Analyzing directories and recovering deleted files and artifacts with Autopsy 4
As previously mentioned, Autopsy has a very simple and uncomplicated interface. The Autopsy window is separated into three panes, as described here:
- The left pane shows the data source that was examined and analyzed and all directories and files discovered and recovered by Autopsy
- The main pane displays all the discovered files within the data source folders
- The lower pane displays file details such as Hex, Text, File Metadata, and Data Artifacts
In the following screenshot, I’ve expanded the Data Sources, File Views, and Deleted Files folders by clicking on the plus signs (+) next to each of the mentioned items, which all display sub-directories, as seen in the following screenshot:
Figure 13.19 – Analyzed data source findings in Autopsy
By expanding the Data Sources item on the left pane, we can see that the evidence file has two volumes...