Autopsy User Documentation  4.5.0
Graphical digital forensics platform for The Sleuth Kit and other tools.
Encryption Detection Module

Overview

The Encryption Detection Module searches for files that could be encrypted using an entropy calculation.

Running the module

The module's settings can be configured at runtime.

encrypt_module.png

Minimum entropy can be set higher or lower, depending on how many false hits are being produced. There is also an option to only run the test on files whose size is a multiple of 512, which is useful for finding certain encryption algorithms.

Viewing results

Files that pass the test are shown in the Results tree under "Encryption Suspected".

encrypt_tree.png

Each hit also generates an inbox message. These are viewed through the warning triangle near the top of the screen.

encrypt_inbox.png

Selecting one of the encryption detection hits displays the calculated entropy of the file.

encrypt_entropy.png

Copyright © 2012-2016 Basis Technology. Generated on Sun Jan 21 2018
This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.