Difference between pages "Volatility Framework" and "Adroit Photo Forensics"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
 
(Features)
 
Line 1: Line 1:
 
{{Infobox_Software |
 
{{Infobox_Software |
   name = Volatility |
+
   name = Adroit Photo Forensics (APF) |
   maintainer = [[AAron Walters]] |
+
   maintainer = [[Digital Assembly]] |
   os = {{Cross-platform}} |
+
   os = {{Windows}} |
   genre = [[Memory analysis]] |
+
   genre = {{Analysis}} |
   license = {{GPL}} |
+
   license = {{Commercial}} |
   website = [https://www.volatilesystems.com/default/volatility https://www.volatilesystems.com/] |
+
   website = [http://www.digital-assembly.com/products digital-assembly.com] |
 
}}
 
}}
  
The '''Volatility Framework''' is a completely open collection of tools, implemented in Python under the GNU General Public License, for the extraction of digital artifacts from volatile memory (RAM) samples. The extraction techniques are performed completely independent of the system being investigated but offer unprecedented visibility into the runtime state of the system. The framework is intended to introduce people to the techniques and complexities associated with extracting digital artifacts from volatile memory samples and provide a platform for further work into this exciting area of research.  
+
'''Adroit Photo Forensics''' ('''APF''') is a commercial forensic software package distributed by [[Digital Assembly]].
 +
It specializes in the recovery and analysis of digital photographs.
  
The project was originally developed by and is now headed up by [[AAron Walters]] of [[Volatile Systems]].
+
=Features=
  
== Plugins ==
+
Adroit Photo Forensics can parse a number of filesystems, including [[FAT]] 12/16/32, [[NTFS]], [[HFS]], and [[HFS+]]. It can
See: [[List of Volatility Plugins]]
+
read from [[EnCase]] as well as raw/[[dd]] images.
  
== Memory acquisition drivers ==
+
It is best known for implementing the [[File_Carving:SmartCarving|SmartCarving]] and [[File_Carving:SmartCarving|GuidedCarving]]
 +
algorithms to recover fragmented photos.
  
In 2012 [[Michael Cohen]] contributed both a Linux and a Windows Open Source memory (acquisition) driver to the volatility project.
+
== Exif ==
  
These drivers are currently available in the volatility scudette branch and soon to be released as a separate download. To obtain this branch run:
+
Adroit Photo Forensics also parses exif data and can be used to view and group files based on exif date stamps instead of
<pre>
+
file system date stamps. APF also includes a full zoomable time-line viewer based on exif and file system date stamps.  
svn checkout http://volatility.googlecode.com/svn/branches/scudette/ volatility
+
</pre>
+
  
In the scudette branch the drivers can be found under:
+
== Other Features ==
<pre>
+
volatility/tools/linux and volatility/tools/
+
</pre>
+
  
=== Linux ===
+
Adroit Photo Forensics interface is optimized for the display of photos. APF also include grouping and sorting options that are
 +
photo relevant.
  
To build the kernel module for the current kernel version, make sure you have a working build environment and the kernel headers installed. Change into this directory and run make:
+
== External Links ==
<pre>
+
cd volatility/tools/linux/
+
make
+
</pre>
+
  
The acquisition driver is named pmem.ko.
+
[http://digital-assembly.com/products/adroit-photo-forensics/ Adroit Photo Forensics Product Information]
 
+
To load the driver:
+
<pre>
+
sudo insmod pmem.ko
+
</pre>
+
 
+
To check if the driver is running:
+
<pre>
+
sudo lsmod
+
</pre>
+
 
+
The driver create a device file named:
+
<pre>
+
/dev/pmem
+
</pre>
+
 
+
To unload the driver:
+
<pre>
+
sudo rmmod pmem
+
</pre>
+
 
+
To read acquire the memory just read from the device file. e.g.
+
<pre>
+
dd if=/dev/pmem of=image.raw
+
</pre>
+
 
+
For more information see:
+
<pre>
+
volatility/tools/linux/README
+
</pre>
+
 
+
=== Windows ===
+
Since recent versions of 64 bit Windows require a signed driver the volatility scudette branch comes with both pre-built (binary) and source versions of the driver. The prebuilt binary is signed.
+
 
+
Both the i386 and amd64 binary version of the driver can be found on the downloads part of the [http://code.google.com/p/volatility/ Volatility code repository] as winpmem or in the scudette branch under:
+
<pre>
+
volatility/tools/winpmem/binaries/
+
</pre>
+
 
+
E.g.
+
<pre>
+
volatility/tools/winpmem/binaries/amd64/winpmem.sys
+
</pre>
+
 
+
A standalone tool for imaging memory that uses an embedded copy of the pmem driver can be found as winpmem.exe in:
+
<pre>
+
volatility/tools/winpmem/executables/Release/
+
</pre>
+
 
+
To load the driver:
+
<pre>
+
winpmem.exe -l
+
</pre>
+
 
+
The device filename is (This can not be changed without recompiling):
+
<pre>
+
\\.\pmem
+
</pre>
+
 
+
To read and acquire the physical memory and write it to image.raw:
+
<pre>
+
winpmem.exe image.raw
+
</pre>
+
 
+
To unload the driver:
+
<pre>
+
winpmem.exe -u
+
</pre>
+
 
+
For more information see:
+
<pre>
+
volatility/tools/windows/README
+
</pre>
+
 
+
== See Also ==
+
* [[List of Volatility Plugins]]
+
 
+
== External Links ==
+
* [https://www.volatilesystems.com/default/volatility Official web site]
+
* [http://code.google.com/p/volatility/ Code repository]
+
* [http://code.google.com/p/volatility/w/list Volatility Documentation]
+

Revision as of 15:02, 26 October 2009

Adroit Photo Forensics (APF)
Maintainer: Digital Assembly
OS: Windows
Genre: Analysis
License: Commercial
Website: digital-assembly.com

Adroit Photo Forensics (APF) is a commercial forensic software package distributed by Digital Assembly. It specializes in the recovery and analysis of digital photographs.

Features

Adroit Photo Forensics can parse a number of filesystems, including FAT 12/16/32, NTFS, HFS, and HFS+. It can read from EnCase as well as raw/dd images.

It is best known for implementing the SmartCarving and GuidedCarving algorithms to recover fragmented photos.

Exif

Adroit Photo Forensics also parses exif data and can be used to view and group files based on exif date stamps instead of file system date stamps. APF also includes a full zoomable time-line viewer based on exif and file system date stamps.

Other Features

Adroit Photo Forensics interface is optimized for the display of photos. APF also include grouping and sorting options that are photo relevant.

External Links

Adroit Photo Forensics Product Information