Atola Insight Forensic

Case management: Changing details in a case

Insight’s case management system has been created to help users efficiently keep track of hard drive-related information. Even if a hard drive has already been used for a while, imaging and hashing have already been performed, it is still possible to open the case and make adjustments to its details. Click the Plus icon next to the Case Number in the top right corner. Now you can enter or change the Case Number and Description. To save your changes click OK button. You will see the description visible next to the Case History. For quick changes, you can also click Change link located right below the description. A little lower Read more…

Atola Insight Forensic

Connecting MacBook using Thunderbolt extension module

Last week we released Atola Insight Forensic 4.9, which includes Thunderbolt extension module. This extension provides Insight users with the capability to image, calculate hash and perform other forensically sound operations on all generations of MacBooks. This guide will explain how to connect a MacBook to Insight using Thunderbolt extension. Extension and cables Thunderbolt extension enables Insight to operate on MacBooks with these interfaces: FireWire, Thunderbolt 2 and Thunderbolt 3 (2016 – 2017 models). There is no need to remove the SSD, Thunderbolt extension allows connecting the whole Apple laptop to Insight. The extension module comes with: Thunderbolt 3 to Thunderbolt 2 adapter (by Apple) Thunderbolt 2 to FireWire adapter Read more…

Atola Insight Forensic

Atola Insight Forensic 4.9 – Thunderbolt extension

We are delighted to announce the release of Atola Insight Forensic 4.9! With this release we introduce our new Thunderbolt extension module, which will enable forensically sound imaging and other operations on all generations of MacBooks. The full list of Atola Insight Forensic 4.9 changes can be found here: Atola Insight Forensic Changelog. Supported interfaces and functionality Thunderbolt extension enables Insight to work on all MacBooks with the following interfaces: FireWire Thunderbolt 2 Thunderbolt 3 (2016 – 2017 models) With the help of Thunderbolt extension module you can perform such operations: imaging hash calculation hash verification comparing media scan file recovery 2016 and 2017 generations of MacBooks have non-extractable SSD Read more…

Atola Insight Forensic

Comparing hashes of source and target to find modified data

So you have a Source evidence drive and its image on a different device, and you have a record that their hash values were identical in the past. If you get a different hash value when you calculate the hash of the target now, it could be due to hardware failure, or because the device containing your image was used by a third party. To understand how substantial these changes are, you will want to locate the sectors that have been modified. In the Disk Utilities category click Compare subcategory. Make sure that the whole range of sectors of the drive and radio button next to Device on DiskSense Target Read more…

Atola Insight Forensic

Case Management: Print reports from a case

Insight’s Case Management system includes flexible printing functionality. To print a report click the Print link in the case’s Home page. In the Print Case History window you get all the reports listed, sortable by date or by reported operation. It is possible to tick just some of the reports or select all reports in the case by ticking the check box in the header of the list. Below there are all pictures attached to the case, which you can also select to be printed. At the top of the Print Case History window there are four check boxes with report listing and printing settings (click on the Case Management Read more…

Atola Insight Forensic

Calculating MD5 and SHA1 hashes of an existing E01 file

It is not uncommon that source evidence drives and their images may be involved in a long-running investigation case or wait to be presented in court for months or even years. Data stored on hard drives or image files may get corrupt over time. That is why an investigator may need to ensure the integrity of data on these devices or image files before resuming to work with them or presenting them in court. Over the years, E01 file format has become a popular format for forensic purposes due to its ability to store not only the physical or logical copy of the source drive, but also case and evidence Read more…

Atola Insight Forensic

Creating a logical image of a source drive

While physical imaging involves sector-for-sector copying the whole evidence drive from the first LBA to the last one, logical acquisition implies bit-for-bit copying of the file structure. Logical acquisition is handy, when time is limited and you need to quickly start working with the file structure. At the same time, logical image does not include remaining fragments of previously deleted files, which makes this imaging method incomplete. On top of that, hash values of the source and the target will not be identical. Therefore, for profound investigation, it is still preferable to use a physical image. This guide will show how Atola Insight Forensic’s flexible imaging functionality enables users to Read more…

Atola Insight Forensic

Case Management: Finding and Opening a Case

Insight’s Case Management system records every step of data acquisition process saving them into reports grouped by cases. To view the whole list of cases and their devices: Go to Case category in the top menu Click on Search/Open option In the Search and Open Case window you will see the list of all the devices that have ever been connected and identified by your Insight. It is possible to search for cases using multiple criteria and sort the results ascending or descending in any of the columns. Please note that it is possible to store multiple devices under the same case number, allowing you to keep track of all Read more…

Atola Insight Forensic

Q&A during Forensic Europe Expo

Atola team attended the annual Forensic Europe Expo on May 3 – 4 in London. We were pleased to meet both our existing and potential customers, and answer their questions about Atola Insight Forensic. Those of you who were not able to attend this event may have similar questions, so here are the most frequently asked ones at the Expo and our answers to them. We would be happy to answer any further queries you may have, so please don’t hesitate to write a comment below or send us a message here.   Question: Does write protection work for SATA source drives only? Answer: No, write protection works for all source Read more…

Atola Insight Forensic

Verifying Damaged Target Images with Segmented Hashing

Last November Atola Technology team presented a new hashing method called Segmented hashing. Unlike the conventional linear hashing, segmented hashing produces not a single hash, but a list of hashes of corresponding LBA ranges of the image saved into a CSV file in this format: Hash, start LBA, end LBA By validating all hashes in the list, you can prove that the entire image has not been modified. For more information about this hashing method, please follow this link: Segmented Hashing. While this method of hashing has a number of benefits for forensic specialists, among its strongest advantages is its applicability to damaged drives. For one, this non-linear hashing method allows calculating hashes Read more…