Autopsy

Autopsy is a free, open-source digital forensics platform and the graphical interface for The Sleuth Kit, created by Brian Carrier. Investigators, incident responders and students use it to analyze disk images and drives, recover deleted files, and rebuild what happened on a computer.

Key features include timeline analysis, keyword search, web browser and email artifact extraction, Windows Registry analysis, EXIF metadata viewing, hash lookups (such as NSRL) and file carving through its PhotoRec module. Autopsy runs on Windows, Linux and macOS.

On Cracking Station you’ll find hands-on Autopsy tutorials, forensics walkthroughs and comparisons with other data carving and recovery tools such as PhotoRec, Scalpel, Bulk Extractor and X-Ways. They’re built for beginners, CHFI candidates and anyone learning digital forensics.

Back to top button