Summary
In this chapter, we looked at automated DFIR investigation and analysis using the Autopsy forensic browser and The Sleuth Kit. Compared to individual tools, Autopsy has case management features and supports various types of file analysis, searching, and sorting of allocated, unallocated, and hidden files. Autopsy can also perform hashing on the file and directory levels to maintain evidence integrity.
In the next chapter, we will be using the updated and much more powerful stand-alone version of the Autopsy GUI, version 4, to analyze the same file used in this chapter for comparison.