Features of Autopsy
|
Multi-User Cases
|
- |
Collaborate with fellow examiners on large cases. |
|
Timeline Analysis
|
- |
Displays system events in a graphical interface to help identify activity. |
|
Keyword Search
|
- |
Text extraction and index searched modules enable you to find files that mention specific terms and find regular expression patterns. |
|
Web Artifacts
|
- |
Extracts web activity from common browsers to help identify user activity. |
|
Registry Analysis
|
- |
Uses RegRipper to identify recently accessed documents and USB devices. |
|
LNK File Analysis
|
- |
Identifies shortcuts and accessed documents |
|
Email Analysis
|
- |
Parses MBOX format messages, such as Thunderbird. |
|
EXIF
|
- |
Extracts geolocation and camera information from JPEG files.
|
|
Robust File System Analysis
|
- |
Support for common file systems, including NTFS, FAT12/FAT16/FAT32/ExFAT, HFS+, ISO9660 (CD-ROM), Ext2/Ext3/Ext4, Yaffs2. |
|
Thumbnail Viewer
|
- |
Displays thumbnails of images to help quick view pictures. |
|
Unicode Strings Extraction
|
- |
Extracts strings from unallocated space and unknown file types in many languages |
|
Hash Set Filtering
|
- |
Displays thumbnails of images to help quick view pictures. |
|
File Type Detection
|
- |
based on signatures and extension mismatch |
|
Android Support |
- |
Extracts data from SMS, call logs, contacts, Tango, Words with Friends, and more. |
No comments:
Post a Comment