Chillli fd47aa4458 Revert "Mistake Fixed"
This reverts commit 57f7403645d59dde2e40afa1d424634f6a637c28.
2016-03-09 21:20:50 +01:00
2016-03-09 21:20:50 +01:00
2016-03-01 16:24:58 -05:00
2016-03-01 16:24:58 -05:00
2016-02-18 11:22:44 -05:00
2016-03-01 16:24:58 -05:00
2015-12-29 16:33:23 -05:00
2015-10-30 15:29:52 -04:00
2012-08-07 14:10:19 -04:00
2011-11-09 13:10:50 -05:00
2015-10-30 17:31:53 -04:00

Autopsy 4.0

http://www.sleuthkit.org/

March 3, 2016

##OVERVIEW

Autopsy is a graphical interface to The Sleuth Kit and other open source digital forensics tools. Autopsy 4 (and 3) are a complete rewrite from Autopsy 2, and none of this document is relevant to Autopsy 2.

Although Autopsy is designed to be cross-platform (Windows, Linux, MacOSX), the current version is fully functional and fully tested only on Windows. You can run Autopsy 4 on Linux and OS X, but it must be built from source code.

Autopsy 3 and 4 source code are distributed under a Apache 2 license. The package contains libraries that may have different licenses.

##INSTALLATION

All Autopsy dependencies are bundled with the installer provided. For Autopsy 3, there is no need for manual installation of additional dependencies if the installer is used. The current version of Autopsy 4 is distributed on sleuthkit.org only as a Windows installer. It can run on Linux and OS X, but requires some manual setup. To install Autopsy, perform the following steps:

  • Run the Autopsy msi file
  • If Windows prompts with User Account Control, click Yes
  • Click through the dialog boxes until you click a button that says Finish
  • Autopsy should now be fully installed

If you want the Japanese localized version, you must have the Japanese language pack (http://support.microsoft.com/kb/972813) installed and the default locale set to JA. (http://windows.microsoft.com/en-us/windows/change-system-locale#1TC=windows-7).

Refer to the next section for additional info on third-party software requirements to run Autopsy without installer.

Refer to the KNOWN_ISSUES.txt file for known bugs that could cause investigation problems.

##SUPPORT

There is a built-in help system in Autopsy once you get it started. There is also a QuickStart Guide that came with the installer.

Send any bug reports or feature requests to the sleuthkit-users e-mail list. http://www.sleuthkit.org/support.php

##LICENSE

The Autopsy code is released under the Apache License, Version 2. See LICENSE-2.0.txt for details.

##EMBEDDED SOFTWARE

This section lists the software components and libraries that are used inside of Autopsy. These tools are bundled with the installer, unless specified otherwise.

JRE (Java Runtime Environment) 1.8

Netbeans 7.3 RCP platform and .jar files bundled with the platform

Sleuth Kit for analyzing disk images.

Libewf for opening E01 files

zlib for opening E01 files

Solr (including Lucene and TIKA) for keyword search

GStreamer for viewing video files

GStreamer-java for viewing video files

Regripper for pulling recently activity (Including custom plugins)

Pasco2 for pulling Internet Explorer activity

Jericho for extracting content from HTML files

Advanced installer 9 (Freeware) (not embedded in Autopsy, but used to generate Autopsy installer.)

Metadata Extractor 2.6.2 for extracting Exif metadata

Reflections 0.9.8 for ingest module loading

Sigar for process monitoring

7Zip and 7Zip java bindings for 7Zip extractor module

ImgScalr 4.2 for image resizing in image viewers

##EMBEDED RESOURCES

This section lists other resources, such as icons, that are used by Autopsy.

FAMFAMFAM Silk Icons v1.3

Fugue Icons v3.5.6

WebHostingHub Glyphs

Splashy Icons (free as in free)

Description
Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. This is a fork of the main branch, where a flatpak version should be maintained.
Readme 2.2 GiB
Languages
Java 91.3%
Python 3.5%
HTML 1.8%
Shell 1.3%
CSS 0.9%
Other 1.1%