• We just launched and are currently in beta. Join us as we build and grow the community.

How to Collect Forensics Evidence of PC using P2 Commander (Part 1)

sinned1

Blockchain Integration Engineer
S Rep
0
0
0
Rep
0
S Vouches
0
0
0
Vouches
0
Posts
120
Likes
197
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 400 XP
P2C is a comprehensive digital investigation tool with over ten years of court-approved use by forensic examiners. An integrated database and true multi-threading mean faster processing. P2C was built on Paraben’s trusted email examination tools for unparalleled network email and personal email archive analysis. Advanced features like Data Triage analysis, Xbox analysis, pornography detection.

First Download the p2 commander from here and install in victim pc and open p2 commander Click New Case the ‘Create a New Case’ page will open

1.png


Then click on next to proceed to next step.

2.png


Here in next step you have to enter the case name and DEMO details and click on finish to proceed to next step

3.png


Here in next step you have to enter the Investigator name and email details and click on finish to proceed to next step

4.png


Now Click ‘Add Evidence’->Choose ‘Image File’

Now select Auto-detect Image option from source type which will add the image evidence in any format. You can choose any option from different available options such as Drive Image or Fat Partition Image.

5.png


Now load the Evidence Disk Image

How to create Disk Image read this article

http://www.hackingarticles.in/how-to-create-copy-of-suspects-evidence-using-ftk-imager/

After selecting the evidence Image, click on Open.

6.png


Now you will see the case Demo is created, which will show you the hierarchy of the directories of the evidence image.

7.png


Now you can click on any one of the directories of the evidence image and it will show you all the containing files and sub folders within that folder describing their file name, file type, file size, creation time and last modification etc.

8.png


Now click on generate report tab.

9.png


Select the report type which is to be generated. In my case I am selecting HTML Investigative Report & select the destination folder. Then click on next.

10.png


Now select the sorted file which is to be added by clicking on Add and Export button with their file types. Now click on next to proceed further.

11.png


Now click on Finish to proceed to next step.

12.png


The report file will be saved on your destination folder. Now you will visualize the details of your report.

13.png


Author:
Mukul Mohan
is a Microsoft Certified system engineer in security and messaging .He is a Microsoft Certified Technology Specialist with high level of expertise in handling server side operations based on windows platform. An experienced IT Technical Trainer with over 20 years’ Technical Training experience you can contact him at [email protected]
 

440,010

316,559

316,568

Top