Presentation is loading. Please wait.

Presentation is loading. Please wait.

File Extractor Pro’s File Signature Builder

Similar presentations


Presentation on theme: "File Extractor Pro’s File Signature Builder"— Presentation transcript:

1 File Extractor Pro’s File Signature Builder
File Carving Tools File Extractor Pro’s File Signature Builder © Dr. D. Kall Loper, all rights reserved

2 File Signature Builder
Premise A data runs in unallocated space were at one time an active file. Propositions The program that created the file created more than one file. This program need not be on the computer. At least two sample files are still active on the system. © 2012 Dr. D. Kall Loper & 2006 Core Digital Forensics Inc. all respective rights reserved

3 File Signature Builder
Match Sample Files FSB examines each file in the folders selected. The file must be larger the 32K or else it is skipped. At least two files are needed for a match. System files and “locked” files are skipped. © 2012 Dr. D. Kall Loper & 2006 Core Digital Forensics Inc. all respective rights reserved

4 File Signature Builder
Identify matching file signatures, Matching bytes at the beginning plus various trigger points within the file Create a list of all newly identified file signatures Search unallocated space for any of the newly identified file signatures © 2012 Dr. D. Kall Loper & 2006 Core Digital Forensics Inc. all respective rights reserved

5 File Signature Builder
Files system objects are gathered. Illustration © Dr. D. Kall Loper, all rights reserved

6 File Signature Builder
FSB creates an MD4 hash from the first 2.5 MB. If the file is smaller than 2.5 MB then whole file is hashed. Illustration © Dr. D. Kall Loper, all rights reserved

7 File Signature Builder
Files with duplicate hashes are removed from the analysis. Illustration © Dr. D. Kall Loper, all rights reserved

8 File Signature Builder
FSB looks for files with similar first 15 bytes. Unique files are excluded from the analysis. Illustration © Dr. D. Kall Loper, all rights reserved

9 File Signature Builder
FSB compares file signatures by stepping through each byte of the matching groups. Illustration © Dr. D. Kall Loper, all rights reserved

10 File Signature Builder
FSB creates a 'draft' list of signatures. Illustration © Dr. D. Kall Loper, all rights reserved

11 File Signature Builder
Unworkable or useless (all 00xh) headers are removed. Illustration © Dr. D. Kall Loper, all rights reserved

12 File Signature Builder
Using File Extractor Pro The signatures are added to the custom signature list in File Extractor Pro. © 2012 Dr. D. Kall Loper & 2006 Core Digital Forensics Inc. all respective rights reserved


Download ppt "File Extractor Pro’s File Signature Builder"

Similar presentations


Ads by Google