The Sleuth Kit (TSK) - Autopsy
The Sleuth Kit - Autopsy
The sleuth kit is set of c library and command line utilities which is used for analysis of disk image and for recovery of data from them.
Autopsy is simple to use GUI based software that provides a way for analysing the hard drive and mobile phones. It is generally used by military purpose, corporate examiners, law enforcement to study what happened on the computer. You can also use it for recovering the camera's memory card.
Autopsy is free available for general use. Don't use it for any illegal activity. You can download autopsy from here. Now we are going to see that how autopsy work in windows environment.
After installing the autopsy, run it and select new case.
Then type the case number and examiner's other details. Then click finish.
Then select the Data Source which is your USB drive and enter other details according to you and click next.
After that configure the ingest as per your choice. There are many modules to scan, select as per your choice. Click Next.
After that click Finish.
Then you now seeing the progress bar of analysing files from your local disk. Make sure it will fully complete. It will recommend for proper investigation. Meanwhile you can explore the other capture data.
When all analysing process completed. You can check each data present in the local disk like Text files, Executable files, Audio, Video, System files, deleted files, etc. You can also check it hash and content of it. Where it will created and owner of that. You can also analyse the search tags and many more.
PDF Content Exploring |
We can also check hash value of any files.
Text File Hash |
Deleted File Exploring |
We learnt many things which are related to Sleuth Kit Autopsy. If you want to explore more you can go trough step-wise. We can do lot more things in this tools for forensics purposes.
Comments
Post a Comment