Updated domain discovery documentation.

This commit is contained in:
apriestman 2021-01-20 13:31:27 -05:00
parent b50c4010fa
commit 7fae66bb37
5 changed files with 17 additions and 1 deletions

View File

@ -124,6 +124,18 @@ When there are multiple path options in the filter, they will be applied as foll
This allows you to, for example, make rules to include both the "My Documents" and the "My Pictures" folders.
\subsubsection file_disc_prev_notable_filter Previously Notable Filter
The previously notable filter is for domain searches only and is used to restrict results to only those domains that have previously been marked as "Notable" in the \ref central_repo_page.
\image html FileDiscovery/fd_notableFilter.png
\subsubsection file_disc_known_account_filter Known Account Type Filter
The previously notable filter is for domain searches only and is used to restrict results to only those domains that have a known account type.
\image html FileDiscovery/fd_knownAccountFilter.png
\subsubsection file_disc_result_filter Result Type Filter
The result type filter is for domain searches only and can be used to restrict which types of web results the domains can come from.
@ -158,7 +170,7 @@ The last grouping and sorting option is choosing how to sort the results within
\subsection file_disc_results_overview Overview
Once you select your options and click "Search", you'll see a new window with the list of groups on the left side. Selecting one of these groups will display the results from that group on the right side. For image, video, and document searches, selecting a result will cause a panel to rise showing more details about each instance of that result. You can manually raise and lower this panel using the large arrows on the right side of the divider. This panel is disabled for domain searches.
Once you select your options and click "Search", you'll see a new window with the list of groups on the left side. Selecting one of these groups will display the results from that group on the right side. Selecting a result will cause a panel to rise showing more details about each instance of that result. You can manually raise and lower this panel using the large arrows on the right side of the divider.
If your results are images, you'll see thumbnails for each image in the top area of the right panel.
@ -182,6 +194,10 @@ For image, video, and document searches, when you select a result from the top o
The bottom section of the panel is identical to the standard \ref content_viewer_page and displays data corresponding to the file instance selected in the middle of the panel.
For domain searches, when you select a domain in the top of the right panel you'll see a details area that is a variation on the \ref content_viewer_page. The first tab on details panel displays a simple timeline - selecting a date will show all the results from that date in the center of the panel, with details for the selected result on the right. The other tabs (Web Bookmarks, Web Cookies, etc.) display results of the selected type with a list of results on the left and more details on the right. You can right-click on results to use most of options available in the normal \ref result_viewer_page.
\image html FileDiscovery/fd_domainDetails.png
\subsection file_disc_dedupe De-duplication
This section only applies to image, video and document searches.

Binary file not shown.

After

Width:  |  Height:  |  Size: 50 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 59 KiB

After

Width:  |  Height:  |  Size: 70 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.0 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.8 KiB