home/toolvault/digital forensics/autopsy-sleuth-kit

Autopsy + Sleuth Kit //

Digital Forensicsdisk forensics

Point Autopsy at a disk image and deleted files, browser history and USB artifacts appear in a friendly GUI. Forensics stops being magic and starts being methodical.

difficulty Β· easy
30 min
time to first win
5
guided steps
0
students started here*

HOW TO USE AUTOPSY + SLEUTH KIT

Follow the steps β€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

autopsy-sleuth-kit β€” guided lab session
static view
step 01

New case + add a disk image

Add Data Source β†’ select lab.E01/raw.dd

First rule of forensics: never touch originals β€” images only.

step 02

Recover the deleted

Views β†’ Deleted Files

Attackers delete tracks; forensic tools read unallocated space.

step 03

Timeline everything

Timeline tab

When things happened, in order β€” the IR question answered.

step 04

Browser archaeology

Results β†’ Web History/Cookies/Downloads

Web artifacts are the #1 'what did the user click?' answer.

step 05

Tag & report

tag evidence β†’ Generate Report

Forensics without reporting is just browsing; export the story.

THE WORKFLOW AT A GLANCE

πŸ–ΌοΈ
Image
E01/dd only
πŸ”
Ingest
auto-analysis
πŸ—‘οΈ
Recover
deleted data
πŸ•
Timeline
when & order
πŸ“
Report
the story
LEARNING CURVE
easy β€” 30 min to first win

FLAGS & SUPER-MOVES

Ingest modulespluggable analyzers
Deleted filesunallocated carve
Timelineevent chronology
Keyword searchregex/lists
Hash setsknown-good filter (NSRL)
Reportcase export

PRO TIPS

01

CyberDefenders disk labs + Autopsy = perfect practice pair.

CyberDefenders disk labs + Autopsy = perfect practice pair.

02

FTK Imager first (create the image), Autopsy second (analyze it).

FTK Imager first (create the image), Autopsy second (analyze it).

03

Learn where artifacts live

Learn where artifacts live: Prefetch, ShimCache, USN Journal, $MFT.

04

Eric Zimmerman's tools complement Autopsy for Windows artifacts.

Eric Zimmerman's tools complement Autopsy for Windows artifacts.

βš–οΈ

Golden rule

Use Autopsy + Sleuth Kit only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
✍️ Author LDM · ldmhub4u@gmail.com
full guide v1 Β· v2 immersive Β· latest news
Made for learners, everywhere Β· 2026
*plausibly. verify commands with official docs.