[Tool] Autopsy 3.1 ...
 
Notifications
Clear all

[Tool] Autopsy 3.1 Released - Parallel Pipelines and Android

24 Posts
8 Users
0 Reactions
4,519 Views
KungFuAction
(@kungfuaction)
Estimable Member
Joined: 13 years ago
Posts: 109
 

It probably makes sense to get some more details on your environment in order to help you, but I would suggest continuing the conversation on the dedicated forum for Autopsy support.

I'm just noting it here. I've written there, which is how I found their Wiki. Still doesn't work.


   
ReplyQuote
(@tl1000matze)
New Member
Joined: 11 years ago
Posts: 1
 

Just curious. New here and new to Autopsy. I just downloaded it yesterday (Windows version) and from what I can tell, there is no imaging aspect of the program. What are people using to image devices for analysis with Autopsy?

For example encase forensic imager v7 or paladin by sumuri.


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Just curious. New here and new to Autopsy. I just downloaded it yesterday (Windows version) and from what I can tell, there is no imaging aspect of the program. What are people using to image devices for analysis with Autopsy?

Well, you would not want to make an image under Windows anyway (unless you have a suitable hardware write blocker).

You would otherwise use a "forensically oriented" Linux distro (that normally include suitable imaging programs) or build yourself a WinFE of some kind, example
http//reboot.pro/topic/19036-mini-winfe/
http//mistype.reboot.pro/mini-winfe.docs/readme.html
that includes a few imaging tools and provides structure for adding "external" ones (such as FTK imager in this case).

jaclaz


   
ReplyQuote
(@bitstorm)
Trusted Member
Joined: 14 years ago
Posts: 53
 

What about Python Modules, which the new version 3.1.1 supports. I'm not a coder, but how difficult would it be to integrate existing Python solutions (volatility framework, Willi Ballenthins EVTXtract)? Is that a rewrite of such solutions or there only some bridging/ connect work to be done? The answer would be very short if I understand the dev docu No Data content viewer modules in Python.

The dev docu can be found here http//sleuthkit.org/autopsy/docs/api-docs/3.1/
The Dev doc states that only report and ingest modules are supported with Python. I don't know the reason behind that limitation but having Data content viewer support Autopsy could get feature enhanced with stuff you do today with external tools. Either functionality is only based on unstructured strings or parsing of data is not available. That would benefit also timeline functionality which looks very good since 3.1.1.

Removing the Python Module limitation would get Autopsy convert to a killer forensic tool.


   
ReplyQuote
Page 3 / 3
Share: