From storage media to user activity

Host & Storage Analysis

Recover, examine, and correlate persistent evidence from disks, file systems, Windows artefacts, browsers, the Registry, and event logs.

6analysis routes44practical tools1supported timeline
01

Move from image to finding

Select each stage to follow a repeatable host-analysis workflow.

Stage 1Preserve the working basis

Work from a verified image or controlled copy, retain the original evidence, and record the tools and time settings used.

Ask: Can I return to the same starting point?
02

Find your analysis path

Choose the evidence question that most closely matches your starting point.

Best matchStart with disk image and recovery

Mount or examine an image safely, then identify recoverable files and useful volumes.

03

Build your foundation

Open the concept guide that matches the evidence you are examining.

04

Choose a tool by evidence

Begin with one focused tool and record the version, inputs, settings, and outputs.

Best starting point for broad image examinationAutopsy

Examine a disk image through an integrated case workflow and review multiple artefact types.

Also consider Arsenal Image Mounter for presenting an image as a disk or PhotoRec for focused file recovery.
Explore Autopsy
05

Check analysis readiness

Confirm that your working basis and interpretation context are recorded.

!
Preparation required5 checks remaining.