Course list http://www.c-jump.com/bcc/

Adroit Photo Forensics


  1. Adroit Photo Forensics Overview
  2. Investigation involving photos
  3. Evidence Acquisition
  4. Photo Recovery of Active Files
  5. Photo Recovery - Carving
  6. Importance of complete carving
  7. Importance of complete carving, cont.
  8. APF Photo Formats
  9. Photo Organization
  10. APF Forensic Photo Gallery
  11. Photo Gallery - Camera Grouping
  12. Content Analysis
  13. APF Smart Filtering
  14. Explicit Image Detection
  15. Explicit Image Detection, cont.
  16. Thumbnail Mismatch
  17. MD5 Hash Alerts -- Smart Hashing
  18. Smart Hashing, cont.
  19. Photo Details -- APF photo viewer
  20. APF photo viewer
  21. Photo Details - Timelines
  22. APF Timelines
  23. Classification/Categorization
  24. Verify Integrity
  25. Verify Integrity
  26. Reporting and Exporting
  27. Reporting and Exporting, cont.
  28. Additional APF Features

1. Adroit Photo Forensics Overview


    Adroit Photo Forensics
  • Developed by Nasir Memon, a professor at the Polytechnic Institute of New York University in Brooklyn

  • APF can be used in investigations involving deliberately deleted images:

    • CP

    • Government/Corporate spying/intelligence

    • Terrorism Activity

    • Photographs of a particular person

    • Explicit images of adults

    • Indoor/outdoor photos

  • Also, private sector recovery of accidentally deleted images on corporate or consumer systems:


2. Investigation involving photos


  • Evidence Acquisition

    Evidence Acquisition
  • Photo Recovery

    Photo Recovery
  • Organization

    Organization
  • Content Analysis

  • Classification/Categorization

  • Verify Integrity

    Content Analysis
  • Photo Details

    Photo Details
  • Reporting and Exporting

    Reporting and Exporting

3. Evidence Acquisition


    Evidence Acquisition
  • Adroit Photo Forensics (APF) supports evidence formats that forensic examiners commonly work with:

    • Disk Images

    • EnCase (E01) single/split images

    • DD/RAW/BIN single/split images

    • Logical Drives

    • Physical Drives


4. Photo Recovery of Active Files


    Photo Recovery
  • Adroit Photo Forensics provides Active recovery for the following file systems:

    • FAT12/16/32

    • NTFS

    • HFS

    • HFS+

  • All other file systems are carved.


5. Photo Recovery - Carving


    carving
  • APF recovers photos using:

    • Validated Carving: Verifies that the photos follow the rules of the format and file signatures

    • NTFS Log Carving: Uses NTFS transaction logs to validate and carve deleted photos

    • Smart Carving: Automatic recovery of deleted/fragmented photos

    • Guided Carving: Manual assisted recovery of deleted/fragmented photos

      guided carving


6. Importance of complete carving



7. Importance of complete carving, cont.



8. APF Photo Formats


    photo formats
  • Adroit Photo Forensics recovers photos taken by digital cameras:

    • JPEG

    • RAW (Canon, Sony, Olympus, Nikon etc.)

    • Adobe DNG

    • TIFF

    • PNG

    • GIF

    • BMP


9. Photo Organization


    Organization
  • Traditional forensic applications are focused on plain text and other file formats

  • APF provides tools for organization and processing of cases involving photos

  • APF Forensic Photo Gallery provides both the view and tools to organize photos

  • Sort/Group/Filter are based on photo-specific properties


10. APF Forensic Photo Gallery


    photo gallery
    photo filters
  • The tools include

    • Identify with one click

    • Cameras used

    • Image Manipulation Software (ex. Photoshop)

    • EXIF Date/Times (Day, Month or Year)

    • File name, folder, and more

  • Photo Filters include

    • By Photo Format

    • By Resolution (include/exclude thumbnails etc.)


11. Photo Gallery - Camera Grouping



12. Content Analysis


    Content Analysis
  • There can be hundreds of thousands of photos in a single disk image

  • Analyzing them manually is not very efficient

  • Viewing photos by the thumbnails can still take a huge amount of time

  • Thumbnails are subject to anti-forensic attacks

  • APF's Smart Filtering can reduce the view to only forensically important photos.


13. APF Smart Filtering


    Smart Filtering
  • Smart Filtering includes:

    • Explicit Image Detection (Fast/Best)

    • Face Detection

    • Thumbnail Mismatch

    • Smart Hash

    • Hash Alerts

  • Designed to focus on the most forensically relevant photos


14. Explicit Image Detection



15. Explicit Image Detection, cont.



16. Thumbnail Mismatch


    thumbnail mismatch
    thumbnail mismatch
  • Thumbnail Mismatch identifies photos where the full image does not match its embedded thumbnail:

    • Criminals know that investigators maybe reviewing evidence via thumbnails.

    • Investigators rarely have the time to view each photo in full detail.

    • Illicit images can be hidden behind "safe" thumbnails, which are easy to do manually or using photo applications like Photoshop or Gimp.


17. MD5 Hash Alerts -- Smart Hashing



18. Smart Hashing, cont.



19. Photo Details -- APF photo viewer



20. APF photo viewer



21. Photo Details - Timelines



22. APF Timelines



23. Classification/Categorization



24. Verify Integrity



25. Verify Integrity



26. Reporting and Exporting



27. Reporting and Exporting, cont.



28. Additional APF Features


    thumbnail blur
  • Batch Analysis for running multiple cases over night or over the weekend

  • Ability to quickly blur thumbnails to prevent others from viewing photos

  • Full hotkey support for all major features.

  • Built-in context sensitive help

  • Certified Adroit Forensic Examiner (CAFE) training