Professional Documents
Culture Documents
523 TYCS Chinmay CF Input
523 TYCS Chinmay CF Input
Q1 Creating a Forensic Image using FTK Imager/Encase Imager : Creating Forensic ,ImageCheck
,Integrity of DataAnalyze Forensic Image
1. Click File, and then Create Disk Image, or click the button on the tool bar.
2. Select the source evidence type you want to make an image of and click Next.
Chinmay Gujar CF TYCS/523
4. In the Image Destination Folder field, type the location path where you want to save the
After adding the image destination path click on finish and start the image processing.
Chinmay Gujar CF TYCS/523
6. After the images are successfully created, click Image Summary to view detailed file
Click on Add Evidence Item to add evidence from disk, image file or folder.
Q2) Recovering and Inspecting deleted files: Check for Deleted Files,Recover the Deleted
Files, Analysing and Inspecting the recovered files
Step 3: Enter the New case Information and click on Next Button
Chinmay Gujar CF TYCS/523
Step 5: Now Select Source Type as Local disk and Select Local disk form drop down list and
click on
Next.
Chinmay Gujar CF TYCS/523
Step 8: Now Autopsy window will appear and it will analyzing the disk that we have selected
Chinmay Gujar CF TYCS/523
Step 9: All files will appear in table tab select any file to see the data
Step 10:Expand the tree from left side panel to view the document files
Step 11: To recover the file, go to view node=>gt; Deleted Files node , here select any file
and right click
Chinmay Gujar CF TYCS/523
Step 12: By default Export folder is choose to save the recovered file
Chinmay Gujar CF TYCS/523
Step 15: Click on Generate Report from autopsy window and Select the Excel format and
click on next
Step 16: Now Report is Generated So click on close Button .we can see the Report on Report
Node
Chinmay Gujar CF TYCS/523
Step 17: Now open the Report folder and Open Excel File.