Course list http://www.c-jump.com/bcc/
![]() |
|
Photo Forensic Case Stages:
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
![]() |
|
![]() |
|
![]() |
|
On average 16-20% of photos are fragmented.
Every additional picture recovered can contain:
Potential Suspects
Potential Leads
Potential Victims
Potential Locations
Missing timeline information
NOTE: images are often stored in fragments when the media card of the camera starts to fill up. Not only harddisks, but photo camera's flash cards must be forensically wiped before they can be sold or given away.
![]() |
|
![]() |
|
![]() ![]() |
|
![]() |
|
![]() |
|
Uses 2 Modes:
Best for detailed analysis
Fast for triage (does not slow down recovery)
Experimental Child Explicit Image Detector included
Dynamic slider used for reducing or increasing explicit images shown.
Detection by "by skin percentage"
To reduce the amount of false positives and false negatives, EID uses
skin/face/body form analysis and combines them together
machine-learning algorithms to distinguish child from not-child
Machine learning is a process of identification of certain kinds of images by processing other similar images.
For example, program may compute the distance between a person's eyes and nose and other facial features to separate children from adults.
APF is about 70 percent accurate in identifying images of interest.
![]() ![]() |
|
To finding known illicit images, examiners normally use known MD5 hash sets
APF naturally supports loading hash sets and MD5 hash alerts
But if the photo is slightly changed...
...MD5 Hash will not work
APF incorporates "Smart Hashing" that finds photos even if the photo was
Resized
Color changed
Brightness changed
Slightly Cropped/Rotated
Touched up
Underwent a Logo insertion or removal
The photo viewer includes:
Full Image
Preview/Thumbnail Images
Photo Header Details
EXIF MetaData
File System Information
Categorization and Bookmark Info
Summary
Cluster/Fragment Linking
APF generate zoomable time lines based on
File Access Dates
File Creation Dates
File Modification Dates
EXIF Date/Time
Can extract EXIF Date/Times to get date time information even if files are deleted.
Has filter based on dates
Categorization is an important part of a forensic analyst's work.
APF categorization includes built-in category profiles
UK CP
North American CP
APF allows creation of custom profiles.
Create rules to automatically categorize based on Smart Filters
Use hot keys to efficiently categorize from any screen (adult, nudity, CP, and so on.)
Use categories to view/report/export/save/timeline of the photos
Verify Integrity includes:
Full Viewable Logs
Generated MD5/SHA1/SHA256 hashes of photos
Generated MD5/SHA1/SHA256 hashes of evidence before and after recovery
Evidence hashes compared:
prior to recovery,
against current hashes, and
stored hashe sets (limited to Encase format only)
Customizable reports for:
File System Data
Photo Details
EXIF Details
Thumbnails
CSV Exporting of:
File System Data
Photo Details
EXIF Details
Thumbnails
FTK Known File Filter (FTK KFF) Exporting
![]() |
|