Examining a Case

Once the case has been processed, the left-hand pane will populate with the number of artifacts located on the system:

In the previous screenshot, there are several items listed under the Extracted Content portion. These include looking at programs that have been installed, the operating system information, and recent documents. Another key feature of Autopsy is the ability to examine the entire folder structure of the image file.Clicking on the plus sign next to Data Sources expands the entire folder structure. This is useful if, through other sources, an analyst is able to identify the location of a suspect file.

There ...

Get Digital Forensics and Incident Response now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.