In this chapter, we looked at forensics using the Autopsy Forensic Browser with The Sleuth Kit. Compared to individual tools, Autopsy has case management features and supports various types of file analysis, searching, and sorting of allocated, unallocated, and hidden files. Autopsy can also perform hashing on a file and directory levels to maintain evidence integrity.
Next up, we have analysis of internet and network artifacts using another very powerful GUI tool called Xplico. See you in Chapter 9, Network and Internet Capture Analysis with Xplico.
Â