Autopsy User Documentation  3.1
Graphical digital forensics platform for The Sleuth Kit and other tools.
Directory Tree

About Data Explorer (Directory Tree)

The data explorer tree is a very important area of the interface. This is where you will start many of your analysis approaches and find saved results from automated procedures (ingest). The tree has three main areas:

Below is an example of an Data Explorer Tree window: image html explorer-tree.PNG

Image Detail Window

The Image Details window shows you basic information about a disk image. You can access it by right-clicking on an image in the tree and choosing "Image Details".

show-image-details.PNG

An example is shown here:

image-detail-window.PNG

Volume Detail Window

The Volume Details window shows you information about a volume. It shows information such as the starting sector, length, and description. You can view the information by right clicking on a volume in the tree and choosing "Volume Details".

show-volume-details.PNG

An example is shown here:

volume-detail-window.PNG

Extracting Unallocated Space

Unallocated space are chunks of the file system that is currently not being used for anything. Unallocated space can store deleted files and other interesting artifacts. On the actual image, Unallocated space is stored in blocks with distinct locations on the system. However, because of the way various carving tools work, it is more ideal to feed them a single, large unallocated file. Autopsy provides access to both methods of looking at unallocated space.

Below is where to find the single file extraction option

extracting-unallocated-space.PNG

Copyright © 2012-2015 Basis Technology. Generated on Tue Mar 17 2015
This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.