0% found this document useful (0 votes)
131 views

Digital Forensics Experiment - 1: Study and Learning of Digital Forensic Tool

Autopsy is a digital forensics tool used by law enforcement, military, and corporations to investigate computer activity. It allows users to analyze files, folders, and disks to generate detailed reports on what occurred. The tool ingests data sources and configures modules to investigate specified aspects of files. Users can view generated logical files and disk images to analyze the evidence in a tabular format and then generate reports on their findings.

Uploaded by

Kshitij Singla
Copyright
© © All Rights Reserved
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
131 views

Digital Forensics Experiment - 1: Study and Learning of Digital Forensic Tool

Autopsy is a digital forensics tool used by law enforcement, military, and corporations to investigate computer activity. It allows users to analyze files, folders, and disks to generate detailed reports on what occurred. The tool ingests data sources and configures modules to investigate specified aspects of files. Users can view generated logical files and disk images to analyze the evidence in a tabular format and then generate reports on their findings.

Uploaded by

Kshitij Singla
Copyright
© © All Rights Reserved
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 7

DIGITAL FORENSICS

EXPERIMENT - 1

Name – Kartik Soni Submitted To:

Registration Number- 17BCE2403 Mr. Aju D.

Study and learning of digital forensic tool: Autopsy

AUTOPSY:-

Autopsy is a cyber forensics tool provided and maintained


by sleuth kit. It is used by law enforcement, military, and
corporate examiners to investigate what happened on a
computer. You can even use it to recover photos from your
camera's memory card.
STEPS FOR USING AUTOPSY:-

1.Start the autopsy Software and choose between New


Case/Open case/Open Recent Case Options and then
choose the directory
2. If working on a New case fill in the required
information and then

3.Click on Add Data Source and then add the Folder


or disc(available only in Run as Administrator option)
4. Next Step involves configuring the ingest modules that
is choosing which aspects of file/folder you want to
investigate

5. Next Click on the logical files generated to look at


the detailed tabular analysis
6. Screenshot of Detailed tabular analysis

7. Go into views to view all the different types of files


GENERATION OF REPORT:-

1. Click on Generate report option in the Navbar and


then choose the Format of report to be generated

Similarly for the disc we must use run as administrator


option and then in data source select logical disk

We will get a disk like image in place of logical files for this
case which is given below
Click on the disk image to view detailed description of disc
Report For the disc will be as follows

You might also like