Home Projects Blog Wiki Support About Contact
  

The Sleuth Kit
  

Autopsy
     
Features
     
Download
     
Documents
     
History
     
Licenses
     
Version 2
        
Download
  

Sleuth Kit Hadoop
  

mac-robber
  

Case Studies
  




Get Autopsy at SourceForge.net. Fast, secure and Free Open Source software downloads

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.

If you are looking for a version of Autopsy that runs on Linux and OS X, refer to version 2.

Training and Commercial Support are available from Basis Technology.

Easy to Use

Autopsy was designed to be intuitive out of the box. Installation is easy and wizards guide you through every step. All results are found in a single tree. See the intuitive page for more details.

Extensible

Autopsy was designed to be an end-to-end platform with modules that come with it out of the box and others that are available from third-parties. Some of the modules provide:

  • Timeline Analysis - Graphical event viewing interface.
  • Hash Filtering - Flag known bad files and ignore known good.
  • File System Forensic Analysis - Recover files from most common formats.
  • Keyword Search - Indexed keyword search to find files that mention relevant terms.
  • Web Artifacts - Extract history, bookmarks, and cookies from Firefox, Chrome, and IE.
  • Multimedia - Extract EXIF from pictures and watch videos.

See the Features page for more details. Developers should refer to the module development page for details on building modules.

There is currently a Student Autopsy Module Writing Contest and OSDFCon Module Contest going on right now. Start writing modules for cash prizes.

Fast

Everyone wants results yesterday. Autopsy runs background tasks in parallel using multiple cores and provides results to you as soon as they are found. It may take hours to fully search the drive, but you will know in minutes if your keywords were found in the user's home folder. See the fast results page for more details.

Cost Effective

Autopsy is free. As budgets are decreasing, cost effective digital forensics solutions are essential. Autopsy offers the same core features as other digital forensics tools and offers other essential features, such as web artifact analysis and registry analysis, that other commercial tools do not provide.