Forensics · Open source (Apache 2.0; built on The Sleuth Kit)

Autopsy

Autopsy is a free, open-source digital forensics platform that provides a graphical front end to The Sleuth Kit and other forensic tools. Investigators use it to analyse disk images and storage media: recovering deleted files, building timelines, extracting web and email artefacts, keyword-searching, carving files, and reviewing photos and documents. It is widely used by law enforcement, corporate investigators and students because it makes structured, repeatable forensic examination accessible without expensive commercial suites.

Last updated: 6 August 2026

What Autopsy is actually used for

Autopsy turns a raw disk image into an organised case. An examiner adds an image as a data source, runs ingest modules (hash lookup, file-type sorting, keyword search, EXIF, web history, registry) and then reviews the results through a case tree and timeline. It recovers deleted and hidden files, flags known-bad files by hash, and extracts browser history, recent documents and connected-device traces. In practice it is used for incident investigations, e-discovery and criminal casework, producing reports that document findings for review.

Platforms

Windows · Linux · macOS

Licence

Open source (Apache 2.0; built on The Sleuth Kit)

Commands worth knowing

New Case > Add Data Source

Create a case and load a disk image, local drive or logical files.

Run Ingest Modules

Kick off automated analysis: hashing, keyword search, EXIF, web artefacts and more.

Views > Deleted Files

List recoverable files that were deleted from the file system.

Keyword Search

Search across the image for terms, phone numbers or regex patterns.

Timeline

Visualise file and activity events chronologically to reconstruct what happened.

Hash Sets (import NSRL / known-bad)

Auto-flag known files and filter out known-good ones to focus the review.

Generate Report

Export a documented HTML/Excel report of tagged findings.

The legal line

Examine only media you own or are legally authorised to investigate, ideally working from a verified forensic image of the original. In India, digital evidence handling is governed by the IT Act 2000 and evidence law; maintaining chain of custody and hash integrity is essential for findings to be admissible. Unauthorised access to someone's device or data is an offence.

What Autopsy is bad at

Autopsy analyses persistent storage, so it will not capture data that exists only in memory or in transit. Strong full-disk encryption can render an image unreadable without keys. Ingest on large images is slow, automated results still need expert interpretation, and anti-forensic techniques (wiping, timestomping) can hide or falsify evidence.

Alternatives, and when to pick them

ToolPick it when
The Sleuth Kit (CLI)You want the underlying command-line tools for scripting and automation.
EnCaseYou need a court-established commercial suite common in law enforcement.
FTK (Forensic Toolkit)You want a commercial platform with strong indexing and processing.
X-Ways ForensicsYou want a fast, lightweight commercial tool favoured by many examiners.
VolatilityYour evidence is a memory dump rather than a disk image.

Where we teach it

Advanced module — digital forensics and incident response (mentored)

We are not affiliated with, endorsed by, or a reseller for the vendors of any tool on this site.

Autopsy — FAQs

Is Autopsy really free?

Yes. Autopsy is free and open source under the Apache 2.0 licence, built on The Sleuth Kit. It gives students and investigators a capable forensic platform without the cost of commercial suites like EnCase or FTK.

What can Autopsy recover from a disk image?

Deleted files, web and email artefacts, timelines of activity, EXIF metadata from photos, recent documents, registry information on Windows, and files carved from unallocated space, among other artefacts, depending on the ingest modules you run.

Is Autopsy admissible in court?

Tools do not make evidence admissible; process does. Autopsy is built on well-regarded open-source components, but admissibility depends on proper authorisation, a verified image, documented chain of custody and hash integrity, per the IT Act 2000 and evidence rules.

Autopsy se delete hui files wapas mil sakti hain kya?

Haan, agar unke data blocks abhi overwrite nahi hue hain to Autopsy deleted files recover kar sakta hai. Lekin overwrite ho chuke ya securely wipe kiye gaye data ko recover karna mushkil ya asambhav hota hai.

Learn Autopsy properly, in a legal lab

Free counselling call. We will tell you honestly whether a full course is worth it for what you actually want to do.

Call +91 75175 72000