Analysis of Data Source Using Autopsy (original) (raw)

Last Updated : 28 Apr, 2026

The Sleuth Kit (TSK) is a collection of command-line tools used in digital forensics to analyze disk images, examine file systems, and recover deleted data without altering the original evidence. Autopsy provides a graphical interface for TSK, making analysis more accessible and efficient while preserving forensic integrity.

Steps for Data Analysis Using Autopsy

Follow the below steps to do analysis of data using autopsy:

**1. Getting Started

Autopsy Tool

**2. Adding a Data Source

Autopsy supports multiple types of data sources:

Data Sources in autopsy tool

mantooth.E01 file

**3. Configuring Ingest Modules

Ingest modules define how the data will be analyzed. Selecting the right modules is critical for effective investigation.

configure ingest modules

**Important Ingest Modules

configure ingest modules

After selecting relevant modules, click Next and then Finish.

**Exploring the Data Source

Once ingestion is complete, Autopsy organizes data into structured views.

**Data Source Information

data source information

**Partition Analysis

data sources

MSOCache

**Views in Autopsy

**1. File Type View

File type view

**2. Deleted Files

deleted files view

**3. File Size View

**Note: It is usually advised to not scan or extract any suspected files/ disks such as payload files, etc. in the main system, rather scan them in safe environments such as a virtual machine, and then extract the data, as they hold the possibility of being corrupt and may infect the examiner's system with viruses.

**Results Section

The Results panel provides extracted and analyzed insights:

extracted content

**Key Artifacts

Keyword Hints

e  mail messages

accounts

reportsconfigure reportsreports excelsheey

**Advanced Features

additional features

additional images/videos

communications

timeline

**Best Practices for Forensic Analysis