Difference between revisions of "Easy Button Load"

From truxwiki.com
Jump to navigation Jump to search
Line 28: Line 28:
  
 
=The Details=
 
=The Details=
 +
Easy Button was designed so you don't need the Truxton application in order to look at the data Truxton processed.
 +
All you need is a browser.
 +
 
When you Easy Button Load a folder, a new top level folder will be created on the drive of the folder you are loading.
 
When you Easy Button Load a folder, a new top level folder will be created on the drive of the folder you are loading.
 
It will be called "Truxton Results" and will contain a folder with the same name as the one you loaded.
 
It will be called "Truxton Results" and will contain a folder with the same name as the one you loaded.

Revision as of 16:24, 20 January 2022

An Easy Button Load is a way to have Truxton perform processing on an external drive. Everything that Truxton does is put on that drive.

Operating Scenario

Easy Button Load assumes several things:

  1. You have forensically collected your media
  2. You have created a top level folder on an external drive
  3. You have copied the media to that folder
  4. There is room on the external drive to hold Truxton
  5. In File Explorer, you right button on your top level folder on the external drive and select "Easy Button Load into Truxton"
  6. When Truxton completes...
  7. You run the Desktop GUI to peruse the data
  8. When you are finished, you go to File Explorer, right button on any folder and select "Easy Button Reset"
  9. You give the external drive to someone else
  10. They attach it to their machine, right button on XXX and select "Use This Truxton Database"
  11. When they are done, they "Easy Button Reset"

Sample Folder Structure

Let's say we have collected a hard drive, an SD card and a UFED dump of a phone. You attached a Samsung T7 external drive, created a top level folder on that drive named "Collection 1" and copied the data to it. For the rest of this article we will assume the external drive is drive letter D. The drive contains the following:

D:\Collection 1\PC1\PC1.E01
D:\Collection 1\SD1\SDCard.E01
D:\Collection 1\Phone\Report.xml

The Details

Easy Button was designed so you don't need the Truxton application in order to look at the data Truxton processed. All you need is a browser.

When you Easy Button Load a folder, a new top level folder will be created on the drive of the folder you are loading. It will be called "Truxton Results" and will contain a folder with the same name as the one you loaded. For sample in this article, it will be called "D:\Truxton Results\Collection 1" In this folder, you will see a file named "Reports.html" Opening that file in a browser will show you links to the Investigation level reports as well as the reports for each piece of media loaded. The two report types generated are the Consolidated Contacts report and the Summary report. You will also notice two folders in "D:\Truxton Results\Collection 1" named "Processing" and "Reports"

The Reports Folder

The "D:\Truxton Results\Collection 1\Reports" folder will contain an "Everything" folder and one folder for each media in the investigation.

Everything

This folder ("D:\Truxton Results\Collection 1\Reports\Everything") contains:

  • Contacts.zip - This contains the Consolidated Contacts HTML report for the investigation with supporting files
  • Geographic Information.kmz - This contains all of the geographic coordinates from the media in the investigation
  • Investigation Summary.zip - This contains the Investigation Summary HTML report and supporting files
  • Investigation.tpif - The database records for all media in the investigation. This is used to import this investigation into someone else's Truxton.
  • Unique Artifacts.xlsx - An Excel spreadsheet containing all of the unique artifacts from the media

PC1

This folder ("D:\Truxton Results\Collection 1\Reports\PC1") contains:

  • Contacts.zip - This contains the Consolidated Contacts HTML report for this media with supporting files
  • Geographic Information.kmz - This contains all of the geographic coordinates from this media
  • Investigation Summary.zip - This contains the Media Summary HTML report and supporting files
  • Unique Artifacts.xlsx - An Excel spreadsheet containing all of the unique artifacts from this media