Autopsy
One alternative to commercial forensics programs is Autopsy. Autopsy is a GUI-based forensic platform based on the open source The Sleuth Kit toolset. This open source platform provides features that are commonly found in commercial platforms. This includes timeline analysis, keyword searching, web and email artifacts, and the ability to filter results on known bad file hashes. One of its key features is its ease of use. This allows incident responders to have a light platform that focuses on critical tasks and obtain the critical evidence that’s needed.
Installing Autopsy
Several of the Linux distributions we discussed previously have Autopsy preinstalled. It is good practice for responders to ensure that the platform they are using is up to date. For the Windows operating system, download the Microsoft self-installer file located at https://www.sleuthkit.org/autopsy/download.php. Once downloaded, execute the MSI file and choose an install location. Once you&...