One alternative to the commercial forensics programs is Autopsy.Autopsy is a GUI-based forensic platform based upon the open source SleuthKit toolset. This open sourced platform has features commonly found in commercial platforms. This includes timeline analysis, keyword searching, web and email artifacts and the ability to filter results on known bad file hashes.One of the key features is its ease of use. This allows incident responders to have a light platform that focuses on critical tasks and obtain the critical evidence needed.

Get Digital Forensics and Incident Response now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.