Bitcurator Operating
Bitcurator Operating
Bitcurator Operating
Published:
Revised:
Contents
Introduction ..................................................................................................................................... 2
Whats an Image? ....................................................................................................................... 2
Booting up BitCurator .................................................................................................................. 4
Booting for the First Time ....................................................................................................... 4
Mounting Media as Read-Only.............................................................................................. 4
Creating a Forensic Image with Guymager .......................................................................... 6
Understanding Linux Directory Structure ............................................................................ 8
Generating a Forensic Report.................................................................................................. 12
Viewing a Forensic Report ........................................................................................................ 16
Revised:
Introduction
BitCurator is open-source digital forensic software designed to help archival
institutions acquire images of digital files.
Whats an Image?
A digital image is a snapshot of the digital file that contains the content and metadata.
With an image, you are not using the actual digital file, just the snapshot.
Revised:
Blankpage
Revised:
Booting up BitCurator
Booting for the First Time
1. Open Oracle VM VirtualBox. Click Settings.
2. Click USB.
3. Uncheck All USB Devices under USB Device Filters.
4. Click OK.
5. Select the BitCurator virtual machine and click Start.
Revised:
Blankpage
Revised:
Revised:
Revised:
Revised:
Figure 4: home
directory
Figure 5:
bcadmin folder
within home
directory
Revised:
Revised:
10
Blankpage
11
Revised:
4. Under Image file, navigate to the image file you created in Guymager.
5. Under Output Feature Directory, navigate to the Bulk Extractor Output folder you
created on the desktop
6. Under Scanners, make sure base16, Facebook, and Outlook are checked.
Revised:
12
13
Revised:
10.1: Under Annotated Feature File Directory, navigate to the Annotated Features folder you
created on the desktop.
10.2: Under Output Directory for Reports, navigate to the Report Output folder you created
on the desktop and type a filename for the report.
11. Click Run.
When the report is completed, you can view each report item in the folder you created on the
desktop.
Revised:
14
Blank page
15
Revised:
5. Click OK.
6. Click on the type of report you want to view in the Reports window. In the Feature
File window, you will see all of the files that pertain to a specific filter.
When you click on a specific file in Feature File, you will see the relevant data in the
file image. In Figure 11, the left window shows that the telephone filter is selected. The
middle window shows all of the telephone numbers that have been found in the disk
image. The right window shows where the numbers are located in the disk image.
Revised:
16
17
Revised: