Section 7: Various Small Modules (File Type, Exif, etc.)

Hi, I am Ahmad Bappy.
In section 7: Lab steps, I couldn’t find these given below. I finished the full scan though.please help.

2.From the “Views” area, find the 7z file that is named “Archive.zip”.

  1. Go to original directory (Right click -> View File In Directory).
  2. Double click on it to go into it.
  3. Question : What is the MIME type listed for the file “D3D11_Default.shader-db.bin”?
  4. Question : What is the file size for the file “D3D11_Default.shader-db.bin”?”

Hello,

If you are not seeing results, did you do the pre-requisite steps listed in Section 6?

Disable all modules except the following (we will pre-load some for the next lap):

  1. Hash Lookup
  2. File Type Identification
  3. Extension Mismatch Detector
  4. Embedded File Extractor
  5. Exif Parser
  6. Email Parser
  7. Correlation Engine

If you did that and are not seeing results, try closing Autopsy and opening it again, your UI may not be refreshing properly.

Thank you

I did prerequisite steps in section 6. After that i had closed autopsy and the very next day i opened autopsy again. Performed 100% scan. Fillup frst step of section 7 lab. Bt after that i couldn’t find step 2 any where in the UI. And mostly i couldn’t understand what to do now.

If everything ran, and you have the data to go through, the next steps are (remember, these are two separate things you must do)

2.From the “Views” area, find the 7z file that is named “Archive.zip”. (This is in the Autopsy UI, on the left side)

  1. Go to original directory (Right click → View File In Directory).

  2. Double click on it to go into it.

  3. Question : What is the MIME type listed for the file “D3D11_Default.shader-db.bin”?

  4. Question : What is the file size for the file “D3D11_Default.shader-db.bin”?”

(Without giving any answers to you, you have a file name, so maybe you could do a search for the file name, and find the MIME type and file size.)

How to perform both of these tasks are covered in the video for that section, if you are still having issues we suggest watching the video again.

Thank you

Hi Brian
the exif is not in the preload module. Am currently running 4.17.0 L.E. bundle.
it does show exif module. how do i get that into the module.
NGM

EXIF was renamed Picture Analyzer.

yes. thank you. I did a little digging around and realize it change to Picture Analyzer. Lol as always thank you…:slight_smile: