AX200 Axiom Examination

Descripción

Magnet Axiom Examinations (AX200) is ideal for those who need intermediate-level training on a digital investigation platform covering cases involving smartphones, tablets, computers, and cloud data, all within a single collaborative interface.
This course is the perfect starting point for examiners who are new to Axiom.

Description
Magnet Axiom Examinations (AX200) is ideal for those who need intermediate-level training on a digital investigation platform that covers cases involving smartphones, tablets, computers, and cloud data, all within a single collaborative interface.
This course is the perfect starting point for examiners who are new to Axiom.

What to Expect
Hear directly from Danny Norris, forensic instructor at Magnet Forensics, about how he brings his field experience into the classroom and how AX200 can help you make the most of your potential when working with computer forensics tools.

Course Requirements
None.


Course Objectives

Module 1: Introduction and Installation of Magnet Axiom

The learning objectives and expected outcomes throughout the four days of the course will be presented.
Hands-on exercises will allow you to install Magnet Axiom and learn about its components: Axiom Process and Axiom Examine.

Module 2: Evidence Processing and Case Creation

All Axiom Process settings will be reviewed to maximize efficiency during processing and reduce times.
The collection from various evidence sources such as hard drives, USB, cloud data, and mobile devices will be explained and demonstrated.
Practical exercises will include:

  • add keywords,
  • choose encodings (ASCII, Unicode…),
  • use of hashing and hash types (NSRL, Project VIC/CAID, gold-build),
  • OCR and Magnet.AI,
  • enable/disable artifacts to speed up processing.

By the end, students will be able to acquire forensic images, configure global and specific options, and create a case to analyze in Axiom Examine.

Module 3: Operating System Artifacts – Part 1

Focus on OS artifacts recovered from the Windows Registry.
Use of the Registry and Timeline explorers to validate artifacts.
You will learn to obtain key system information:

  • operating system information,
  • file system,
  • user accounts,
  • installed applications.

Module 4: Encryption / Anti-forensics

Importance of identifying encryption and anti-forensic tools.
Use of encryption plugins in Axiom Process to identify, decrypt, and process additional evidence in an existing case.

Module 5: Refined Results

Refined Results consolidate key artifacts into easy-to-review subcategories.
Example: all Google searches, regardless of browser.
You will also learn to:

  • create suspect and victim profiles,
  • use basic and advanced filters,
  • save filters for future cases.

Module 6: Web Artifacts

Analysis of how browsers (Chrome, Firefox, Edge) store history, favorites, and bookmarks.
Review of autocomplete and previous searches.

Module 7: Communications

Recovery of emails and attachments.
Filtering, labeling, and analysis of headers.
Use of the Connections Explorer to connect key pieces of evidence.
Export of emails in multiple formats.
On Android, how SMS/MMS are stored in SQLite using a conversational view will be reviewed.

Module 8: Documents

Review of different view types and metadata.
Export of documents from Axiom.
Use of filters, searches, and OCR to make PDFs and images fully searchable.

Module 9: Operating System Artifacts – Part 2

Continuation of OS artifact analysis such as:

  • LNK files,
  • USB devices,
  • UserAssist,
  • Jump Lists, among others.

Module 10: Media (Photos and Videos)

Review of image and video artifacts.
Use of filmstrip-type views and thumbnails.
EXIF, geolocation, camera model, etc.
Officer Wellness function and classification for illicit image cases.
Use of Magnet.AI for automatic categorization.
Introduction to the Media Explorer for advanced searches and duplicate detection.

Module 11: Cloud

Importance of understanding artifacts left in the cloud.
Review of Axiom's capabilities to collect and analyze cloud data.
Combination of computer, mobile, and cloud data within a single case.

Module 12: Reports

Exploration of export and reporting functions in Axiom Examine.
Creation of portable cases, final reports, and configuration of the report wizard to maintain standardized formats.


Additional Information

Who should attend: Participants with no prior computer forensics experience.
Preparation: None.
Program level: Intermediate.
Area: Computer software and applications.
Modality: In-person group.