Thread: [sleuthkit-users] Autopsy 3.1.2 is available
Brought to you by:
carrier
From: Brian C. <ca...@sl...> - 2015-03-05 04:35:04
|
Autopsy 3.1.2 is on the website. Details of what is in it are below. The most requested feature that is part of this release is carving using PhotoRec. http://sleuthkit.org/autopsy/ Also a reminder that we'll be using this version in the next training course, which is on March 18 and available both in person in Herndon, VA and online: http://www.basistech.com/digital-forensics/autopsy/training/ What's New in 3.1.2: • New PhotoRec carving ingest module • Metadata tab in lower right now also shows istat (TSK) output for more metadata details • Regripper output is available as a report instead of TOOL_OUTPUT artifact • Updated version of RegRipper • New STIX/Cybox report module (manually run after image has been analyzed) • File type module supports user defined file types and can alert when they are found • More artifacts are extracted from registry • User docs were moved online (http://sleuthkit.org/autopsy/docs/user-docs/3.1/) |
From: Anthony S. <ant...@gm...> - 2015-03-05 13:41:01
|
<p dir="ltr">Awesome. Thanks!<br><br></p> <p dir="ltr">Sent using <a href="https://cloudmagic.com/k/d/mailapp?ct=ta&cv=6.0.6.1&pv=5.0.2">CloudMagic</a></p> <br/><div class="cm_quote" style=" color: #787878">On Wed, Mar 04, 2015 at 11:38 pm, Brian Carrier <<a href="mailto:ca...@sl...">ca...@sl...</a>> wrote:</div><br><div id="oldcontent" style="background: rgb(255, 255, 255);"><blockquote style=""><p dir="ltr">Autopsy 3.1.2 is on the website. Details of what is in it are below. The most requested feature that is part of this release is carving using PhotoRec. <br> <br> http://sleuthkit.org/autopsy/ <br> <br> Also a reminder that we'll be using this version in the next training course, which is on March 18 and available both in person in Herndon, VA and online: <br> <br> http://www.basistech.com/digital-forensics/autopsy/training/ <br> <br> What's New in 3.1.2: <br> <br> • New PhotoRec carving ingest module <br> • Metadata tab in lower right now also shows istat (TSK) output for more metadata details <br> • Regripper output is available as a report instead of TOOL_OUTPUT artifact <br> • Updated version of RegRipper <br> • New STIX/Cybox report module (manually run after image has been analyzed) <br> • File type module supports user defined file types and can alert when they are found <br> • More artifacts are extracted from registry <br> • User docs were moved online (http://sleuthkit.org/autopsy/docs/user-docs/3.1/) <br> ------------------------------------------------------------------------------ <br> Dive into the World of Parallel Programming The Go Parallel Website, sponsored <br> by Intel and developed in partnership with Slashdot Media, is your hub for all <br> things parallel software development, from weekly thought leadership blogs to <br> news, videos, case studies, tutorials and more. Take a look and join the <br> conversation now. http://goparallel.sourceforge.net/ <br> _______________________________________________ <br> sleuthkit-users mailing list <br> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <br> http://www.sleuthkit.org <br> </p> </blockquote></div> |
From: Greg F. <gre...@gm...> - 2015-03-11 19:54:55
|
Brian, Has autopsy 3.x ever grown linux support? Thanks Greg -- Greg Freemyer On Wed, Mar 4, 2015 at 11:34 PM, Brian Carrier <ca...@sl...> wrote: > Autopsy 3.1.2 is on the website. Details of what is in it are below. The most requested feature that is part of this release is carving using PhotoRec. > > http://sleuthkit.org/autopsy/ > > Also a reminder that we'll be using this version in the next training course, which is on March 18 and available both in person in Herndon, VA and online: > > http://www.basistech.com/digital-forensics/autopsy/training/ > > What's New in 3.1.2: > > • New PhotoRec carving ingest module > • Metadata tab in lower right now also shows istat (TSK) output for more metadata details > • Regripper output is available as a report instead of TOOL_OUTPUT artifact > • Updated version of RegRipper > • New STIX/Cybox report module (manually run after image has been analyzed) > • File type module supports user defined file types and can alert when they are found > • More artifacts are extracted from registry > • User docs were moved online (http://sleuthkit.org/autopsy/docs/user-docs/3.1/) > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Brian C. <ca...@sl...> - 2015-03-12 01:38:51
|
There is a link on the forum for Ubuntu: http://forum.sleuthkit.org/viewtopic.php?f=5&t=106 On Mar 11, 2015, at 3:54 PM, Greg Freemyer <gre...@gm...> wrote: > Brian, > > Has autopsy 3.x ever grown linux support? > > Thanks > Greg > -- > Greg Freemyer > > > On Wed, Mar 4, 2015 at 11:34 PM, Brian Carrier <ca...@sl...> wrote: >> Autopsy 3.1.2 is on the website. Details of what is in it are below. The most requested feature that is part of this release is carving using PhotoRec. >> >> http://sleuthkit.org/autopsy/ >> >> Also a reminder that we'll be using this version in the next training course, which is on March 18 and available both in person in Herndon, VA and online: >> >> http://www.basistech.com/digital-forensics/autopsy/training/ >> >> What's New in 3.1.2: >> >> • New PhotoRec carving ingest module >> • Metadata tab in lower right now also shows istat (TSK) output for more metadata details >> • Regripper output is available as a report instead of TOOL_OUTPUT artifact >> • Updated version of RegRipper >> • New STIX/Cybox report module (manually run after image has been analyzed) >> • File type module supports user defined file types and can alert when they are found >> • More artifacts are extracted from registry >> • User docs were moved online (http://sleuthkit.org/autopsy/docs/user-docs/3.1/) >> ------------------------------------------------------------------------------ >> Dive into the World of Parallel Programming The Go Parallel Website, sponsored >> by Intel and developed in partnership with Slashdot Media, is your hub for all >> things parallel software development, from weekly thought leadership blogs to >> news, videos, case studies, tutorials and more. Take a look and join the >> conversation now. http://goparallel.sourceforge.net/ >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: <gre...@gm...> - 2015-03-12 01:58:56
|
thanks I'll try it. On March 11, 2015 9:38:46 PM EDT, Brian Carrier <ca...@sl...> wrote: >There is a link on the forum for Ubuntu: > >http://forum.sleuthkit.org/viewtopic.php?f=5&t=106 > >On Mar 11, 2015, at 3:54 PM, Greg Freemyer <gre...@gm...> >wrote: > >> Brian, >> >> Has autopsy 3.x ever grown linux support? >> >> Thanks >> Greg >> -- >> Greg Freemyer >> >> >> On Wed, Mar 4, 2015 at 11:34 PM, Brian Carrier ><ca...@sl...> wrote: >>> Autopsy 3.1.2 is on the website. Details of what is in it are >below. The most requested feature that is part of this release is >carving using PhotoRec. >>> >>> http://sleuthkit.org/autopsy/ >>> >>> Also a reminder that we'll be using this version in the next >training course, which is on March 18 and available both in person in >Herndon, VA and online: >>> >>> http://www.basistech.com/digital-forensics/autopsy/training/ >>> >>> What's New in 3.1.2: >>> >>> • New PhotoRec carving ingest module >>> • Metadata tab in lower right now also shows istat (TSK) >output for more metadata details >>> • Regripper output is available as a report instead of >TOOL_OUTPUT artifact >>> • Updated version of RegRipper >>> • New STIX/Cybox report module (manually run after image has >been analyzed) >>> • File type module supports user defined file types and can >alert when they are found >>> • More artifacts are extracted from registry >>> • User docs were moved online >(http://sleuthkit.org/autopsy/docs/user-docs/3.1/) >>> >------------------------------------------------------------------------------ >>> Dive into the World of Parallel Programming The Go Parallel Website, >sponsored >>> by Intel and developed in partnership with Slashdot Media, is your >hub for all >>> things parallel software development, from weekly thought leadership >blogs to >>> news, videos, case studies, tutorials and more. Take a look and join >the >>> conversation now. http://goparallel.sourceforge.net/ >>> _______________________________________________ >>> sleuthkit-users mailing list >>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>> http://www.sleuthkit.org >> >> >------------------------------------------------------------------------------ >> Dive into the World of Parallel Programming The Go Parallel Website, >sponsored >> by Intel and developed in partnership with Slashdot Media, is your >hub for all >> things parallel software development, from weekly thought leadership >blogs to >> news, videos, case studies, tutorials and more. Take a look and join >the >> conversation now. http://goparallel.sourceforge.net/ >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org -- Sent from my Android device with K-9 Mail. Please excuse my brevity. |