Getting Started with Magnet AXIOM Examine - Search and Filters

Magnet Forensics
1 Jun 201808:28

Summary

TLDRIn this Magnet Forensics tutorial, Jimmy McQuaid introduces viewers to the powerful search and filtering capabilities of Magnet Axiom. He demonstrates how to apply global and column filters to streamline case analysis, highlighting the tool's unique ability to separate and filter date and time stamps. The video also covers keyword searches across various data types, showcasing the speed and efficiency of Axiom's indexed search feature. McQuaid concludes with a quick guide on setting up keyword lists for both pre- and post-processing stages.

Takeaways

  • 🔍 The video is a tutorial on using Magnet Axiom, focusing on searching and filtering evidence within a case.
  • 📊 Filters in Axiom are categorized into global filters and column filters, each serving different scopes within the case.
  • 🔎 Column filters are applied within specific artifacts and columns, allowing for targeted searches based on column content.
  • 🗂️ Global filters apply across the entire case, not limited to a single artifact or column, and include evidence sources, artifacts, and content types.
  • ⏰ A unique feature of Axiom is the separation of date and time in filters, enabling more precise searches based on these parameters.
  • 📅 The video demonstrates how to filter evidence based on business hours, such as Monday to Friday, 9:00 AM to 5:00 PM.
  • 🔑 Keyword searches can be performed quickly due to indexing during the processing of artifacts, which speeds up the search without a full disk index.
  • 📚 The tutorial shows how to apply multiple filters and keyword searches simultaneously, narrowing down the evidence efficiently.
  • 🖥️ Axiom allows for keyword searches and filtering on the file system and registry, with options for recursive searches in folders.
  • 🔑 The video explains how to use keyword lists for advanced searching, including the ability to combine multiple lists for 'OR' searches.
  • 🛠️ The tutorial concludes with a reminder that keyword lists can be set up during or after processing, enhancing the search capabilities in Axiom.

Q & A

  • What is the main focus of the video by Jimmy McQuaid from Magnet Forensics?

    -The main focus of the video is to help users get started with Magnet Axiom, specifically discussing searching and filtering in Axiom Examined.

  • What are the two main categories of filters mentioned in the video?

    -The two main categories of filters mentioned are global filters and column filters.

  • How does the column filter work in Axiom Examined?

    -The column filter allows users to filter data within a specific artifact and column by right-clicking and applying a search term to that column.

  • What is a global filter in the context of Magnet Axiom?

    -A global filter in Magnet Axiom applies to the entire case, not just a specific artifact or column, and can filter based on evidence, artifacts, content types, and other case-wide criteria.

  • How does Magnet Axiom handle date and time filtering?

    -Magnet Axiom splits up the date and time and stores them separately, allowing users to filter with the date or time independently, which is unique compared to most tools.

  • What is the benefit of filtering by 'business hours' in a case?

    -Filtering by 'business hours' allows users to focus on data relevant to specific time periods, such as weekdays from 9:00 to 5:00, which can be particularly useful in corporate cases or understanding user activity during typical working hours.

  • How can users apply multiple filters in Magnet Axiom?

    -Users can stack filters by applying them one after another, with each additional filter narrowing down the results based on the previous filters, effectively applying an 'and' operation between them.

  • What is the significance of indexing during the processing in Magnet Axiom?

    -Indexing during the processing in Magnet Axiom allows for quick keyword searches by indexing all artifacts, which adds minimal overhead but significantly speeds up the search process compared to a full disk index.

  • How can users perform keyword searches on the file system and registry in Axiom Examined?

    -Users can perform keyword searches on the file system and registry by navigating to those sections and using the search term feature, with the option to conduct a recursive search across all subfolders for a more comprehensive result.

  • What is the purpose of using keyword lists in Magnet Axiom?

    -Keyword lists in Magnet Axiom allow users to import and search for multiple keywords simultaneously, which can be particularly useful for targeted investigations or when specific terms need to be flagged or analyzed.

  • How does the quick search feature differ from a keyword list search in Magnet Axiom?

    -The quick search feature in Magnet Axiom adds an 'and' operator between keywords, while keyword list searches treat each keyword as an 'or' search, allowing for broader or more specific searches depending on the user's needs.

Outlines

00:00

🔍 Introduction to Searching and Filtering in Magnet Axiom

Jimmy McQuaid from Magnet Forensics introduces a tutorial video on using Magnet Axiom, focusing on searching and filtering functionalities. The video demonstrates how to apply filters to evidence items within a case. Filters are categorized into global filters, which apply to the entire case, and column filters, which are specific to individual artifacts and columns. The tutorial shows how to use column filters to search for specific terms like 'how to' within Google searches and how to apply date/time filters to narrow down evidence based on timestamps. The video also explains how global filters can be used to filter evidence by source, artifacts, content types, and other criteria. A unique feature of Magnet Axiom is its ability to separate date and time in filters, allowing for more precise queries, such as filtering for business hours on weekdays.

05:02

🚀 Advanced Filtering and Keyword Searches in Magnet Axiom

This section of the video script delves into advanced filtering techniques and keyword searches within Magnet Axiom. It highlights the speed of keyword searches due to the indexing of artifacts during the processing stage, which is efficient and quicker than a full disk index. The video shows how to apply filters and keyword searches to various data types, including documents, emails, and chats. It also discusses the use of keyword lists for complex searches and the ability to stack filters for more refined results. Additionally, the script covers how to conduct keyword searches on the file system and registry, with options for recursive searches and the use of the F3 key to navigate between keyword hits. The video concludes with a brief mention of setting up keyword lists during processing and a thank you note to viewers.

Mindmap

Keywords

💡Magnet Axiom

Magnet Axiom is a digital forensics platform designed to help investigators analyze large volumes of data efficiently. In the video, it is the central tool being discussed, with the presenter, Jimmy McQuaid, demonstrating how to use its various features for searching and filtering evidence within a case.

💡Global Filters

Global filters are a type of filter in Magnet Axiom that apply across the entire case, not just to a specific artifact or column. They are used to narrow down the data set based on criteria such as evidence source, artifacts, content types, and more. The script mentions global filters as a way to apply broad criteria to the entire case, such as filtering by evidence source like a 'Windows 10 computer' or 'Samsung J7 phone'.

💡Column Filters

Column filters are specific to a single artifact and column within Magnet Axiom. They allow users to filter data based on the content of a particular column, such as searching for a specific term within 'Google searches' or setting a date/time range. The video script illustrates this by showing how to apply a filter to show only 'how-to' search terms in Google search results.

💡Artifacts

In the context of Magnet Axiom, artifacts refer to the digital evidence items that are analyzed within a case. They can be filtered by category or individually, and the video demonstrates how to apply filters to specific artifacts, such as filtering by 'Google searches' artifact to find specific search terms.

💡Date/Time Filtering

Date/time filtering is a feature in Magnet Axiom that allows users to set a range for when data was created or modified. The video highlights the unique capability of Magnet Axiom to separate date and time, enabling precise filtering, such as showing data only from 'Monday to Friday, 9:00 to 5:00'.

💡Keyword Searches

Keyword searches are a method of finding specific terms or phrases within the data. The video script describes how to perform quick keyword searches across the case and how these searches can be combined with other filters for more targeted results, such as searching for 'how to' in conjunction with specific time filters.

💡Indexing

Indexing in Magnet Axiom refers to the process of creating a searchable database of artifacts during the processing stage, which speeds up subsequent searches. The video emphasizes the efficiency of this feature, noting that it is faster than a full disk index and allows for quick keyword searches, as demonstrated when searching for 'how to' across various data types.

💡File System

The file system in Magnet Axiom represents the structured hierarchy of files and folders on a device. The video script explains how to perform keyword searches and apply filters within the file system, such as searching for a specific file path or conducting a recursive search across all subfolders.

💡Registry

The registry in Magnet Axiom is a database that stores configuration settings and options on Windows systems. The video demonstrates how to perform keyword searches within the registry, which is crucial for finding specific configuration settings or user preferences.

💡Keyword Lists

Keyword lists in Magnet Axiom are collections of terms used for searching and filtering data. The video script explains how to create and import keyword lists for more complex searches, such as using 'OR' conditions to find data that matches any term in the list, which is demonstrated by adding keywords under 'keyword lists' for an 'OR' search.

💡Evidence

Evidence in the context of Magnet Axiom refers to the data sources that are being analyzed, such as computers, phones, and other digital devices. The video script discusses how global filters can be applied to filter evidence by source, which is essential for managing and analyzing data from multiple sources within a case.

Highlights

Introduction to Magnet Axiom and its capabilities for searching and filtering in digital forensics.

Explanation of global filters and their application across the entire case.

Demonstration of column filters within individual artifacts.

Tutorial on applying filters to specific columns such as search terms and date/time.

Example of filtering Google searches for the term 'how to'.

Discussion on the flexibility of column filters to accommodate different data types.

Overview of global filters including evidence, artifacts, and content types.

Unique feature of Axiom's date and time filtering, allowing separate date and time ranges.

Practical example of filtering for business hours to narrow down case evidence.

Capability to stack filters for more precise searching within a case.

Quick keyword search demonstration across various types of evidence.

Highlighting of search results within documents and emails for the keyword 'how to'.

Efficiency of Axiom's indexing during processing for fast keyword searching.

Introduction to keyword lists and their use in advanced searches.

Guide on conducting keyword searches in the file system and registry.

Use of the F3 key to navigate between multiple keyword hits in a search.

Setting up keyword lists during or after processing for enhanced searching.

Conclusion and thanks for watching the tutorial on Magnet Axiom.

Transcripts

play00:04

hello everyone my name is Jimmy McQuaid

play00:07

from magnet forensics and today we've

play00:08

got another video to help you get

play00:09

started with magnet axiom in this video

play00:12

we're gonna talk about searching and

play00:13

filtering in axiom examined so I've got

play00:16

a case already up here ready to go

play00:19

axiom examines open with a case a bunch

play00:21

of evidence items and we're gonna talk

play00:23

about searching and filtering now you

play00:25

can break down our our filters into two

play00:27

main categories global filters which are

play00:30

up here across the top and call them

play00:32

filters which are inside each artifact

play00:34

in apply to each column so column filter

play00:37

is pretty straightforward you're in

play00:39

where in the Google searches artifact

play00:40

here you could filter on any of these

play00:43

columns by right clicking this is for

play00:46

the search term I can say filter on

play00:47

column and I can apply that search term

play00:49

so I'm gonna use maybe the word how to

play00:51

because I think there's a bunch of

play00:52

searches for how to and we can see it

play00:55

applies a filter on just the how-to so

play00:58

you get hits for how to in all the

play01:00

Google searches now these are specific

play01:01

to the single artifact for that single

play01:03

column and you can continue to add other

play01:05

filters and those filters are specific

play01:08

to what the content in the in the each

play01:11

column so the the search term obviously

play01:13

it's a string the date/time is a

play01:15

timestamp so if I filter on that it'll

play01:17

allow you to set a date and time range

play01:19

so depending on what type of data is in

play01:21

each column or each field you can filter

play01:24

independent of that so that's how the

play01:27

column filters work and if I remove that

play01:29

you can see it goes back to the full set

play01:32

and we're back to square one again

play01:34

now the global filters similar but that

play01:38

applies to the entire case so not just

play01:40

Google searches not just the specific

play01:42

column it applies to everything so the

play01:44

first one evidence so this is pretty

play01:46

obvious it'll filter on the source

play01:47

evidence and as you can see in this case

play01:49

I have a whole bunch of evidence sources

play01:51

loaded into this one a Windows 10

play01:52

computer samsung j7 phone a ram capture

play01:57

for the computer a USB device and an

play01:59

iPhone so I could filter on any one of

play02:01

these very easily you could also filter

play02:03

on the artifacts either by category or

play02:05

individual artifacts or you could do it

play02:08

by content types

play02:09

these are common things like URLs

play02:11

anything that has

play02:12

a user ID name picture video or anything

play02:15

like that even items that are accessible

play02:18

or inaccessible by the users that's

play02:20

dictated based on the source so if the

play02:22

user can access it natively through

play02:24

Windows it's accessible if they can't

play02:26

access it if it's the leader or we had

play02:27

to do something special forensic lis to

play02:29

get to it it's inaccessible still on the

play02:32

computer but inaccessible to to the

play02:34

native viewer they might have deleted it

play02:36

and it's it's an unallocated space or

play02:37

something like that

play02:38

my favorite date and time so you can

play02:41

filter on the date and time and axioms

play02:43

really nice and unique in the way that

play02:45

um most tools when when you parse out

play02:48

time stamps the date and time is stored

play02:51

together axiom when it processes it

play02:53

splits up the date and time and stores

play02:55

them separately so you can actually do

play02:57

filters with the date or time

play02:59

independent of each other so where most

play03:02

tools you can you can sit there and say

play03:03

show me everything 7:00 to 10:00 p.m.

play03:04

last night great you can do that with

play03:07

axiom but with with this you can you can

play03:09

actually filter out and say show me

play03:12

based on a schedule maybe it's a it's a

play03:14

corporate case and you want to say ok I

play03:17

only care what he was doing at work or

play03:18

if you know your users schedule or

play03:20

anything like that so I can create a

play03:22

filter like this one and say go to

play03:24

weekdays only Monday to Friday and if I

play03:27

go down I can choose you can customize

play03:29

the time range but you can say business

play03:31

hours 9:00 to 5:00 and you can specify

play03:33

anything you want but we'll just use the

play03:34

default one there and hit go and now

play03:36

this will actually filter out everything

play03:39

in the case and now we're down to if I

play03:41

look at everything 31,000 artifacts or

play03:44

so that's 31,000 out of four hundred and

play03:46

sixteen thousand so there's only 31,000

play03:49

that have timestamps Monday to Friday

play03:51

9:00 to 5:00 and you can see the filters

play03:53

applied across the top there which is

play03:55

great and you can continue to add other

play03:56

filters you can filter based on tags you

play03:58

might have applied some tags before any

play04:01

profiles you built out results keywords

play04:04

if you added a keyword list you can

play04:05

filter on the keyword lists skin tone

play04:07

filter for pictures or media

play04:09

categorization so I if you're doing

play04:11

Child Exploitation cases that have media

play04:14

categorizations already applied you can

play04:16

filter on those as well but you can

play04:18

stack these filters as well and it

play04:20

basically applies an and two to any of

play04:22

these so we've got Monday to Friday 9:00

play04:24

to 5:00 and if I want to do

play04:25

same keyword search for how to I can

play04:27

just do how to and hit go and it'll

play04:31

apply a keyword search to that as well

play04:33

so now we've got the quick keyword

play04:35

search to it as well as the the other

play04:37

filter and that gets stocked up there

play04:39

and now we're down to 51 hits you got

play04:40

some Google searches we've got some

play04:42

Safari hits here so you can see the

play04:44

Safari ones you can see it's highlighted

play04:46

the word how-to in the title we've got

play04:48

some emails here so there's some Android

play04:51

Gmail's with this user and if I take a

play04:54

look it should have it highlighted in

play04:56

the actual email let me just see if I go

play04:59

there it is just about missed it there

play05:02

it is right there how to break it I

play05:04

don't know for whatever but basically

play05:06

there it is highlighted in the dot and

play05:08

the the email same thing goes if it's a

play05:10

document we've got just a intell

play05:13

document here nothing super special you

play05:14

can preview the document here or we can

play05:17

go down and we can start looking through

play05:19

and seeing if we can find that keyword

play05:22

oh there it is so there's the

play05:23

highlighted keyword in that document and

play05:25

you can see that that was a very quick

play05:27

keyword search you go through it it

play05:29

found everything within documents emails

play05:31

a Google searches chats whatever it

play05:34

searches through it'll find that keyword

play05:36

in there and you might have noticed how

play05:37

fast that was the reason being is we

play05:39

actually index during the processing

play05:41

index all of the artifacts for your case

play05:43

it's better than a full index because a

play05:45

full disk index will take a long time it

play05:47

can take several hours but we basically

play05:49

just index anything that's an artifact

play05:51

it adds minimal overhead but still gets

play05:53

you the majority of what you need for

play05:55

your investigation it's a really nice

play05:56

feature and you can see how quick that

play05:58

the keyword search applies along with

play06:01

the the filter that we applied there so

play06:04

I can clear those filters go back to the

play06:06

top here and we're back to to square one

play06:08

on the entire case now any keywords that

play06:12

you add here in the quick search are

play06:14

Anne's

play06:15

so you can say how to and something else

play06:18

it's there all and so as you add

play06:19

keywords on the quick search it always

play06:21

adds an and operator to it now if you

play06:23

wanted to add an or and say hey I want

play06:25

to do this one or this one or this one

play06:27

you would add it under keyword lists you

play06:29

can import a keyword list there and you

play06:31

can import a whole bunch of them say

play06:33

this one this one or this one and those

play06:35

would actually come in as an

play06:36

or keyword search now you can also do

play06:39

keyword searches and and filtering on

play06:42

the file system and registry side so if

play06:44

I move from the artifacts and we go to

play06:45

file system you can sit there and take a

play06:48

look at where in the file system you can

play06:50

run filters based on date and time file

play06:52

size attributes a tags and comments

play06:55

again very good there or you can do a

play06:57

quick search as well now the search is

play06:59

relative to what's in the evidence pane

play07:01

so if I let's say I go to this Windows

play07:03

10 PC go to partition 3 and users and

play07:07

now I've got the administer I'll go into

play07:11

the min profile now I could do a search

play07:14

for and to user dot and would come up

play07:16

here based on the the quick search on

play07:18

the file path however if I want to

play07:20

search every subfolder do a recursive

play07:22

search across everything in here I would

play07:25

want to flip over change from selected

play07:27

folder only to all subfolders this gives

play07:29

me a recursive view of all the

play07:31

subfolders under the user admins profile

play07:34

here so now I see everything and then I

play07:36

can conduct that keyword search so it's

play07:38

important to understand the difference

play07:39

between doing the recursive one or just

play07:43

the the parent folder as as it stands in

play07:47

addition if I move over to the registry

play07:50

you can also do keyword searches in the

play07:52

registry right here search term you type

play07:54

it in and it would give you your

play07:56

keywords now for this one if you get

play07:58

multiple keyword hits you can just hit

play07:59

the f3 button and it will move on to the

play08:01

next one so just you can hit f3 and it

play08:04

moves on to the next keyword hit each

play08:05

time so lots of ways to do keyword

play08:07

searches in axiom if I jump back to the

play08:11

start we've already mentioned during

play08:13

processing you can set up keyword lists

play08:15

before this is how you would do it

play08:16

afterwards both work really well that's

play08:19

everything I wanted to show for this

play08:21

video thanks for watching bye bye

play08:25

you

Rate This

5.0 / 5 (0 votes)

関連タグ
Digital ForensicsMagnet AxiomKeyword SearchData FilteringEvidence AnalysisCase ManagementForensic ToolsInvestigation TechniquesSearch TechniquesFiltering Tutorial
英語で要約が必要ですか?