Autopsy is one of the best tools for filesystem examinations. Unfortunately, iOS parsing is not provided in Autopsy, but it still may be useful for filesystem images. Autopsy can be downloaded from http://sleuthkit.org/autopsy/. When using Autopsy, the Android Analyzer module will parse some application data from the device. Let's look at how to use Autopsy for Android image analysis.
To use Autopsy, download the software and install it on a Windows machine and follow these instructions. Make sure that you are always using the latest version:
- Launch Autopsy.
- Create a new case:
- Select Next and then ...