Additional Disk Analysis Flashcards
1
Q
What are Autopsy Data Sources
A
Browse the filesystem
2
Q
What are Autopsy File Views
A
Browse by extension
3
Q
What are autopsy data artifacts
A
Various artifacts from analyzing the data.
4
Q
What command do you use to create a shadow copy
A
gwmi win32_shadowcopy
5
Q
Binwalk
A
CLI tool that automatically extracts files from a volume.
6
Q
What does the –dd flag do in binwalk?
A
Defines the file extensions to extract.
7
Q
When would you search by MIME type rather than extension?
A
Whenever the extension might be misidentified.