autopsy

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.

  • Owner: sleuthkit/autopsy
  • Platform:
  • License::
  • Category::
  • Topic:
  • Like:
    0
      Compare:

Github stars Tracking Chart

Autopsy 4
http://www.sleuthkit.org/
March 15, 2016

OVERVIEW

Autopsy is a graphical interface to The Sleuth Kit and other open source digital forensics tools.
Autopsy 3 was a complete rewrite from Autopsy 2 to make it Java-based.
Autopsy 4 improves on Autopsy 3 by supporting collaboration on a single case by multiple users.

Although Autopsy is designed to be cross-platform (Windows, Linux, MacOSX), the current version is fully functional and fully tested only on Windows.
We have run it on XP, Vista, and Windows 7 with no problems.

Autopsy 4 is released under the Apache 2.0 license.
Some libraries Autopsy uses may have different, but similar, open source licenses.

INSTALLATION

For a Windows installation, all Autopsy dependencies are bundled with the installer provided.
There is no need for manual installation of additional dependencies if the Windows installer is used.

If you want the Japanese localized version, you must have the Japanese language pack (http://support.microsoft.com/kb/972813) installed and the default locale set to JA. (http://windows.microsoft.com/en-us/windows/change-system-locale#1TC=windows-7).

Refer to the KNOWN_ISSUES.txt file for known bugs that could cause investigation problems.

SUPPORT

There is a built-in help system in Autopsy once you get it started. There is also a QuickStart Guide that comes with the installer.

Send any bug reports or feature requests to the sleuthkit-users e-mail list.
http://www.sleuthkit.org/support.php

LICENSE

The Autopsy code is released under the Apache License, Version 2. See LICENSE-2.0.txt for details.

EMBEDDED SOFTWARE

This section lists the software components and libraries that are used by
Autopsy. These tools are bundled with the Windows installer, unless specified otherwise.

JRE (Java Runtime Environment) 1.8

Netbeans 8.0.2 RCP platform and .jar files bundled with the platform

Sleuth Kit for analyzing disk images.

Libewf for opening E01 files

zlib for opening E01 files

Solr (including Lucene and TIKA) for keyword search

GStreamer for viewing video files

GStreamer 1.x Java Core for viewing video files

Regripper for pulling recent activity
(Including custom plugins)

Pasco2 for pulling Internet Explorer activity

Jericho for extracting content from HTML files

Advanced installer 9 (Freeware)
(not embedded in Autopsy, but used to generate Autopsy installer.)

Metadata Extractor 2.6.2 for extracting Exif metadata

Reflections 0.9.8 for ingest module loading

Sigar for process monitoring

7Zip and 7Zip java bindings for 7Zip extractor module

ImgScalr 4.2 for image resizing in image viewers

ControlsFX JavaFX GUI library

JFXtras JavaFX GUI library

Mustache.java templating system

Joda-Time date and time library

TwelveMonkeys ImageIO plugins

EMBEDDED RESOURCES

This section lists other resources, such as icons, that are used by Autopsy.

FAMFAMFAM Silk Icons v1.3

Fugue Icons v3.5.6

WebHostingHub Glyphs

Splashy Icons (free as in free)

Main metrics

Overview
Name With Ownersleuthkit/autopsy
Primary LanguageJava
Program languageHTML (Language Count: 10)
Platform
License:
所有者活动
Created At2011-10-05 02:11:11
Pushed At2025-05-16 18:18:03
Last Commit At
Release Count56
Last Release Nameautopsy-4.22.1 (Posted on 2025-04-15 16:28:54)
First Release Nameautopsy-2.20 (Posted on 2008-10-17 20:23:38)
用户参与
Stargazers Count2.7k
Watchers Count131
Fork Count623
Commits Count35.8k
Has Issues Enabled
Issues Count630
Issue Open Count363
Pull Requests Count6415
Pull Requests Open Count10
Pull Requests Close Count860
项目设置
Has Wiki Enabled
Is Archived
Is Fork
Is Locked
Is Mirror
Is Private