We have learned how to image a drive, but the next step is to use a tool to extract data from the drive or recover deleted information. This is where Autopsy comes in; it is an excellent utility for this purpose.
Before we use Autopsy, you might have wondered how you could recover a deleted file. When a file is deleted from a computer, it is not removed from the storage device. Instead, the filesystem marks the area the file uses as available for new data. The file's data remains on the disk until new data overwrites it.
This is why a recovery tool like Autopsy can reconstruct the deleted files and recover the information. However, if the deleted file has been partially overwritten, recovery becomes more challenging, and you might only be able to recover fragments of the file.
Autopsy software is digital forensic software that forensic investigators and law enforcement agencies can use to analyze and investigate digital evidence obtained from electronic devices such as computers, smartphones, tablets, and other storage media.
Autopsy software provides tools and features for examining and extracting data from digital devices in a forensically sound manner. It allows investigators to search for files, recover deleted data, analyze metadata, view file contents, and generate reports detailing their findings.
Some typical features of autopsy software include:
Disk Imaging: Creating a forensic image of the storage media to preserve the original evidence.
File Recovery: Identifying and recovering deleted or hidden files from the disk image.
Keyword Search: Searching for specific terms or keywords within the digital evidence.
File Analysis: Analyzing file metadata and contents to extract information relevant to the investigation.
Timeline Analysis: Creating a timeline of events based on file creation, modification, and access timestamps.
Hashing and Integrity Checking: Calculating hash values to ensure the integrity of the evidence and verify its authenticity.
Reporting: Generating detailed reports summarizing the findings of the forensic analysis.
Autopsy software plays a crucial role in digital forensic investigations by helping investigators collect, preserve, and analyze evidence to support legal proceedings, such as criminal prosecutions or civil litigation.
Now that we have a bit of an understanding of what Autopsy can do, let us install it. I highly recommend that you install and run this in Windows. You can run it on MacOS or in Linux, but it takes a bit to set up. Kali Linux uses an older version, so please ensure to use at least Autopsy 4.x during this course.
You can download it at: https://www.autopsy.com/
Autopsy is a powerful utility and can do a lot. We will focus on the basics of what it can do:
Creating a new case
Adding a data source
View data
Delete files
By size
By type
Email addresses
Timeline
Keyword search
Hash Analysis
Report
The demo provides a quick overview of some of the features you should be able to use and understand while doing an investigation. I highly suggest practicing and learning about the other features that Autopsy provides.