Autopsy Favicon

Autopsy

Autopsy is a free, open-source digital forensics platform providing a graphical interface for disk analysis, file recovery, and timeline investigations.

Digital Forensics Disk Forensics File Recovery Timeline Analysis

Overview

Autopsy is a leading free, open-source digital forensics platform maintained by Sleuth Kit Labs, led by Brian Carrier. It provides a user-friendly graphical interface for The Sleuth Kit, enabling investigators to perform comprehensive disk analysis, file recovery, keyword searching, timeline analysis, and web artifact extraction. Autopsy is widely used by law enforcement, corporate investigators, and security professionals for forensic investigations, incident response, and data recovery. Autopsy 4.22.0, released in March 2025, added BitLocker support allowing investigators to enter a recovery key when adding an encrypted drive for automatic decryption on Windows, and enabled Autopsy to run alongside Cyber Triage without file path conflicts, allowing investigators to pivot between the two tools seamlessly [citation:1][citation:5]. Autopsy 4.22.1 followed with library updates and fixes for Excel report generation [citation:5]. Key capabilities include hash filtering with NSRL and known-bad hash sets, indexed keyword search and inline keyword search for faster triage without building a Solr index, deleted file carving using integrated PhotoRec engine, EXIF data extraction from images, web artifact extraction including browser history and cookies, email message parsing, registry analysis, and enhanced timeline analysis with graphical visualization [citation:4][citation:8][citation:9]. Autopsy supports multiple file systems and evidence image formats, and offers network-based collaboration allowing multiple examiners to work on the same case simultaneously [citation:4]. A modular architecture supports Python and Java plug-in development, with community-contributed modules extending capabilities for Android parsing, Registry analysis, malware scanning, and specialized artifact extraction [citation:4][citation:6]. The Cyber Triage Malware Scanner ingest module, available with a commercial license, scans executables for malware using 40+ engines without mounting disk images or uploading files to VirusTotal [citation:8].

Primary Use Cases

✔ Conducting forensic disk analysis and investigations across Windows, Linux, and macOS file systems with support for raw dd, E01, AFF, and other evidence image formats.
✔ Recovering deleted files and data using integrated PhotoRec carving engine to extract images, videos, and documents from unallocated disk space.
✔ Performing timeline analysis and incident response investigations with graphical visualization to reconstruct system activity and file changes chronologically.
✔ Executing keyword searches using indexed Solr search or inline triage search for locating sensitive information such as credit card numbers and identity data across large datasets.
✔ Extracting and analyzing web artifacts, email messages, EXIF metadata, and registry hives for comprehensive forensic examination of user activity.
✔ Collaborating on investigations through network-based case sharing that allows multiple examiners to analyze and tag evidence simultaneously.

Frequently Asked Questions

Autopsy is a leading free, open-source digital forensics platform maintained by Basis Technology that provides a graphical interface for The Sleuth Kit for disk analysis and investigations.

Yes, Autopsy is completely free and open-source. It is available for anyone to download and use without cost.

Autopsy offers comprehensive features including disk analysis, file recovery, keyword searching, timeline analysis, web artifact extraction, and support for multiple file systems.

Autopsy is ideal for law enforcement, corporate investigators, security professionals, incident responders, and anyone conducting digital forensic investigations.

Autopsy simplifies digital forensics by providing a user-friendly graphical interface for The Sleuth Kit, making complex forensic analysis accessible to investigators of all skill levels.

Metadata

Official Website Visit Website
Category Info

Graphical forensic platforms for disk analysis, file recovery, and timeline investigations.

Added On

August 20, 2026

Last Updated

August 20, 2026

Digital Forensics

KAPE (Kroll Artifact Parser and Extractor) is a free triage tool that rapidly collects and parses forensic artifacts from Windows systems, d...

Digital Forensics

Volatility 3 is the reference open-source memory forensics framework for analyzing RAM captures to uncover hidden processes, injected code, ...

Digital Forensics

CAINE is a free, open-source GNU/Linux live distribution created specifically for digital forensics with an integrated forensic environment.