Android logical forensics extraction using AFLogical OSE on Santoku Linux 0.5

แชร์
ฝัง
  • เผยแพร่เมื่อ 6 ก.พ. 2025
  • Populating an Android emulator, then extracting the data using Santoku Linux 0.5. Completed in a VMWare Fusion VM on Mac OSX.

ความคิดเห็น • 19

  • @ayushkayasth2501
    @ayushkayasth2501 3 หลายเดือนก่อน

    🎯 Key points for quick navigation:
    00:00 *Introduction to performing a logical forensic acquisition on an Android device using Santoku Linux.*
    00:14 *Navigate to the Santoku image, select the Android SDK manager, and start installing necessary tools.*
    00:40 *Install specified SDK tools and accept licenses, fast-forward through the install process.*
    01:48 *Install additional packages under the tools folder, accept the licenses, and proceed.*
    02:46 *Create a new Android virtual device (AVD), configure it with specified parameters.*
    03:45 *Launch the newly created Android device, acknowledging potential resource-heavy load times.*
    04:33 *Populate data on the Android device with mock contacts, calls, and text messages for testing.*
    05:00 *Begin the forensic process via Santoku's AFLogical O, typing specific commands into the terminal.*
    05:39 *Use default credentials or leave blank to open the AFLogical application on the Android device.*
    06:21 *Capture data from the Android device to your home directory by following specified prompts.*
    07:07 *Locate and access the captured data in CSV format, containing the information from the device.*
    Made with HARPA AI

  • @dmalqahtani
    @dmalqahtani 5 ปีที่แล้ว

    Thank you Kevin, that is really useful :)

  • @oai9106
    @oai9106 5 ปีที่แล้ว +1

    Thanks, Kevin see when am in inside santoku am unable to navigate out of the distro I always have to shut it down is there anything I need to do so I can navigate in and out of the box thanks

  • @harrypilkington3007
    @harrypilkington3007 8 ปีที่แล้ว

    how to i take a physical image of a galaxy s7 with a screen that will not display

  • @bupeshp777
    @bupeshp777 9 ปีที่แล้ว +1

    failed to create directory /usr/share/android-sdk/sdk/temp i am getting this as an error while following as u said after cliking on install 5 packages. please help me

    • @redsfan1211
      @redsfan1211  9 ปีที่แล้ว +1

      +Anchor Bupesh Pyush open a terminal window and type 'sudo mkdir /usr/share/android-sdk/sdk/temp' then try again

  • @MTF1Gaming
    @MTF1Gaming 4 ปีที่แล้ว

    Hello, can you please make a tutorial on how to pull emails using Santoku ? Thanks great video nonetheless.

  • @bupeshp777
    @bupeshp777 9 ปีที่แล้ว

    URL not found: /usr/share/android-sdk/sdk/temp/support_r23.0.1.zip (Permission denied)
    Skipping 'intel x86 Atom System Image, Android API 10, revision 3 '; it depends on 'SDK
    Platform Android 2.3.3,API 10, revision 2' which was not installed
    Done. Nothing was installed
    this was the error when i try to install the packages android sdk manager log .. please help me sir thanks in advance.

    • @redsfan1211
      @redsfan1211  9 ปีที่แล้ว

      +Anchor Bupesh Pyush The issues here is likely that Android Studio is now the defacto tool for the Android emulator. I recommend downloading Android Studio and working off that. You can download that here: developer.android.com/sdk/index.html

    • @bupeshp777
      @bupeshp777 9 ปีที่แล้ว

      Shall i download it to santoku linux or should i download it to my normal os

    • @redsfan1211
      @redsfan1211  9 ปีที่แล้ว +1

      Santoku

    • @bupeshp777
      @bupeshp777 9 ปีที่แล้ว

      i am not able to access intenet in santoku sir

  • @cindysanchez6203
    @cindysanchez6203 8 ปีที่แล้ว +2

    Does it also recover deleted text messages?

    • @redsfan1211
      @redsfan1211  7 ปีที่แล้ว

      Cindy, AFLogical OSE only recovers messages still on the device. To recover deleted messages, you'd have to pull the .db file and use a tool like scalpel to carve for deleted data.

  • @くさあさ
    @くさあさ 8 ปีที่แล้ว

    why chose api 2.3
    to for example??

    • @redsfan1211
      @redsfan1211  8 ปีที่แล้ว +1

      Uses the least amount of resources & runs the fastest in virtualized environment.

  • @RyanBarnes
    @RyanBarnes 7 ปีที่แล้ว

    I know this is an old video, but you mention that you're using Android 2.3.3 because it's smaller resource footprint, is that still true in 2017?

    • @redsfan1211
      @redsfan1211  7 ปีที่แล้ว +1

      I'd assume so. I haven't tested recently, but my past experience I've found that the newer the OS, the more resource intensive it is.

  • @Guest-gy9vp
    @Guest-gy9vp 7 ปีที่แล้ว

    does not work anymore