Downloading sample files for automated analysis
The sample evidence file we will be using will be the same terry-work-usb-2009-12-11.E01
file downloaded in the previous chapter, which was analyzed using the Autopsy forensic browser. It can again be downloaded directly from here: https://digitalcorpora.s3.amazonaws.com/corpora/scenarios/2009-m57-patents/usb/terry-work-usb-2009-12-11.E01.
I’d also like you to take this opportunity to download the other files for this example from the digitalcorpora.com website, which you can analyze on your own to become fully acquainted with Autopsy 4 as this is one of the main open source and free tools used by DFIR investigators and analysts:
- The
Charlie-work-usb
file: https://digitalcorpora.s3.amazonaws.com/corpora/scenarios/2009-m57-patents/usb/charlie-work-usb-2009-12-11.E01 - The
Jo-favorites-usb
file: https://digitalcorpora.s3.amazonaws.com/corpora/scenarios/2009-m57-patents/usb/jo-favorites-usb-2009-12-11.E01 - The
Jo-work...