最新kali之autopsy

描述:

  默认情况下,autopsy会在端口9999上启动``autopsy取证浏览器’'服务器并接受来自localhost的连接。如果指定了-p端口,则服务器将在该端口上打开,如果指定了地址,则仅会从该主机接受连接。 当给出-i参数时,autopsy将进入实时分析模式。
  启动时,程序将显示一个URL,以便粘贴到HTML浏览器中。浏览器必须支持框架和表单。Autopsy鉴定浏览器将允许调查人员分析由dd(1)生成的图像作为证据。该程序允许图像通过浏览文件,块,inode,或搜索块进行分析。该程序还生成autopsy报告,包括收集时间、调查人员姓名和MD5哈希值。

选项:

	-c
		强制程序即使在本地主机上也使用cookie。

	-C
		强制程序即使对远程主机也不要使用cookie。

	-d evid_locker
		存储案例和主机的目录。这将覆盖conf.pl中的LOCKDIR值。路径必须是一个完整的路径(即以/开头)。
		
	-I device filesystem mnt
		指定实时分析模式的信息。 可以根据需要指定多次。 设备字段用于原始文件系统设备,文件系统字段用于文件系统类型,而mnt字段用于文件系统的安装点

	-p port
		服务器监听的TCP端口。

	addr
		调查人员所在的IP地址或主机名。 如果使用本地主机,则URL中必须使用'本地主机'。如果使用实际的主机名或IP,它将被拒绝。

注:更多kali相关资讯可关注公众号(bi路),也可以访问个人搭建的kali专属站点笔路(https://www.bilu.asia)

kali站点笔路
同时也可以直接访问https://mobile.yangkeduo.com/goods.html?goods_id=209567782598 ,提前一步获取kali相关资讯。

在这里插入图片描述

接下来每天会发布一篇kali相关文档,敬请关注留意。

  • 3
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论
Learn the skills you need to take advantage of Kali Linux for digital forensics investigations using this comprehensive guide Key Features Master powerful Kali Linux tools for digital investigation and analysis Perform evidence acquisition, preservation, and analysis using various tools within Kali Linux Implement the concept of cryptographic hashing and imaging using Kali Linux Perform memory forensics with Volatility and internet forensics with Xplico. Discover the capabilities of professional forensic tools such as Autopsy and DFF (Digital Forensic Framework) used by law enforcement and military personnel alike Book Description Kali Linux is a Linux-based distribution used mainly for penetration testing and digital forensics. It has a wide range of tools to help in forensics investigations and incident response mechanisms. You will start by understanding the fundamentals of digital forensics and setting up your Kali Linux environment to perform different investigation practices. The book will delve into the realm of operating systems and the various formats for file storage, including secret hiding places unseen by the end user or even the operating system. The book will also teach you to create forensic images of data and maintain integrity using hashing tools. Next, you will also master some advanced topics such as autopsies and acquiring investigation data from the network, operating system memory, and so on. The book introduces you to powerful tools that will take your forensic abilities and investigations to a professional level, catering for all aspects of full digital forensic investigations from hashing to reporting. By the end of this book, you will have had hands-on experience in implementing all the pillars of digital forensics—acquisition, extraction, analysis, and presentation using Kali Linux tools. What you will learn Get to grips with the fundamentals of digital forensics and explore best practices Understand the workings of file systems, storage, and data fundamentals Discover incident response procedures and best practices Use DC3DD and Guymager for acquisition and preservation techniques Recover deleted data with Foremost and Scalpel Find evidence of accessed programs and malicious programs using Volatility. Perform network and internet capture analysis with Xplico Carry out professional digital forensics investigations using the DFF and Autopsy automated forensic suites Who This Book Is For This book is targeted at forensics and digital investigators, security analysts, or any stakeholder interested in learning digital forensics using Kali Linux. Basic knowledge of Kali Linux will be an advantage. Table of Contents Introduction to Digital Forensics Installing Kali Linux Understanding File Systems and Storage Media Incident Response and Data Acquisition Evidence Acquisition and Preservation with DC3DD and Guymager File Recovery and Data Carving with Foremost and Scalpel Live and Memory Forensics with Volatility Autopsy – The Sleuth Kit Network and Internet Capture Analysis with Xplico Collecting, Preserving and Revealing Evidence using DFF

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

Vanony

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值