AUTOPSY
Autopsy is an open-source digital forensics platform. Essential for disk image analysis and evidence examination.
INSTALLATION#
# Windows # Download from https://www.autopsy.com/download/ # Linux (via Sleuth Kit) apt install autopsy sleuthkit
GETTING STARTED#
CREATE CASE#
1. File > New Case 2. Enter case name and number 3. Select base directory 4. Add examiner info
ADD DATA SOURCE#
1. Add Data Source 2. Select type: - Disk Image or VM File - Local Disk - Logical Files - Unallocated Space 3. Configure ingest modules
DATA SOURCE TYPES#
DISK IMAGES#
.E01 EnCase format .dd/.raw Raw image .img Disk image .vmdk VMware .vhd/.vhdx Hyper-V
LOCAL DISK#
Physical drive Logical volume USB device
LOGICAL FILES#
Folder import Evidence bag ZIP/tar archives
INGEST MODULES#
CORE MODULES#
Recent Activity Browser history, cookies, downloads Hash Lookup Known bad file identification File Type ID File signature analysis Extension Mismatch Hidden file detection Embedded File Extractor Extract files from archives Exif Parser Image metadata Keyword Search Text searching Email Parser Parse email files Encryption Detection Find encrypted files Interesting Files Flag suspicious files PhotoRec Carver File carving Virtual Machine Extractor Extract VM files
ANALYSIS VIEWS#
DATA SOURCES#
View raw data source structure Navigate file system hierarchy
VIEWS#
File Types By MIME type Deleted Files Recovered deleted File Size Large files Recent Documents Recently accessed
RESULTS#
Extracted Content Parsed data Keyword Hits Search matches Hashset Hits Known files Interesting Items Flagged items E-mail Messages Parsed emails Accounts User accounts
TAGS/COMMENTS#
Bookmark evidence Add examiner notes Tag for follow-up
KEYWORD SEARCH#
BASIC SEARCH#
# Search box in toolbar # Single term or phrase
ADVANCED SEARCH#
# Tools > Run Ingest Modules > Keyword Search
REGEX SEARCH#
# Use regex patterns
\d{3}-\d{2}-\d{4} # SSN
\d{16} # Credit card
[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+ # Email
KEYWORD LISTS#
# Create predefined lists # Run against evidence
TIMELINE#
GENERATE TIMELINE#
# Tools > Timeline
TIMELINE EVENTS#
File created (B) File accessed (A) File modified (M) File changed (C) Web activity Registry changes
FILTER TIMELINE#
By date range By event type By data source
HASH ANALYSIS#
HASH DATABASES#
# Tools > Options > Hash Database NSRL Known good files Custom hashsets Known bad files
COMPUTE HASHES#
MD5 SHA1 SHA256
FLAGGED HASHES#
Known malware Known tools Custom indicators
FILE ANALYSIS#
FILE METADATA#
Right-click > View File Metadata - File times (MAC) - Size - Hashes - Path
HEX VIEW#
Right-click > View in Hex - Raw file bytes - Search hex patterns
STRING EXTRACTION#
Right-click > Extract Strings - ASCII strings - Unicode strings
APPLICATION DATA#
WEB ARTIFACTS#
# Results > Extracted Content > Web - Browser history - Bookmarks - Cookies - Downloads - Cache - Search queries - Form autofill
EMAIL#
# Results > Extracted Content > E-mail - PST/OST files - MBOX - EML files - Attachments
REGISTRY#
# Results > Extracted Content > Registry - User profiles - Installed software - Run keys - USB devices - Recent files
OPERATING SYSTEM#
# Results > Extracted Content > OS - Installed programs - Scheduled tasks - Services - User accounts
COMMUNICATIONS#
# Results > Extracted Content > Communications - Call logs - Contacts - Messages (SMS/Chat)
EVIDENCE EXPORT#
EXPORT FILES#
Right-click > Extract File(s) - Single file - Selected files - Directory
GENERATE REPORT#
# Tools > Generate Report
REPORT FORMATS#
HTML Report Excel Report KML (Google Earth) Body File Tagged/Bookmarked items
PORTABLE CASE#
# Generate portable case for sharing # Includes selected evidence
COMMAND LINE#
SLEUTH KIT TOOLS#
fls List files icat Extract file by inode istat File system details mmls Partition table fsstat File system info tsk_recover Recover deleted files sorter Sort files by type mactime Timeline creation
EXAMPLES#
# List files fls -r image.dd # Extract file icat image.dd 12345 > extracted_file # Partition table mmls image.dd # Create timeline fls -r -m / image.dd > bodyfile.txt mactime -b bodyfile.txt > timeline.csv
MOBILE FORENSICS#
SUPPORTED DEVICES#
Android logical images iOS logical images Backup files
MOBILE ARTIFACTS#
Call logs SMS/MMS Contacts App data Location data Media files
COMMON WORKFLOWS#
TRIAGE ANALYSIS#
1. Add data source 2. Run Recent Activity module 3. Review web/email artifacts 4. Check deleted files 5. Search keywords
MALWARE ANALYSIS#
1. Run Hash Lookup 2. Check Interesting Files 3. Review executables 4. Examine registry 5. Check persistence
INCIDENT RESPONSE#
1. Add disk image 2. Run all modules 3. Generate timeline 4. Search for IOCs 5. Export evidence
QUICK REFERENCE#
# Create case and add evidence File > New Case Add Data Source > Disk Image # Key views Results > Extracted Content # Parsed artifacts Views > Deleted Files # Recovered files Keyword Search # Text search # Export Right-click > Extract File Tools > Generate Report # Sleuth Kit fls -r image.dd # List files icat image.dd inode > file # Extract file mmls image.dd # Partitions
AUTOPSY CHEATSHEET
==================
Source: https://cheatsheet.johlem.net
Autopsy is an open-source digital forensics platform.
Essential for disk image analysis and evidence examination.
INSTALLATION
------------
# Windows
# Download from https://www.autopsy.com/download/
# Linux (via Sleuth Kit)
apt install autopsy sleuthkit
GETTING STARTED
===============
CREATE CASE
-----------
1. File > New Case
2. Enter case name and number
3. Select base directory
4. Add examiner info
ADD DATA SOURCE
---------------
1. Add Data Source
2. Select type:
- Disk Image or VM File
- Local Disk
- Logical Files
- Unallocated Space
3. Configure ingest modules
DATA SOURCE TYPES
=================
DISK IMAGES
-----------
.E01 EnCase format
.dd/.raw Raw image
.img Disk image
.vmdk VMware
.vhd/.vhdx Hyper-V
LOCAL DISK
----------
Physical drive
Logical volume
USB device
LOGICAL FILES
-------------
Folder import
Evidence bag
ZIP/tar archives
INGEST MODULES
==============
CORE MODULES
------------
Recent Activity Browser history, cookies, downloads
Hash Lookup Known bad file identification
File Type ID File signature analysis
Extension Mismatch Hidden file detection
Embedded File Extractor Extract files from archives
Exif Parser Image metadata
Keyword Search Text searching
Email Parser Parse email files
Encryption Detection Find encrypted files
Interesting Files Flag suspicious files
PhotoRec Carver File carving
Virtual Machine Extractor Extract VM files
ANALYSIS VIEWS
==============
DATA SOURCES
------------
View raw data source structure
Navigate file system hierarchy
VIEWS
-----
File Types By MIME type
Deleted Files Recovered deleted
File Size Large files
Recent Documents Recently accessed
RESULTS
-------
Extracted Content Parsed data
Keyword Hits Search matches
Hashset Hits Known files
Interesting Items Flagged items
E-mail Messages Parsed emails
Accounts User accounts
TAGS/COMMENTS
-------------
Bookmark evidence
Add examiner notes
Tag for follow-up
KEYWORD SEARCH
==============
BASIC SEARCH
------------
# Search box in toolbar
# Single term or phrase
ADVANCED SEARCH
---------------
# Tools > Run Ingest Modules > Keyword Search
REGEX SEARCH
------------
# Use regex patterns
\d{3}-\d{2}-\d{4} # SSN
\d{16} # Credit card
[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+ # Email
KEYWORD LISTS
-------------
# Create predefined lists
# Run against evidence
TIMELINE
========
GENERATE TIMELINE
-----------------
# Tools > Timeline
TIMELINE EVENTS
---------------
File created (B)
File accessed (A)
File modified (M)
File changed (C)
Web activity
Registry changes
FILTER TIMELINE
---------------
By date range
By event type
By data source
HASH ANALYSIS
=============
HASH DATABASES
--------------
# Tools > Options > Hash Database
NSRL Known good files
Custom hashsets Known bad files
COMPUTE HASHES
--------------
MD5
SHA1
SHA256
FLAGGED HASHES
--------------
Known malware
Known tools
Custom indicators
FILE ANALYSIS
=============
FILE METADATA
-------------
Right-click > View File Metadata
- File times (MAC)
- Size
- Hashes
- Path
HEX VIEW
--------
Right-click > View in Hex
- Raw file bytes
- Search hex patterns
STRING EXTRACTION
-----------------
Right-click > Extract Strings
- ASCII strings
- Unicode strings
APPLICATION DATA
================
WEB ARTIFACTS
-------------
# Results > Extracted Content > Web
- Browser history
- Bookmarks
- Cookies
- Downloads
- Cache
- Search queries
- Form autofill
EMAIL
-----
# Results > Extracted Content > E-mail
- PST/OST files
- MBOX
- EML files
- Attachments
REGISTRY
--------
# Results > Extracted Content > Registry
- User profiles
- Installed software
- Run keys
- USB devices
- Recent files
OPERATING SYSTEM
----------------
# Results > Extracted Content > OS
- Installed programs
- Scheduled tasks
- Services
- User accounts
COMMUNICATIONS
--------------
# Results > Extracted Content > Communications
- Call logs
- Contacts
- Messages (SMS/Chat)
EVIDENCE EXPORT
===============
EXPORT FILES
------------
Right-click > Extract File(s)
- Single file
- Selected files
- Directory
GENERATE REPORT
---------------
# Tools > Generate Report
REPORT FORMATS
--------------
HTML Report
Excel Report
KML (Google Earth)
Body File
Tagged/Bookmarked items
PORTABLE CASE
-------------
# Generate portable case for sharing
# Includes selected evidence
COMMAND LINE
============
SLEUTH KIT TOOLS
----------------
fls List files
icat Extract file by inode
istat File system details
mmls Partition table
fsstat File system info
tsk_recover Recover deleted files
sorter Sort files by type
mactime Timeline creation
EXAMPLES
--------
# List files
fls -r image.dd
# Extract file
icat image.dd 12345 > extracted_file
# Partition table
mmls image.dd
# Create timeline
fls -r -m / image.dd > bodyfile.txt
mactime -b bodyfile.txt > timeline.csv
MOBILE FORENSICS
================
SUPPORTED DEVICES
-----------------
Android logical images
iOS logical images
Backup files
MOBILE ARTIFACTS
----------------
Call logs
SMS/MMS
Contacts
App data
Location data
Media files
COMMON WORKFLOWS
================
TRIAGE ANALYSIS
---------------
1. Add data source
2. Run Recent Activity module
3. Review web/email artifacts
4. Check deleted files
5. Search keywords
MALWARE ANALYSIS
----------------
1. Run Hash Lookup
2. Check Interesting Files
3. Review executables
4. Examine registry
5. Check persistence
INCIDENT RESPONSE
-----------------
1. Add disk image
2. Run all modules
3. Generate timeline
4. Search for IOCs
5. Export evidence
QUICK REFERENCE
---------------
# Create case and add evidence
File > New Case
Add Data Source > Disk Image
# Key views
Results > Extracted Content # Parsed artifacts
Views > Deleted Files # Recovered files
Keyword Search # Text search
# Export
Right-click > Extract File
Tools > Generate Report
# Sleuth Kit
fls -r image.dd # List files
icat image.dd inode > file # Extract file
mmls image.dd # Partitions
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.