Performing a Full DFIR Analysis with the Autopsy 4 GUI
As we previously learned in Chapter 12, Autopsy Forensic Browser, when we used the Autopsy forensic browser, which comes with Kali Linux, Autopsy is quite a powerful tool when it comes to automated evidence and file analysis. However, the Autopsy forensic browser has some limitations, especially as it is older and not as frequently updated as the Graphical User Interface (GUI) version. The Autopsy forensic browser has been at version 2.2 for many years, whereas the Autopsy GUI is currently, at the time of writing, up to version 4.19.
In this chapter, we will focus on the Autopsy v4 GUI (also called the Autopsy 4 GUI) and analyze the very same file used in the previous chapter to compare the usage, features, and differences in analysis findings (if any). The following topics will be covered in this chapter:
- Autopsy 4 GUI features
- Installing Autopsy 4 in Kali Linux using Wine
- Downloading sample files for automated...