Autopsy is a free, open-source digital forensics platform that provides a graphical front end to The Sleuth Kit and other forensic tools. Investigators use it to analyse disk images and storage media: recovering deleted files, building timelines, extracting web and email artefacts, keyword-searching, carving files, and reviewing photos and documents. It is widely used by law enforcement, corporate investigators and students because it makes structured, repeatable forensic examination accessible without expensive commercial suites.
Last updated: 6 August 2026
Autopsy turns a raw disk image into an organised case. An examiner adds an image as a data source, runs ingest modules (hash lookup, file-type sorting, keyword search, EXIF, web history, registry) and then reviews the results through a case tree and timeline. It recovers deleted and hidden files, flags known-bad files by hash, and extracts browser history, recent documents and connected-device traces. In practice it is used for incident investigations, e-discovery and criminal casework, producing reports that document findings for review.
Windows · Linux · macOS
Open source (Apache 2.0; built on The Sleuth Kit)
New Case > Add Data SourceCreate a case and load a disk image, local drive or logical files.
Run Ingest ModulesKick off automated analysis: hashing, keyword search, EXIF, web artefacts and more.
Views > Deleted FilesList recoverable files that were deleted from the file system.
Keyword SearchSearch across the image for terms, phone numbers or regex patterns.
TimelineVisualise file and activity events chronologically to reconstruct what happened.
Hash Sets (import NSRL / known-bad)Auto-flag known files and filter out known-good ones to focus the review.
Generate ReportExport a documented HTML/Excel report of tagged findings.
Examine only media you own or are legally authorised to investigate, ideally working from a verified forensic image of the original. In India, digital evidence handling is governed by the IT Act 2000 and evidence law; maintaining chain of custody and hash integrity is essential for findings to be admissible. Unauthorised access to someone's device or data is an offence.
Autopsy analyses persistent storage, so it will not capture data that exists only in memory or in transit. Strong full-disk encryption can render an image unreadable without keys. Ingest on large images is slow, automated results still need expert interpretation, and anti-forensic techniques (wiping, timestomping) can hide or falsify evidence.
| Tool | Pick it when |
|---|---|
| The Sleuth Kit (CLI) | You want the underlying command-line tools for scripting and automation. |
| EnCase | You need a court-established commercial suite common in law enforcement. |
| FTK (Forensic Toolkit) | You want a commercial platform with strong indexing and processing. |
| X-Ways Forensics | You want a fast, lightweight commercial tool favoured by many examiners. |
| Volatility | Your evidence is a memory dump rather than a disk image. |
Advanced module — digital forensics and incident response (mentored)
We are not affiliated with, endorsed by, or a reseller for the vendors of any tool on this site.
Free counselling call. We will tell you honestly whether a full course is worth it for what you actually want to do.
Call +91 75175 72000