The Sleuth Kit (TSK) - Autopsy

 

The Sleuth Kit - Autopsy

The sleuth kit is set of c library and command line utilities which is used for analysis of disk image and for recovery of data from them.

Autopsy is simple to use GUI based software that provides a way for analysing the hard drive and mobile phones. It is generally used by military purpose, corporate examiners, law enforcement to study what happened on the computer. You can also use it for recovering the camera's memory card.

AutopsyLogo(autopsy.com)

Autopsy is free available for general use. Don't use it for any illegal activity. You can download autopsy from here. Now we are going to see that how autopsy work in windows environment.

After installing the autopsy, run it and select new case.

AutopsyHomePage

After that enter the case name which is related to your case or device you are going to scan and select the location of the case in device and also select the case type, and then click next.

CaseInformationPanel

Then type the case number and examiner's other details. Then click finish.

CaseOptionalInformation

Then just wait for some time. Our case database environment going to create. After that select host name will appear, click next. Then select the data source type that you want to scan. Here I selected the local disk as I want to scan my USB pen-drive.

SelectingDataSource

Then select the Data Source which is your USB drive and enter other details according to you and click next.

DataSourceSelection

After that configure the ingest as per your choice. There are many modules to scan, select as per your choice. Click Next.

IngestConfigure

After that click Finish.

Then you now seeing the progress bar of analysing files from your local disk. Make sure it will fully complete. It will recommend for proper investigation. Meanwhile you can explore the other capture data.

When all analysing process completed. You can check each data present in the local disk like Text files, Executable files, Audio, Video, System files, deleted files, etc. You can also check it hash and content of it. Where it will created and owner of that. You can also analyse the search tags and many more.

PDFFileView

PDF Content Exploring


We can also check hash value of any files.

TextFileHash

Text File Hash

We also see the Hex value, File Metadata and OS account of deleted file.

DeletedFileData
Deleted File Exploring

We learnt many things which are related to Sleuth Kit Autopsy. If you want to explore more you can go trough step-wise. We can do lot more things in this tools for forensics purposes.

Comments

Popular posts from this blog

Basics Forensics Imaging with dd, dcfldd, and dc3dd

Understanding and Demonstrating working of Jumplists

Study and install Pro-discover and Encase free version