Getting Started in Digital Forensics with Autopsy and The Sleuth Kit: A Free Training Guide
Autopsy is a free open source forensics analysis platform and the right place to start learning. How it relates to The Sleuth Kit, command equivalents, lab setup, lawful practice datasets, a step by step first examination, the extension mismatch lesson, comparison with commercial suites and a three month learning path.
Quick answer: Autopsy is a free and open source digital forensics platform built on The Sleuth Kit. It is the right tool to start learning forensics because there is no licence barrier and the command line tools underneath it (fls, icat, mmls) actually teach how the work is done. A typical first lesson runs like this: download a training image, create a case, add the image as a data source, run ingest modules, examine the file system and deleted files, then tag findings and generate a report. Autopsy does not acquire images, it analyzes them, and that distinction is the most commonly confused point.
Everyone starting in digital forensics asks the same first question: which tool should I begin with. The answer is less controversial than people assume. Commercial suites are powerful, but their multi thousand dollar licences mean nothing while you are learning. Autopsy is free, and The Sleuth Kit behind it teaches the core concepts directly. This article lays out a realistic learning path from zero.
How Autopsy and The Sleuth Kit relate
The two names are always mentioned together but they are different things.
The Sleuth Kit (TSK) is a set of command line tools developed by Brian Carrier. It reads disk images, parses file systems and extracts deleted records. It has no graphical interface.
Autopsy is the graphical interface built on top of TSK. It adds case management, timeline, keyword search, a module system and reporting.
The key learning point: if you know which TSK tool runs behind a button in Autopsy, you are genuinely learning. If you do not, you are only learning to operate an interface. A good examiner can do both.
Core TSK commands and their equivalents:
| Command | What it does | Autopsy equivalent |
|---|---|---|
mmls |
Lists the partition table | Partition selection when adding a data source |
fsstat |
Reports file system details | Data source properties |
fls |
Lists files and directories including deleted | File tree view |
icat |
Extracts the content of an inode | File export |
istat |
Shows metadata for an inode | File metadata tab |
blkls |
Extracts unallocated space | Unallocated space analysis |
What Autopsy does and does not do
The most common mistake is treating Autopsy as an acquisition tool. Autopsy is an analysis platform.
- It does: read images, parse file systems, recover deleted files, carve files, index keywords, match hashes, build timelines, parse browser and registry artifacts, parse email, and produce reports.
- It does not: create a forensic image from a disk. That requires a separate tool. See our article on imaging and hash verification with FTK Imager. On Linux, Guymager and dd are common.
Build your lab
While learning you do not need to work on a real case, and you should not. Examining someone else's device without authorization creates legal problems.
Hardware. Autopsy uses memory and disk heavily while indexing. For learning, 16 GB of RAM and an SSD are comfortable. With small training images, 8 GB is enough.
Installation. The Windows installation is the least troublesome. On Linux you install TSK from the package manager and Autopsy separately.
Legal and free practice data. This is the most critical part of learning:
- NIST CFReDS (Computer Forensic Reference Data Sets) are official reference sets that ship with answer keys.
- Digital Corpora provides scenario images produced for academic use.
- DFRWS challenge datasets suit advanced practice.
- You can also build your own: put files on a virtual machine and delete them, then image it and try to find them with Autopsy. Because you know the answer, you also measure whether the tool behaves correctly.
Your first examination, step by step
- Create a case. Enter case name, number and examiner. These fields appear in the report and form part of the chain of custody.
- Add a data source. You can add a disk image, a virtual machine file or a folder. Set the time zone correctly, a wrong time zone shifts your whole timeline and is the most common silent mistake.
- Choose ingest modules. Do not enable everything at once. While learning, run them one at a time and observe what each produces. Start with Recent Activity, Hash Lookup, Keyword Search, File Type Identification, Extension Mismatch Detector and Exif Parser.
- Read the results. Browse the Views and Results sections in the left tree. Deleted files, files whose extension does not match their content, and browser history appear here.
- Build a timeline. The Timeline view is the fastest way to understand when something happened.
- Tag findings. Tag every significant item, because the report is generated from those tags.
- Produce the report. Export HTML or Excel, then read it and add your technical narrative. An automated report alone is not an expert report.
Extension mismatch: your first real lesson
Autopsy's Extension Mismatch Detector compares a file's extension with its actual type. If someone created a file named hidden.jpg containing a ZIP archive, this module catches it. In forensics the signature (magic bytes), not the file name, is decisive. Seeing this once in practice makes the professional mindset click.
Autopsy versus commercial suites
| Criterion | Autopsy | Commercial suites (FTK, EnCase) |
|---|---|---|
| Cost | Free | High annual licence |
| Learning curve | Low | Moderate to high |
| Indexing speed | Can slow on very large images | Optimized, distributed processing |
| Mobile support | Limited | Strong, through separate products |
| Extensibility | Python and Java modules, large community | Proprietary scripting |
| Court acceptance | Fine when the method is documented | Benefit of wide familiarity |
The most misunderstood item is court acceptance. A tool being free does not weaken your report. What matters is that the method is documented, verifiable and reproducible by an independent expert. The NIST tool testing programme (CFTT) tests open source tools as well.
A path to build your skills
Month one. Learn the TSK commands. Navigate an image using only the command line. Find partitions with mmls, see a deleted record with fls, extract it with icat.
Month two. Examine the same image in Autopsy and map each interface action to the underlying command. Practice timeline and keyword search.
Month three. Write reports. Finding something and explaining it are different skills, and in court the second one decides.
After that. Move to memory analysis, because disk is only half the story. Then open up to network and mobile.
Frequently asked questions
Is Autopsy really free, and is it used commercially? Yes, it is open source and free, and it is used in commercial examinations. The constraint is not the licence but the examiner's method and report.
Can I acquire a disk image with Autopsy? No. Autopsy is an analysis tool. Use FTK Imager, Guymager or dd for imaging.
Which operating system should I use? Windows creates the least friction while learning. Working with TSK commands on Linux is more instructive.
Does Autopsy examine mobile devices? Only to a limited extent. Mobile requires dedicated and usually commercial tools.
Where do I find images to practice on? NIST CFReDS, Digital Corpora and DFRWS datasets are free and lawful. Never examine someone else's device without authorization.
Is there a certification? There is no formal certification specific to Autopsy. The industry recognizes GCFE, GCFA and EnCE, though employers mostly assess practical ability.
Sources
- Autopsy official site and documentation: https://www.autopsy.com
- The Sleuth Kit: https://www.sleuthkit.org
- NIST CFReDS reference data sets: https://cfreds.nist.gov
- Digital Corpora, academic scenario images: https://digitalcorpora.org
- NIST Computer Forensics Tool Testing programme: https://www.nist.gov/itl/ssd/software-quality-group/computer-forensics-tool-testing-program-cftt
To plan hands on forensics training for your team or to get expert support on a case, contact DSET. From our Ankara Hacettepe Teknokent laboratory we run examinations, training and expert reporting.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.