Navigating Autopsy

The Autopsy GUI is divided into three main sections. These sections display details relating to both the system and specific files. When Autopsy has completed processing a new case or opening an existing case, the analyst will see the following window:

As the previous screenshot shows, Autopsy is divided into three main panes. The first of these is the left pane, which contains the data sources and file structure, as well as search results. Clicking on the plus sign expands the results and clicking on the minus sign collapses them. This allows the analyst to access the system at a high level, as well as drilling down to ...

Get Digital Forensics and Incident Response now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.