Introduction to Autopsy Forensic Browser

GIAC Certified Forensic Examiner Objectives:

Fundamental Digital Forensics

  • The candidate will demonstrate an understanding of forensic methodology, key forensic concepts, identifying types of evidence on current Windows operating systems and be familiar with the structure and composition of modern Windows file systems.

Foundations of Digital Forensics Acquisitions

  • The candidate will demonstrate an understanding of the methodologies and tools used to collect and process digital forensic evidence.

Overview

This lab is part of a series of lab exercises intended to support courseware for Forensics training. The development of this document is funded by the Department of Labor (DOL) Trade Adjustment Assistance Community College and Career Training (TAACCCT) Grant No. TC-22525-11-60-A-48.

There is different digital forensic investigation software available to digital forensic specialists. We will investigate the Autopsy Forensic Browser, which is a free and open-source tool that can be used to examine disk images and perform forensic investigations. In this lab, students will use the Autopsy Forensic Browser as part of the forensic process.

OUTCOMES:

In this lab, you will learn to:

  1. Install the Autopsy Forensic Browser
  2. Create a case in Autopsy Forensic Browser
  3. Examine an image with Autopsy
  4. Generate a report

Key terms and descriptions

Autopsy
The open-source digital investigation tool (digital forensic tool), Autopsy, runs on Windows, Linux, OS X, and other UNIX systems. Autopsy can be used to analyze disk images and perform in-depth analysis of file systems such as NTFS and FAT.
Bookmark
Within a case, relevant items can be designated important or bookmarked.
Forensic Report
Forensic software such as FTK, EnCase, and Autopsy allow examiners to generate forensic reports, which contain relevant bookmarks of important artifacts.
The Sleuth Kit
The Sleuth Kit (TSK) is a collection of command line tools that are utilized by the Autopsy forensic browser. The Sleuth Kit tools can be utilized without Autopsy.
E01 File
A proprietary imaging format developed by Guidance Software (the makers of EnCase). This image format is supported by other tools, such as FTK, PTK, and Autopsy.