Learning Autopsy for Digital Forensics
1h 23mBeginner2022-02-03
Authors

Bennett Hendrix
Course details
Anyone who’s ever used a computer has lost or accidentally deleted a file. In other instances, people often want to erase their digital tracks and hide their information and activity. If you work in digital forensics, recovering files and reconstructing a person’s activity on a computer can require finding and analyzing data from several sources. In this course, Bennett Hendrix III shows you the basics of Autopsy, a digital forensic platform and graphical interface that makes it easier to deploy the tools of the Sleuth Kit and other digital forensic tools. Bennett shows you how to use the platform to analyze and recover files of interest, whether for leisure or professional investigations, and explains how to analyze evidence and covers the must-know information for how to collect these findings. Additionally, Bennett explains how to optimize the user interface to best utilize the tools in available Autopsy.
Skills covered
AutopsySleuth KitIncident ResponseCybersecurityLearning
Concepts
0. Introduction
- 01 - Hey, where's the data
- 02 - Getting the most out of this course
1. Preparing Autopsy
- 03 - Introduction and installation of Autopsy
- 04 - Autopsy workflow
- 05 - Creating a case
- 06 - What data sources are allowed
- 07 - Viewing case logs and output
- 08 - Challenge - View case logs and output
- 09 - Solution - View case logs and output
2. Ingest Modules
- 10 - Utilizing Automated Analysis in Autopsy
- 11 - The Extension Mismatch and USB device-attached modules
- 12 - The Recent Activity and Interesting Files modules
- 13 - Installing third-party modules
- 14 - Challenge - Install a third-party module
- 15 - Solution - Install a third-party module
3. Reviewing Results
- 16 - UI layout
- 17 - The image and video gallery
- 18 - The timeline tool
4. Searching and Reporting
- 19 - Searching for keywords and files
- 20 - Tagging
- 21 - Generating reports in Autopsy
- 22 - Challenge - Search for all instances of a file
- 23 - Solution - Search for all instances of a file
Conclusion
- 24 - Next steps - Create your own case and analyze your files