sleuthkit / autopsy

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.
http://www.sleuthkit.org/autopsy/
2.37k stars 592 forks source link

Detect Cloud Storage / Sync Apps #5952

Open bcarrier opened 4 years ago

bcarrier commented 4 years ago

We are going to add in rules to flag when cloud storage / sync apps are found. These will be rules in the Interesting Files module.

Here is our initial list of apps:

Adobe Creative Cloud Amazon Photo Backup Box Installer Carbonite Personal/PRO Carbonite Safe Server CloudMe DropBox Installer DropBox Windows App eFileCabinet GoodSync Google Drive (Backup and Sync) Google Stream (drive for business) iCloud Installer Win 7, 8 iCloud Windows App MEGA Privacy Windows App MEGAsync installer multi user MEGAsync installer single user nextCloud OneDrive Installer OneDrive Windows App OwnCloud pCloud Resilio Slack SpiderOak One SugarSync Sync Synqion (TeamDrive) Tresorit Yandex Disk Zoho Docs

These are in #5937. Please add comments to this issue if you want other apps flagged. Even better, submit the path that the app installs itself into so that we can make rules from it.

mikefitz80c commented 4 years ago

You could have a look at GigaTribe also

dkarpo commented 4 years ago

Can you please consider adding Seafile and Syncthing?

liamcs98 commented 3 years ago

Will this also include URL hits on these sites?

SkybuIIy commented 2 years ago

Hello @bcarrier ! I was wondering if there are any plans for/progress in development of this feature yet? If not I would be glad to take this on, though possibly not all of the apps. I'd be happy about any additional info you could give me on this project! Best regards

rcordovano commented 2 years ago

Hi @SkybuIIy, the Autopsy development team here at Basis Technology built the feature described by Brian Carrier. You can see the support we currently have by looking at the Interesting Files options panel:

image

Hope this helps!

bcarrier commented 2 years ago

If anyone puts the path for the program they wanted flagged, we can add it to the built-in rules.