Summary
In this chapter, we downloaded and installed the more powerful Windows version of Autopsy known as the Autopsy 4 GUI and were able to run it in Kali Linux using Wine. We also learned how simple it is to automatically analyze evidence files to find artifacts such as deleted files using this version of Autopsy. I hope you enjoyed this chapter as it showcases the much more powerful version of Autopsy when compared to the Autopsy browser, which we looked at in Chapter 12, Autopsy Forensic Browser.
Next, we will learn about some popular scanning and reconnaissance tools that, although not specifically created for DFIR purposes, are very useful in network forensics analysis and investigations. See you in Chapter 14, Network Discovery Tools!