Join Craig Guymon, Director of Solution Consulting, to learn how to take advantage of AXIOM’s File System explorer in your investigations. In this Tips & Tricks webinar, Craig will review several powerful examination techniques that leverage the file system, including how to:
- Create an artifact from a file system file like an executable or log file that can be reported on from the Artifact Explorer
- Save artifacts from the file system to a zip container and keep artifact dates and times intact
- Effectively narrow down the scope of relevant user artifacts from the Artifact Explorer (View Related Artifacts)
- Use the database viewer and plist viewer in the Artifact Explorer
- Use the File system explorer to perform MD5/SHA1 value exports of known good files that can be used later as an “ignorable” list
After viewing this webinar you will be issued a certificate by email documenting that you have taken part in the session.