Forensics
Autopsy
GUI digital forensics platform on The Sleuth Kit.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Disk image investigation and timeline analysis.
How
Create case; add disk image; run ingest modules; review.
Why
Approachable entry into DFIR workflows.
Commands & usage
# GUI application
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Forensics
Volatility 3
Memory forensics framework for RAM dumps.
The Sleuth Kit
CLI tools for disk image forensic analysis.
Wireshark / tshark
World-class packet capture and protocol analysis tool.
tcpdump
CLI packet capture utility.
ExifTool
Read/write metadata in files (images, docs, etc.).
steghide / zsteg / steghide tools
Steganography detection and extraction tools for CTFs and investigations.