Autopsy
Open source digital forensics platform built on The Sleuth Kit, for analyzing disk images through a graphical interface.
When I Use It
- Full analysis of a disk image when I need to browse the file system, recover deleted files, and search across everything
- Building a timeline of file activity on a system
- Cases where a GUI is faster than chaining command line tools, or where I need to show findings to someone else
Installation
Common Tasks
| Task |
Steps |
| Start a case |
Case -> New Case -> name and folder -> Add Data Source |
| Add evidence |
Disk image (E01, raw/dd), local disk, logical files, or virtual machine disk |
| Run analysis |
Choose ingest modules when adding the data source |
| Search |
Keyword Search panel, using exact match, substring, or regular expressions |
| Review results |
The tree on the left: Views (by file type, date), Results (keyword hits, hash hits, interesting items), Tags |
| Timeline |
Tools -> Timeline |
| Report |
Generate Report -> HTML, Excel, or other formats |
Useful Ingest Modules
| Module |
What It Does |
| Recent Activity |
Browser history, recent documents, USB devices, installed programs |
| Hash Lookup |
Flags known-bad files and filters known-good ones using hash sets |
| File Type Identification |
Identifies files by signature, not extension |
| Extension Mismatch Detector |
Files whose extension does not match their content |
| Keyword Search |
Indexes text for searching, including Unicode string extraction |
| Email Parser |
MBOX and PST email |
| Interesting Files Identifier |
Files matching rules you define |
| Embedded File Extractor |
Contents of archives and Office documents |
Reading the Output
- Results under "Extension Mismatch" and "Interesting Items" are worth checking early; renamed executables show up there
- Deleted files appear with a red X; whether they can be recovered depends on whether the space was reused
- Ingest runs in the background, so results keep appearing while analysis continues
Resources