How to do it...

The steps to process and analyze data using Magnet AXIOM are as follows:

  1. Start the Magnet AXIOM Process.
  2. The first window you will see is CASE DETAILS, as you can see in the following figure:

Figure 5.8. Magnet AXIOM CASE DETAILS window

Here, we have four main parts:

  • LOCATION FOR CASE FILES - Here, you should choose the Folder name and File path being created during processing.
  • LOCATION FOR ACQUIRED EVIDENCE - If you plan to acquire drives or mobile devices via AXIOM, choose the Folder name and File path for them, or just choose the same path as for case files.
  • CASE INFORMATION - Type in your case number, your name, and the case description.
  • REPORT OPTIONS - If you have your own logo or company logo, you can choose it by clicking BROWSE. Make sure the image is square, because it will be resized to 150x150 pixels.
  1. Once you have filled in all the fields, you can click GO TO EVIDENCE SOURCES. You can see the EVIDENCE SOURCES window shown in the following figure:

Figure 5.9. Magnet AXIOM EVIDENCE SOURCES window

Here, we have two options: ACQUIRE EVIDENCE and LOAD EVIDENCE.

  1. We are going to use an image we acquired previously, so our choice is the LOAD EVIDENCE button. You can use one of the images you acquired in the previous recipes.
  1. The next window is LOAD EVIDENCE, as you can see in the following figure:

Figure 5.10. Magnet AXIOM LOAD EVIDENCE window
  1. Here, we have a VOLUME SHADOW COPY option - click it. Now we have two more options: DRIVE and IMAGE.
  1. As we noted earlier, we are going to use an image. Once you choose it, you can see the list of shadow copies available on the image, as in the following figure:
Figure 5.11. Volume Shadow Copies list
  1. You can choose one or more shadow copies and go to processing details by clicking NEXT. This time, we will skip this step and go straight to artifacts details (click the GO TO ARTIFACTS DETAILS button).

As we are working with a shadow copy, the MOBILE ARTIFACTS option is inactive, but we can use the COMPUTER ARTIFACTS option. As in Belkasoft Evidence Center, here we have a wide range of artifacts, as you can see in the following figure:

Figure 5.12. Magnet AXIOM SELECT ARTIFACTS TO INCLUDE IN CASE window
  1. For testing purposes, we have included all available artifacts in the case. Click the GO TO ANALYZE EVIDENCE button, and the ANALYZE EVIDENCE button right after that. This will start Magnet AXIOM Examine.
  2. Once processing is finished, you will see the results in Magnet AXIOM Examine.
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.133.109.30