All tools

Forensics

Autopsy

GUI digital forensics platform on The Sleuth Kit.

beginner
Windows
Linux
Forensics

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Disk image investigation and timeline analysis.

How

Create case; add disk image; run ingest modules; review.

Why

Approachable entry into DFIR workflows.

Commands & usage

# GUI application

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

disk
dfir
gui

Related in Forensics