Autopsy is the graphical front-end for The Sleuth Kit (TSK), the leading open-source disk forensics library. It is the de facto free alternative to EnCase / FTK for dead-box analysis and is widely used in law enforcement and education.
Modules a CySA+ candidate should be aware of:
- Timeline — combined MAC times from file system + logs.
- Hash Lookup — NSRL and custom hash sets to ignore known goods.
- Keyword Search with indexed full-text.
- Web Artifacts — browser history/cookies/cache.
- Registry / Recent Activity — RegRipper integration.
- PhotoRec carving and EXIF extraction.