EDetective Forensic Analysis Tool Prototype GUI - PowerPoint PPT Presentation

1 / 13
About This Presentation
Title:

EDetective Forensic Analysis Tool Prototype GUI

Description:

Manually import raw data file into ED Centralized Server System for reconstruction ... Recorded data type Listed by source and destination IP connection information ... – PowerPoint PPT presentation

Number of Views:50
Avg rating:3.0/5.0
Slides: 14
Provided by: Deci5
Category:

less

Transcript and Presenter's Notes

Title: EDetective Forensic Analysis Tool Prototype GUI


1
E-Detective Forensic Analysis ToolPrototype GUI
  • Decision Computer Group of Company
  • Website www.edecision4u.com
  • Email decision_at_decision.com.tw

2
Application Diagram
1
2
Raw Data file in PCAP format
Internet Traffic
Manually import raw data file into ED Centralized
Server System for reconstruction
Different sources and tools used for capturing
Internet Raw Data
3
Using E-Detective Forensic Analysis tool for
analyzing
5
E-Detective Centralized Server System
4
Creation of Intermediate file
Download to users PC
3
E-Detective Forensic Analysis Tool Homepage
Reporting function
Special search tool
Display of recorded results
Display of recorded data according to different
applications
Filter rules condition section
Content display from recorded data
4
Selection of Application/Service Type
Recorded data type Listed by Internet
Application/Service type
Display of records
Recorded data type Listed by source and
destination IP connection information
5
View Captured Records (List of Reconstructed
Data Records)
Display and list of recorded data with basic
record information
Selection of Application Type
6
View Captured Records (List of Reconstructed
Files Records)
Display and list of recorded and reconstructed
data file
7
View Captured Records (List of Connection
Records)
Display and list of connection records
8
Display Captured Content Record (Original
Content Display)
Display specific captured application record
content
Display by plain text, picture/image and HEX
9
Display Captured Content Record (Packet
Connection Info)
Display of specific application record packets
connection information
10
Display Captured Content Record
(Files/Attachment Content)
Display captured record file/attachment content
11
Filter Rules Condition (Pre-defined Filter Script)
Able to use JavaScript to define filter script
Filtered Condition Display Section
12
Filter Rules Condition (Pre-defined Filter)
For example to search for records with text
only, executable file only etc.
13
Filter Rules Condition (Conditional Rules)
Filter by Condition
Write a Comment
User Comments (0)
About PowerShow.com