Introduction to Autopsy – The Sleuth Kit
In this chapter, we will focus on the Autopsy browser, which is based on data recovery and disk analysis tools found within The Sleuth Kit. Tools in The Sleuth Kit are all command line-based and the Autopsy browser allows us to access the tools and their functionality via a GUI for easy disk and file carving, recovery, analysis, and reporting.
Autopsy offers GUI access to a variety of investigative command-line tools from The Sleuth Kit, including file analysis, image and file hashing, deleted file recovery, and case management, among other capabilities. Autopsy can be a bit tricky to install but, fortunately for us, it comes built into Kali Linux, and is also very easy to set up and use.
Although the Autopsy browser is based on The Sleuth Kit, the features of Autopsy differ when using the Windows version as compared to the Linux version. We will cover the Windows version of Autopsy using Wine in Chapter 13, Performing a Full DFIR...