Viewing results of Bulk_extractor

To view the output of and findings by bulk_extractor, we can also display a list of directories within the Terminal by typing ls -l. We can see that the bulk_output folder has been created by bulk_extractor:

We can now list the contents of our output folder (bulk_output) by typing ls -l bulk_output:

The list has been split in two to show some of the artifacts found by bulk_extractor:

It should be noted that not all listed text files will contain data. Only the ones with numbers larger than 0 to the left of the text filenames will actually contain data.

The text file ccn.txt is an abbreviation for credit card numbers and will contain credit card information that may have been stolen, illegally used, or stored with possible intention to commit credit card fraud.

If we browse to the output folder location, we can view all extracted data within the individual text files. Viewing the telephone_histogram.txt file reveals telephone numbers:

The url.txt file reveals many websites and links visited:

While this was a simple exercise done with a small evidence file, be sure to have a look at the many others available at http://digitalcorpora.org/ and see what bulk_extractor reveals. Try downloading as many of the images as possible if your bandwidth and storage permit, and also use the other tools we'll use in other chapters.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset