Autopsy
Open-source graphical digital forensics platform built on The Sleuth Kit for disk image, file system, and web artifact analysis with timelines.
Technical Architecture & Overview
Autopsy is a graphical digital forensics platform built on The Sleuth Kit and other open-source tools. It provides a visual interface for disk image, file, registry, web artifact, and keyword analysis. Sleuth Kit Labs maintains the project and offers training and commercial support. Autopsy is fully functional and tested on Windows; Linux and macOS installs are available but less supported.
Targeted Technical Use Cases
Examine disk images, file systems, and triage data in a visual interface to build timelines, search files, and review web or registry artifacts.
Evaluation & Trade-offs
Core Strengths
- +Integrated timeline, keyword search, and artifact analysis modules in one interface.
- +Supports collaboration by multiple examiners on a single case.
Trade-Offs & Limitations
- -Best support and testing are on Windows; Linux and macOS support is limited.
- -Large cases can require substantial memory and storage capacity.
Defensive Security Application
Ingest disk images or triage collections to find suspicious files, user activity, and timeline anomalies, then support remediation and evidence preservation.
Frequently Asked Questions
What is Autopsy?→
Autopsy is a graphical digital forensics platform built on The Sleuth Kit and other open-source tools. It provides a visual interface for disk image, file, registry, web artifact, and keyword analysis. Sleuth Kit Labs maintains the project and offers training and commercial support. Autopsy is fully functional and tested on Windows; Linux and macOS installs are available but less supported.
What is Autopsy used for?→
Examine disk images, file systems, and triage data in a visual interface to build timelines, search files, and review web or registry artifacts.
What are the strengths of Autopsy?→
- +Integrated timeline, keyword search, and artifact analysis modules in one interface.
- +Supports collaboration by multiple examiners on a single case.
What are the limitations of Autopsy?→
- +Best support and testing are on Windows; Linux and macOS support is limited.
- +Large cases can require substantial memory and storage capacity.
How is Autopsy used defensively?→
Ingest disk images or triage collections to find suspicious files, user activity, and timeline anomalies, then support remediation and evidence preservation.