Autopsy User Documentation  4.17.0
Graphical digital forensics platform for The Sleuth Kit and other tools.
Picture Analyzer Module

Table of Contents

Overview

The Picture Analyzer module extracts EXIF (Exchangeable Image File Format) information from ingested pictures. This information can contain geolocation data for the picture, time, date, camera model and settings (exposure values, resolution, etc) and other information. The discovered attributes are added to the Blackboard. This can tell you where and when a picture was taken, and give clues to the camera that took it.

The module also converts HEIC/HEIF images to JPG while maintaining their EXIF information, which will be processed and saved as it would for normal JPG images.

Using the Module

Select the checkbox in the Ingest Modules settings screen to enable the Picture Analyzer module.

Seeing Results

Results are shown in the Results tree.

EXIF-tree.PNG

For HEIC files, the converted JPGs will appear in the data source tree as children of the original file.

EXIF-heic.png

Copyright © 2012-2020 Basis Technology. Generated on Sun Oct 25 2020
This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.