One alternative to the commercial forensics programs is Autopsy. Autopsy is a GUI-based forensic platform based upon the open source The Sleuth Kit toolset. This open source platform has features that are commonly found in commercial platforms. This includes timeline analysis, keyword searching, web and email artifacts, and the ability to filter results on known bad file hashes. One of its key features is its ease of use. This allows incident responders to have a light platform that focuses on critical tasks and obtain the critical evidence that's needed.
Autopsy
Installing Autopsy
Several of the Linux distributions we discussed previously have Autopsy preinstalled. It is good practice for responders to ensure that...