SOC field reference

Autopsy Field Guide

Digital forensics on the disk itself — what's left sitting still on a host after the network traffic is gone and the process list has moved on. Organized by what each ingest module or view surfaces, why it's worth checking, what a suspicious value looks like, and exactly how to pull it up.

Click any card for why it matters, what a suspicious value looks like, its IOC type, and exactly how to pull it up.

Case & Ingest

Setup

Setting up right before you touch a single file — the ingest modules enabled here decide what Autopsy actually surfaces later.

Case → New Case → Add Data Source → Configure Ingest Modules

Timeline & MACB

Chronology

MACB timestamps turn a static file listing into a chronological story — most of the "what happened when" question gets answered here.

Tools → Timeline → zoom to the incident window

Deleted Files & File System

Recovery

What's missing from the live file listing is often more interesting than what's still there.

Data Source → Deleted Files

Keyword & Hash

Search

Finding what you already know to look for, and what you don't — by string, by pattern, and passively by hash.

Keyword Search → Keyword Lists → New List

Web & OS Artifacts

Recent Activity

What the user actually did — browsed, downloaded, installed, plugged in — recovered from browser and OS artifacts.

Results → Extracted Content → Web History

Registry, Email & EXIF

Metadata

The system's own record of itself — accounts, folder access history, mail archives, and what a photo's metadata reveals.

Results → Extracted Content → User Accounts

Tagging & Reporting

Documentation

Turning what you found into a record someone else can trust and act on.

Right-click a result → Tag → Bookmark

No fields match that filter.