Blog

Product Features

Analytics in Magnet AXIOM

We have a proud tradition of bringing analytical tools to Magnet AXIOM — without the need to purchase or install an extra module or add-on product — right from the very first update. With AXIOM 1.1, we launched Magnet.AI, and since then we’ve continued to improve the analytical tools of AXIOM by including Timeline, Connections, and most recently, Media Explorer. 

When we think about Analytics in AXIOM, it’s all about the features and functionality that empower you to derive insights and intelligence quickly and easily. AXIOM does that by using technology like machine learning or CBIR (Content-Based Image Retrieval) as well as using data visualizations so you can intuitively interpret and understand the story of your digital evidence. 

Let’s take a look at some of the Analytics features in AXIOM in a bit more detail. 

Analyze Data From All Evidence Sources in a Single Case File

The analytical tools of AXIOM are only as insightful as the data they can draw insights from, which is why it’s so important that evidence from all devices can be included all in one case.   

When you’re investigating a suspect, you’re most likely not just investigating that suspect’s computer, or only their mobile device, or a specific cloud account. You’re investigating that individual and all of the different digital footprints that they leave regardless of the evidence source. And you need a tool that natively supports examining evidence from all of those evidence sources in a single case file so you can quickly and easily see the entire story of the evidence. 

Magnet AXIOM is the go-to forensics platform for many labs when they need to examine data from computer (Windows, Mac, Chromebook, and Linux devices), memory, mobile, and cloud evidence sources all in one case. 

  • COMPUTER: Ingest and analyze data from Windows, Macs, Chromebooks, and Linux-devices and use an artifacts-first approach to find the most evidence, media, and chats. Plus, easily process memory with Volatility seamlessly integrated into AXIOM.
  • MOBILE: Recover data from Android and iOS devices; plus, AXIOM is the only tool integrated with GrayKey. Bonus: no more manually validating GrayKey images after downloading them, AXIOM does it automatically!
  • CLOUD: Acquire and analyze data from cloud services (e.g. Facebook, Wickr, Signal, and more), plus ingest warrant returns and user-generated archives (e.g., Google Takeout and Facebook Download your Information). 

Case Dashboard: Your Case At-A-Glance 

AXIOM’s Case Dashboard gives you the high-level details of your investigation, the evidence sources, and an overview of the digital evidence so you can quickly move to the analysis phase of your investigation. 

Magnet.AI: Leverage Technology to Save Time

Machine learning has been in AXIOM (almost) from the very beginning: text-based analysis helps to identify luring or grooming conversations common to ICAC investigations. 

Magnet.AI also helps to identify images that may contain depictions of child sexual abuse, nudity, weapons, and drugs—plus it can be used for more classification categories including hate symbols, identification like licenses or passports, screenshots, and more. 

Leverage Content-Based Image Retrieval (CBIR) technology to quickly find similar pictures in your case based on a picture that either in your case, or an external one that you’ve loaded into AXIOM as the query image. With CBIR, effectively, you can customize and create your own image classifications with Magnet.AI, by loading a query image and find similar pictures in your case file. 

With Magnet.AI, you can reduce the amount of “noise” and “junk” with the picture classifier by finding system icons and graphics within datasets. Once they’re identified by Magnet.AI, these items can then be tagged and filtered out. In one of our tests with a real dataset, we reduced the number of media items for review by ~50%. 

Plus, Magnet.AI offers optical character recognition (OCR) and it’s optimized for extracting text from PDF’s, scanned docs, images of docs, and other images that may be included in emails. 

Timeline: See Your Case Unfolding

Timeline is another Analytics feature that is so powerful and easy to use in AXIOM. Timeline creates a graphical visualization based on all of the dates and timestamps available to be parsed out in your case. This includes timestamps reported by the file system, but also because AXIOM takes the artifact first approach to processing data, any timestamps parsed from the artifacts in your case will also be included. 

You can validate what the Timeline is showing without having to dig through the file system to find the file. We do the heavy lifting while giving you quick access to the raw data. 

Another one of the things about Timeline that our customers really love is the Relative Date/Time filter. This is incredibly helpful to quickly learn what happened leading up to an incident or likewise after it. You can anchor on a certain point in time when you know an incident occurred and then apply time range filters before and after that incident. 

Check out the “How to use Timeline in Magnet AXIOM” video to see Timeline in action.  

You can validate what the Timeline is showing without having to dig through the file system to find the file. We do the heavy lifting while giving you quick access to the raw data.

Another one of the things about Timeline that our customers really love is the Relative Date/Time filter. This is incredibly helpful to quickly learn what happened leading up to an incident or likewise after it. You can anchor on a certain point in time when you know an incident occurred and then apply time range filters before and after that incident.

Connections: Visualize Relationships

When you’re working terabytes of data from many different sources, it can be difficult to piece together how artifacts, people, or even devices, all relate to each other. It can be even more difficult to find insights that help you move your investigation forward quickly. 

Connections helps you quickly find and visualize data across all your evidence sources and can shed light on evidence that may never have surfaced otherwise. For example, you can see how a specific picture file got on a device, how it was accessed, if it was shared and with who. 

Check out our blog, Letting Connections in Magnet AXIOM Work for You, to learn more about Connections and watch a brief how-to video to see it in action for yourself. 

Media Explorer: Categorize Media  

With Media Explorer, the goal is to provide an easy and intuitive way to cull images as you work through investigations, reducing the overall volume of media by filtering out known non-relevant content first. 

Media Explorer offers various filters that can quickly be used for just that.  

Whether investigators are working from leads they have from sources, such as when a suspected crime occurred, a specific location, or a specific camera model, we can use the various filters found under the Investigation Leads section to narrow the search.  

For example, when filtering based on items such as camera brand, you can find the camera and lens model and serial numbers.   

Attributes found within VICS hashsets such as Category and Categorization Source, VICS comments series, tags, Identified offenders and victims along with indicators for self-generated and distributed media. Additionally, filters for skin tone %, file size, media attributes such a filtering by extension type, recovery method or even file attributes found on particular file system’s like APFS and MIME type can help narrow results for examiners. Video attributes such as carved video file size, container format, content format and media duration provide even more opportunities for focusing on media files pertinent to the examination. 

Check out our blog to learn more about media categorization and the smart tools available to streamline the workflow of media-centric investigations. 

PORTABLE CASE: SHARE FINDINGS

Portable Case can be created by any AXIOM user to collaborate on a case with other stakeholders. Examiners can choose to include as much or as little digital evidence that has been acquired and recovered in a case to collaborate and review evidence with others.

If you want to dive deeper into Portable Case, you’re in luck! Check out this two-part blog series on Portable Case:

Want to try all the Analytics features—and more—in AXIOM for yourself? Request a free trial of Magnet AXIOM to get started today!

Holo, transparent letter M

Magnet News Delivered Straight to Your Inbox

Subscribe today to hear directly from Magnet Forensics on the latest product updates, industry trends, and company news.

Start modernizing your digital investigations today.

Ready to explore on your own? Start a Free Trial

Top