Evidence analysis using the Autopsy forensic browser
Now that we’ve created our case, added host information with appropriate directories, and added our sample evidence file, we come to the analysis stage, which involves the following steps for file and drive analysis, file carving, and recovery:
- After clicking on the ANALYZE button (see Figure 12.15), we’re presented with several options in the form of tabs with which to begin our investigation:
Figure 12.16 – Analysis tab options
- Let’s look at the details of the image by clicking on the IMAGE DETAILS tab. In the following screenshot, we can see the volume serial number and the operating system (OEM Name) listed as BSD 4.4:
Figure 12.17 – IMAGE DETAILS tab
- Next, we click on the FILE ANALYSIS tab. This tab opens into file browsing mode, which allows the examination of directories and files within the image. Directories...