Autopsy¶
What Autopsy does¶
Integrated disk-image examination
Autopsy is a digital-forensics platform for organising a case, adding disk or virtual-machine images, running selected ingest modules, and reviewing file-system, web, deleted-file, keyword and timeline evidence in one interface.
- Organise the examination
Create a case, identify its host and keep image, case and export storage separate. - Find and correlate leads
Use ingest, search, deleted-file, browser and timeline views to answer a bounded question. - Preserve review context
Retain source paths, settings, time zone, results and exports for another analyst.
Autopsy helps an analyst find and correlate evidence; it does not make every ingest result conclusive. Preserve the source identity, hash, case settings, module configuration and the path from each observation back to its data source.
Choose your journey¶
Stage Autopsy, retain version information and verify that the application starts.
Complete when the recorded shortcut opens the expected version.Beginner · Windows · 15–25 min 02Create and analyse a caseCreate a case, add a verified image, select proportionate ingest modules and investigate bounded leads.
Complete when observations remain attributable to the image.Practical · Training image · 30–60 min 03Hands-on LabsPractise the interface in-browser or complete an evidence-driven Full Lab.
Complete when another analyst can review the evidence trail.Guided beginner · 20–90 minHow the workflow fits together¶
Case structure
A case records where Autopsy stores its databases, indexes, reports and analyst state. Keep that directory separate from the protected image and review exports.
Ingest is a choice
Modules create derived results and consume time and storage. Select those that answer the question and record their settings; manual browsing remains useful.
Evidence quality and limitations¶
- Protect the working basis
Analyse a verified working copy and retain its filename, format, byte size and SHA-256 value. - Treat results as leads
A keyword hit, deleted-file record or browser artefact needs source context and may need corroboration. - Separate observation from conclusion
Record what the interface displays before interpreting authorship, execution or intent. - Preserve reproducibility
Retain the version, case path, host, modules, search terms, filters, time zone and exports.
Use authorised training evidence
Open only images you own or are authorised to examine. Keep original evidence protected and export to separate controlled storage.