Autopsy Hands-on Labs¶
Choose the browser simulation for coached evidence review, or complete the Full Lab with Autopsy and a supplied, verified Windows training image.
Hands-on proof of concept
Scope it. Find it. Corroborate it.
Create a bounded examination, follow one deleted-file lead across Autopsy views, and state only what the evidence supports.
Interactive Lab¶
Full Lab¶
Autopsy Full Lab
Use supplied or authorised training evidence
Analyse a verified working copy, not protected original evidence. Keep the case directory and exports separate from the image, and do not execute files recovered from the training source.
Before you begin
You need: an isolated Windows analysis VM, Autopsy, a documented Windows E01 or VMDK training image, sufficient case/index storage and separate export storage.
Case question
Does the image contain evidence that the named training file was present and deleted, and which independent Autopsy views corroborate that limited conclusion?
Objective¶
For case SUSA-AUT-031, add the verified working image, configure proportionate
ingest, investigate the controlled keyword mimikatz.exe, compare keyword and
deleted-file evidence, add time context, and write a reproducible conclusion
without claiming execution or user intent.
01
Activity 1: Establish the case boundary¶
- Record authority, question, image filename, format, byte size, source and SHA-256.
- Verify the working-copy hash against the recorded source value.
- Record Autopsy version, workstation time zone, case path and export path.
- Create case
SUSA-AUT-031and add the working image as Disk Image or VM File. - Confirm the generated or specified host remains attributable to the image.
Expected result The verified source appears under the intended host and no protected original has been opened.
02
Activity 2: Ingest and investigate¶
- Enable Recent Activity, Keyword Search and other modules required by the supplied image; record every enabled module and relevant setting.
- Start ingest and record start time, completion state, warnings and errors.
- Search for
mimikatz.exeusing a substring match restricted to the training source. - Record result count and one attributable result with source, path and timestamp.
- Review Data Artifacts, Deleted Files or Recycle Bin for a related record.
- Inspect file metadata or content safely; do not execute or open recovered binaries outside a controlled viewer.
Expected result At least two Autopsy views point to the same controlled filename without losing provenance.
03
Activity 3: Corroborate and report¶
- Open a relevant result in Timeline and record the time zone, timestamp type, range and filters.
- Compare the sequence with browser or recent-activity results when available.
- Export only the required table or report to controlled storage and hash it.
- Separate observations, interpretation, confidence and limitations.
- State whether the evidence supports presence and deletion, and identify what additional evidence would be needed to assess execution or user attribution.
Use this structure:
Case and question:
Image, host and SHA-256:
Autopsy version and ingest modules:
Keyword observation:
Deleted-file observation:
Timeline context and time zone:
Conclusion and confidence:
What the evidence does not prove:
Export path and SHA-256:
Full Lab evidence checklist¶
-
Core completion¶
Required for a reviewable image examination.
Troubleshooting¶
| Symptom | First check |
|---|---|
| Image cannot be added | Verify format, path, permissions, free space and working-copy integrity. |
| Ingest is slow | Review selected modules, image size, case volume capacity and current ingest progress. |
| Expected artefact is absent | Confirm module selection, source scope, search match type and whether the artefact exists in the supplied image. |
| Times appear inconsistent | Record Autopsy display time zone and compare the timestamp type and source metadata. |
| Export cannot be reviewed | Preserve its source result, export format, destination path and calculated hash. |
Clean up¶
Close the case, protect the case directory, notes and exports, confirm no file was executed from the image, remove disposable working material when authorised and restore the analysis VM snapshot if required.