Atola Technology

Case management: Changing details in a case

Insight’s case management system has been created to help users efficiently keep track of hard drive-related information.

Even if a hard drive has already been used for a while, imaging and hashing have already been performed, it is still possible to open the case and make adjustments to its details.

Click the Plus icon next to the Case Number in the top right corner.

Now you can enter or change the Case Number and Description. To save your changes click OK button.

You will see the description visible next to the Case History. For quick changes, you can also click Change link located right below the description.

A little lower there is a green Plus icon, which you can click to add a document or an image to the case.

In the Attach File window enter the file location path and leave a comment in the corresponding field.

If you tick the Copy to work folder check box, the file will be copied to the same folder where any other related files are located, e.g. tables with segmented hashes, logs, imaging maps, file signature lists etc.

You can now see all the uploaded files in the case’s Homepage below the description, and you can view all the details and change them when necessary by clicking Manage attached files link.

Attached Files window contains the list of files including an icon representing the file type, the name, the folder where the file is located, the date when the file was attached to the case and the comment added by the user.

Right-clicking a file provides the Edit option enabling a user to edit the Comment or copy the file to the case folder at any time.

Connecting MacBook using Thunderbolt extension module

Last week we released Atola Insight Forensic 4.9, which includes Thunderbolt extension module. This extension provides Insight users with the capability to image, calculate hash and perform other forensically sound operations on all generations of MacBooks.

This guide will explain how to connect a MacBook to Insight using Thunderbolt extension.

Extension and cables

Thunderbolt extension enables Insight to operate on all MacBooks with FireWire, Thunderbolt 2 and Thunderbolt 3 interfaces. There is no need to remove the SSD, Thunderbolt extension allows connecting the whole Apple laptop to Insight.

The extension module comes with:

  • Thunderbolt 3 to Thunderbolt 2 adapter (by Apple)
  • Thunderbolt 2 to FireWire adapter (by Apple)
  • FireWire cable

Connecting MacBook to DiskSense unit

1. Connect MacBook to DiskSense unit with the help of Thunderbolt extension and the FireWire cable (NB Both MacBook and DiskSense have to be turned off). Use the adapters to connect to the MacBooks with Thunderbolt 2 or Thunderbolt 3 interface.

2. Start DiskSense unit and launch Atola Insight Forensic on your computer.

3. Boot the MacBook in Target Disk Mode. To do that, start it up while holding down the T key. You should see a Firewire or Thunderbolt icon displayed on screen signifying that Target Disk Mode is detected and working.

4. Select Identify device option in the pop-up window.

5. In Source – Select MacBook Case window click Add new case button.

6. If this is the first time this MacBook is identified by Insight, you need to enter the Serial number of the MacBook in the pop-up window and click OK. The device has been identified. (NB MacBook’s serial number can be found on the bottom case).

 

Now you can perform these operations with the connected MacBook:

  • imaging
  • hash calculation
  • hash verification
  • comparing
  • media scan
  • file recovery

When a MacBook is connected to Insight for a subsequent session, it is possible to simply select the appropriate case from the table.

 

Atola Insight Forensic 4.9 – Thunderbolt extension

We are delighted to announce the release of Atola Insight Forensic 4.9!

With this release we introduce our new Thunderbolt extension module, which will enable forensically sound imaging and other operations on all generations of MacBooks.

The full list of Atola Insight Forensic 4.9 changes can be found here: Atola Insight Forensic Changelog.

Supported interfaces and functionality

Thunderbolt extension enables Insight to work on all MacBooks with the following interfaces:

  • FireWire
  • Thunderbolt 2
  • Thunderbolt 3

With the help of Thunderbolt extension module you can perform such operations:

  • imaging
  • hash calculation
  • hash verification
  • comparing
  • media scan
  • file recovery

2016 and 2017 generations of MacBooks have non-extractable SSD drives, so the only way to handle such drives is by booting the MacBook in Target mode. In fact, with Insight’s Thunderbolt extension you can operate on all Macbooks the same way, hard drive extraction is no longer necessary.

If you want to learn more about other 4.9 changes, visit this page: Atola Insight Forensic Changelog.

Where to buy

If you still do not have an Atola Insight Forensic and would like to place an order, this can be done directly via Atola Technology, or from a distributor near you:

http://atola.com/wheretobuy/

Please contact our Atola Technology sales to receive more specific information:

P.S. Dear customers, we appreciate your feedback and will take it into account when making changes to the product. Therefore, please feel free to write your thoughts or ideas as comments below.

Comparing hashes of source and target to find modified data

So you have a Source evidence drive and its image on a different device, and you have a record that their hash values were identical in the past.

If you get a different hash value when you calculate the hash of the target now, it could be due to hardware failure, or because the device containing your image was used by a third party.

To understand how substantial these changes are, you will want to locate the sectors that have been modified.

  1. In the Disk Utilities category click Compare subcategory.
  2. Make sure that the whole range of sectors of the drive and radio button next to Device on DiskSense Target Port option is selected
  3. Click Compare button.

Atola Insight Forensic’s high-performance compare function will compare the source and the target and will help you identify and locate the modified sectors:

Case Management: Print reports from a case

Insight’s Case Management system includes flexible printing functionality. To print a report click the Print link in the case’s Home page.

In the Print Case History window you get all the reports listed, sortable by date or by reported operation. It is possible to tick just some of the reports or select all reports in the case by ticking the check box in the header of the list. Below there are all pictures attached to the case, which you can also select to be printed.

At the top of the Print Case History window there are four check boxes with report listing and printing settings (click on the Case Management arrow to view all check boxes):

  • Insert page break after every report on print
  • Also show miscellaneous reports hides/displays all reports of seemingly minor importance, yet essential to some forensic specialists in accordance with their internal procedures
  • Also print CSV logs allows the printed version of the reports to include operation logs saved in CSV format
  • Also print segmented hashes also enables segmented hash saved in CSV files to be included in the printed version of the reports

It is possible to print or save the selected reports and pictures in a PDF, HTML or RTF file by clicking Save to file… or Print buttons.

If you have ticked the two later options, this is how the log and the segmented hashes will be displayed in the report: