Tännler, Luca and Vetsch, Mathias (2016) Forensic Triage Kit. Bachelor thesis, HSR Hochschule für Technik Rapperswil.
Forensic_Triage_Kit_eprints.pdf - Supplemental Material
Download (2MB) | Preview
Abstract
The forensic analysis of Windows systems is usually extremely time consuming. Therefore, in computer forensics, it is important to automatically mark known files whenever possible. This automated process is called forensic triage. The base for forensic triage is a framework, that starts different triage techniques and aggregates all relevant results.
The aim of this project was to create a solution for such a forensic triage kit with a set of standard triage technique features.
In the evaluation phase, different analysis techniques and frameworks were examined. This lead to the use of the Autopsy project as a basis. Autopsy is an open source digital forensics platform already containing a set of forensic triage features.
The implementation was done in a way of contribution to Autopsy itself and the development of several modules. For example, a module performs a check against an uninfected copy of a system, while another module verifies code signing certificates.
The result of the project is a significant improvement of efficiency in the analysis of Windows images when using Autopsy. A huge part of standard Windows images can be automatically marked as known-good with minimal user interaction.
Item Type: | Thesis (Bachelor) |
---|---|
Subjects: | Topics > Security Area of Application > Business oriented Area of Application > Desktop based Technologies > Programming Languages > Java Technologies > Operating Systems > Windows Brands > Microsoft |
Divisions: | Bachelor of Science FHO in Informatik > Bachelor Thesis |
Depositing User: | OST Deposit User |
Contributors: | Contribution Name Email Thesis advisor Brunschwiler, Cyrill UNSPECIFIED |
Date Deposited: | 05 Oct 2016 11:25 |
Last Modified: | 05 Oct 2016 11:25 |
URI: | https://eprints.ost.ch/id/eprint/527 |