Use “Add Hashes to Hash Set” button to copy and paste the following MD5 value into the “Ransom Case” hash set. This is the hash of the ransom note.
07c94320f4e41291f855d450f68c8c5b
The issue is “Add Hashes to Hash Set” button is inactivated, how to activate it?
Configure the Hash Lookup module with two hash sets:
Import the NSRL File (NSRLComplete.txt-md5.idx) that you previously downloaded in Section 1.
1. You may need to unzip the file you downloaded.
2. You can use the default values (i.e. Type: Known).
Create a New Hash Set:
* Destination: Local
* Name: Ransom Case
* Hash Set Path: [Any folder on your computer]
* Type: Notable
Use “Add Hashes to Hash Set” button to copy and paste the following MD5 value into the “Ransom Case” hash set. This is the hash of the ransom note.
07c94320f4e41291f855d450f68c8c5b
I ve done upto here.
now next step, how to Start the Ingest Module? please advice?
please help in
Observe:
Use Ingest Inbox as an indicator when ‘Known Bad’ hash hits are found.
Use “Go To Result” to go to tree area of hash hits.
View the hash hit.
Question : Let ingest get at least 15% through the drive. How many total hits are found under the “Hashset Hits” results after running the Hash Lookup Ingest Module?
Question : What are the filenames of the hash hits?
One of the hits is in a folder named “Pictures”. Right click on the file to “View” there.
Question : How many total “.jpg” files are in the folder “Pictures” where the notable hash hit was found?
While reviewing the images in that folder, it is noticed that “IMG_20191024_155744.jpg” shows health violations by bringing the dog into a restaurant. We want to tag this as Notable:
At this point you need to make a case, add a data source, and then run ingest. On the ingest panel, make sure you enable the Hash Lookup module along with the hash sets you created earlier.
I AM struck up at section 6 - Hash Look Up Module - Lab Steps. While I run the ingest as per instructions provided, it takes hours together but not able to run. I have wasted two days in trying this step but in vain. Can u please provide me solution as I am not able to complete the course because of this hurdle.
You have copied and pasted this message from the support ticket that you have opened, and we are working through it there. Please do not post the exact same thing, that we are providing you assistance on, in multiple places, as it creates more work trying to sort through tickets and support.
The injest activity in section 6 Lab is running very slow. How long does it normally take to finish if we follow the instructions as given? For me it is taking a lot of time.
-Regards, Rahul
I tried this even after cancelling the ingest, but still disabled for me. Do I need to run a full ingest, add the hash after completion, and do it again?