfanton
 
Posts: 1
Joined: Mon Apr 13, 2015 9:18 pm

Re: Basic Features - Hashing and Image Details

Postby carrier » Thu Jun 04, 2015 6:55 pm

Yes, those features have not been added to v3. v3 is a complete rewrite, so they were not removed as much as they were not added.

Re: file system types. We identify the type based on file system structure. We ignore the type in a partition table even if the type is specified.
carrier
 
Posts: 45
Joined: Thu May 15, 2014 3:31 pm


Return to Autopsy General

Who is online

Users browsing this forum: No registered users and 2 guests