Digital forensics on the disk itself — what's left sitting still on a host after the network
traffic is gone and the process list has moved on. Organized by what each ingest module or
view surfaces, why it's worth checking, what a suspicious value looks like, and exactly how
to pull it up.
Click any card for why it matters, what a suspicious value looks like, its IOC type, and exactly how to pull it up.
Case & Ingest
Setup
Setting up right before you touch a single file — the ingest modules enabled here decide what Autopsy actually surfaces later.
Case → New Case → Add Data Source → Configure Ingest Modules
Timeline & MACB
Chronology
MACB timestamps turn a static file listing into a chronological story — most of the "what happened when" question gets answered here.
Tools → Timeline → zoom to the incident window
Deleted Files & File System
Recovery
What's missing from the live file listing is often more interesting than what's still there.
Data Source → Deleted Files
Keyword & Hash
Search
Finding what you already know to look for, and what you don't — by string, by pattern, and passively by hash.
Keyword Search → Keyword Lists → New List
Web & OS Artifacts
Recent Activity
What the user actually did — browsed, downloaded, installed, plugged in — recovered from browser and OS artifacts.
Results → Extracted Content → Web History
Registry, Email & EXIF
Metadata
The system's own record of itself — accounts, folder access history, mail archives, and what a photo's metadata reveals.
Results → Extracted Content → User Accounts
Tagging & Reporting
Documentation
Turning what you found into a record someone else can trust and act on.