Triage Image Creation

แชร์
ฝัง
  • เผยแพร่เมื่อ 10 พ.ย. 2024

ความคิดเห็น • 10

  • @RickHenderson
    @RickHenderson 3 ปีที่แล้ว +1

    Thanks so much, this was really amazing. Not only am I interviewing for a CSIRT position on Friday, but tomorrow I'm helping someone clean up her computer as part of her divorce, and recovering some files might be required! And I have old drives I want to try and recover files from too. I look forward to seeing more of your videos.

    • @13Cubed
      @13Cubed  3 ปีที่แล้ว

      Thanks! Also check out Introduction to KAPE (th-cam.com/video/pZRrZAJif8Q/w-d-xo.html), which is basically a follow-up to this episode. Using KAPE is now the preferred way to create triage images.

  • @kareemh91
    @kareemh91 4 ปีที่แล้ว +1

    Thank you alot for your efforts

  • @delrosarioruck
    @delrosarioruck 3 ปีที่แล้ว

    Hello Sir, is there any other tools that AD1 image can analyze/preview other than FTKSuite and FTKImager?

    • @13Cubed
      @13Cubed  3 ปีที่แล้ว

      You might try Arsenal Image Mounter. Can't say I've tried to mount an AD1 with it, but it's hands down the best image mounting utility you can find.

  • @SajidKiani1
    @SajidKiani1 5 ปีที่แล้ว

    How to create an image of ransomware affected drive? When we plug in any USB, all file are encrypted.

  • @tonymorin83
    @tonymorin83 6 ปีที่แล้ว

    Is the a way to set a default custom content sources? like if you have a core data you want to gather each time and automate the data acquisition using FTK?

    • @richmcelroy2382
      @richmcelroy2382 5 ปีที่แล้ว +1

      I believe FTK imager is manual. To get a customized image use Cylr. You can customize the config file.

    • @tonymorin83
      @tonymorin83 5 ปีที่แล้ว

      @@richmcelroy2382 Thanks

  • @alex_94-r2g
    @alex_94-r2g 6 ปีที่แล้ว

    nice vid thanks