摘要: |
One product of a digital forensics examination is a reconstruction of events recordedin the media. A reconstruction places all of the case relevant trace into temporal,identity and associative relationships. Creating this reconstruction is a manual andtime consuming process for the examiner. This thesis presents Autopsy IntegratedEvent Reconstruction (AIER). AIER integrates automation, abstraction and visu-alization into the Autopsy forensic software to improve the reconstruction process.The integration utilizes a custom Autopsy ingest module to extract and abstractartifact data and an interactive graph-based timeline visualization module. Theseimprovements to the forensic examiner workflow are evaluated through a series of usecases. |