Skip to content

Create and Analyse an Autopsy Case

Use a verified working image and a separate case directory. This guide preserves the original SUSA examples while organising them around decisions an analyst must record.

Create the case

From the welcome screen, select New Case. Use a descriptive case name such as 2025-04-18_WS2019_MalwareIncident and store the case under C:\Labs\Cases. Complete or intentionally omit the optional case number and examiner details, then select Finish.

Screenshot: Select New Case

Create a boundary. Do not reuse an unrelated case.

Screenshot: Enter the case name and base directory

Name and locate it. Keep the case separate from evidence.

Screenshot: Complete optional case details

Retain context. Record deliberate omissions.

Add the verified image

Autopsy organises data sources under hosts. Use the generated host name unless the case plan specifies a recorded host identity, choose Disk Image or VM File, and browse to the verified FTK Imager output or training VMDK.

Screenshot: Select or generate the host

Set host context. Avoid merging unrelated sources.

Screenshot: Choose Disk Image or VM File

Select the source type. Match the acquired format.

Screenshot: Browse to the verified image

Confirm the path. Use the labelled working copy.

Configure ingest proportionately

Ingest modules derive results such as recent activity, hash matches, file types, keywords and browser artefacts. Select only modules relevant to the question, record their settings, and note that Deselect All supports focused manual browsing but produces fewer derived results.

Screenshot: Configure Autopsy ingest modules

Select Next, review the summary, and select Finish to add the source.

Screenshot: Finish adding the data source

Examine and correlate leads

Once loaded, use the tree to retain path context and the listing, metadata and content panes to inspect a selected item. Useful starting locations include Users, AppData, Windows\System32\config and $Recycle.Bin; they are leads, not proof of activity by themselves.

Screenshot: Browse the Autopsy data-source tree and file details

Add time context

Right-click a relevant file such as EventStore.db, choose View File in Timeline, select a bounded range, and record the timestamp type and displayed time zone. Timeline proximity supports correlation but does not establish cause.

Screenshot: Open a file in Timeline

Define the pivot. Record file, timestamp and range.

Screenshot: Review surrounding timeline activity

Correlate carefully. Separate sequence from causation.

Compare multiple artefact views

The preserved Windows 11 example contains a downloaded and deleted mimikatz.exe training artefact. Review browser data, deleted-file records, keyword hits and the timeline as separate observations, then compare their host, path and time context before reaching a conclusion.

Screenshot: Review web bookmarks and browser data

Browser lead. A bookmark does not prove a visit or intent.

Screenshot: Review the Recycle Bin result

Deleted-file lead. Retain original path and deletion time.

Screenshot: Search for mimikatz.exe

Keyword lead. Preserve term, match type and result count.

Screenshot: Review Autopsy Timeline

Timeline context. Record filters and time zone.

Supported conclusion

Multiple attributable artefacts can support a sequence such as download, presence and deletion. They do not automatically prove execution, user authorship or malicious intent; seek corroborating execution and identity evidence.