Open In App

Analysis of Data Source Using Autopsy

The Sleuth Kit is a library and a collection of command-line tools used to investigate disk images. Autopsy is the GUI program for TSK. The results of the forensic search carried over the images are displayed here. These results help the investigator to locate relevant sections of data in their investigation. It is used by law enforcement, military, and corporate examiners to investigate the actions taken place on the evidence computer, however, it can be used to recover deleted data from digital devices too.

Autopsy performs operations onto disk images which can be created using tools like FTK Imager.  Here an already created image is used. You may download Autopsy from here .



1. Getting Started

Open Autopsy and create a new case.



Click on Finish after completing both the steps.

2. Add a data source.

Select the appropriate data source type.

The data source used here is a disk image. Add the data source destination.

Configure ingest modules.

The ingest modules determine factors for which the data in the data source is to be analyzed. Here is a brief overview of each of them.

Select all that will serve the purpose of your investigation and click Next. Once the data source is added, click Finish. It will take some buffer time to extract and analyze the data depending upon the size of the Data Source.

3. Exploring the data source:

The Data Source information: Here the basic metadata is shown. A detailed analysis is displayed in the bottom section. These details can be extracted in the form of Hex values, Results, File Metadata, etc.

The disk image is then broken down based upon its volume partitions.

Each volume can be browsed for its contents, results for which are displayed in the section at the bottom. For example, the content shown below belongs to  Data Sources -> Mantooth.E01 -> MSOCache-> [Parent Folder].

Views (Determines the factor of file classification)

Note: It is usually advised to not scan or extract any suspected files/ disks such as payload files, etc. in the main system, rather scan them in safe environments such as a virtual machine, and then extract the data, as they hold the possibility of being corrupt and may infect the examiner’s system with viruses.

Results:

All the extracted data is viewed in Views/ Data Source. In Results, we get the information about this data.

Additional Features:

Almost all the basic features and how actually Autopsy works have been discussed in this article. However, it is always recommended to go through different sample data sources to explore even more. 


Article Tags :