Point Autopsy at a disk image and deleted files, browser history and USB artifacts appear in a friendly GUI. Forensics stops being magic and starts being methodical.
Follow the steps β click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
First rule of forensics: never touch originals β images only.
Attackers delete tracks; forensic tools read unallocated space.
When things happened, in order β the IR question answered.
Web artifacts are the #1 'what did the user click?' answer.
Forensics without reporting is just browsing; export the story.
| Ingest modules | pluggable analyzers |
| Deleted files | unallocated carve |
| Timeline | event chronology |
| Keyword search | regex/lists |
| Hash sets | known-good filter (NSRL) |
| Report | case export |
CyberDefenders disk labs + Autopsy = perfect practice pair.
FTK Imager first (create the image), Autopsy second (analyze it).
Learn where artifacts live: Prefetch, ShimCache, USN Journal, $MFT.
Eric Zimmerman's tools complement Autopsy for Windows artifacts.
Use Autopsy + Sleuth Kit only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β plenty of legal targets, zero risk.