Autopsy
Forensic analysis of hard drives and media. Recover deleted files, analyze artifacts, and generate reports.
Open the official app on www.autopsy.com
This tool is hosted by its maintainers. Click below to open www.autopsy.com in a new tab — it's their official demo.
Browse security tools →What's next with Autopsy?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Autopsy?
Autopsy is an open-source digital forensics platform designed for investigating digital evidence on computers, storage devices, and memory cards. It serves as a graphical interface for The Sleuth Kit (TSK), a collection of command-line tools for forensic analysis, enabling users to perform in-depth examinations of digital media. Law enforcement agencies, military units, corporate cybersecurity teams, and digital investigators use Autopsy to analyze data from compromised systems, recover deleted files, and reconstruct events during cyber incidents. The tool addresses the challenge of manually sifting through vast amounts of digital data by automating repetitive tasks and providing structured workflows for evidence collection and analysis. Its modular architecture allows integration with other forensic tools, making it a critical component in both incident response and criminal investigations. Autopsy streamlines the process of digital forensics by offering a centralized interface for tasks such as file system analysis, keyword searches, and timeline reconstruction. It supports a wide range of file systems and data sources, including Windows, macOS, Linux, and memory dumps. The platform is particularly valuable in scenarios where time-sensitive evidence must be preserved and analyzed, such as cybercrime investigations or data breaches. By leveraging the Sleuth Kit’s capabilities, Autopsy enables users to recover deleted or encrypted data, examine artifacts left by malware, and generate detailed reports for legal or technical documentation. Its open-source nature ensures continuous development and community-driven improvements, making it a trusted tool for professionals requiring, flexible forensic analysis.
How it works
Autopsy is a digital forensics platform built as a graphical interface for The Sleuth Kit (TSK) and other forensic tools. It enables investigators to analyze digital evidence from storage media, such as hard drives, memory cards, and USB devices. The tool is designed for use by law enforcement, military, and corporate cybersecurity teams to uncover details about past events, such as data breaches or cyberattacks. Its primary purpose is to automate and standardize the process of evidence collection, ensuring that data is preserved and analyzed in a forensically sound manner. The platform supports a broad range of operating systems, including Windows, Linux, and macOS, and can be extended with third-party modules. Autopsy is particularly useful for recovering deleted files, analyzing system artifacts, and reconstructing timelines of digital activity. By integrating with the Sleuth Kit, it provides advanced capabilities for examining file systems, memory dumps, and forensic artifacts, making it a cornerstone tool in digital investigations. Autopsy allows users to perform file system analysis, keyword searches, and timeline reconstruction across multiple data sources. It supports the recovery of deleted files, including those from formatted drives or encrypted partitions. The tool also includes features for examining system logs, registry entries, and browser history to identify user activity. Its integration with the Sleuth Kit enables advanced tasks like memory analysis, disk imaging, and hash-based file identification. Additionally, Autopsy can analyze network traffic and forensic artifacts from incident response scenarios, providing a comprehensive view of digital evidence.
How to use it
- 1Download the Autopsy ZIP file for Linux/macOS or the 64-bit MSI installer for Windows. 2. Install dependencies such as The Sleuth Kit (TSK) and Java, following the provided instructions. 3. Launch Autopsy and select the target storage media or image file for analysis. 4. Configure analysis profiles, such as file system type and search parameters, then initiate the investigation. 5. Review results in the integrated interface, using filters and reports to identify relevant evidence. Practical tips include verifying system requirements before installation and utilizing third-party modules to extend functionality for specific tasks. For advanced users, Autopsy can be integrated with Cyber Triage, an automated DFIR tool, to streamline incident response workflows. This combination allows for rapid data collection and analysis, reducing the time required to investigate compromised systems. Users should also regularly update Autopsy and its dependencies to ensure compatibility with new file systems and forensic techniques.
What it can do
- digital forensics platform
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/sleuthkit/autopsy
- license: Apache-2.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- For authorized use only — use on systems you own or have explicit permission to test.
- Requires manual configuration and setup, which may pose a learning curve for new users.
- Depends on The Sleuth Kit for core functionality, limiting standalone operation without TSK.
- Lacks real-time analysis capabilities compared to some commercial forensic tools.
- Does not support advanced encryption analysis without additional plugins or tools.
Understanding the result
Forensic analysis of hard drives and media. Recover deleted files, analyze artifacts, and generate reports.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (Apache-2.0).
- Built with
- (sleuthkit/autopsy)
- License
- Apache-2.0
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with sleuthkit/autopsy. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- Apache-2.0
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- Apache-2.0 License
Upstream project
Frequently asked
What is Autopsy and what does it do?
Autopsy is an open-source digital forensics platform that serves as a graphical interface for The Sleuth Kit (TSK) and other forensic tools. It enables investigators to analyze digital evidence from storage media, such as hard drives, memory cards, and USB devices. Its primary functions include file system analysis, keyword searches, timeline reconstruction, and the recovery of deleted or encrypted data. Autopsy is used by law enforcement, military, and corporate cybersecurity teams to investigate cyber incidents, recover digital artifacts, and generate forensic reports for legal or technical purposes.
How does Autopsy integrate with The Sleuth Kit?
Autopsy leverages The Sleuth Kit (TSK) as its core forensic engine, providing a graphical interface to execute TSK commands. This integration allows users to perform advanced tasks like disk imaging, file system analysis, and memory analysis without manually running TSK commands. Autopsy abstracts the complexity of TSK by offering pre-configured analysis modules, enabling users to focus on interpreting results rather than managing low-level forensic operations. The tool also supports custom TSK plugins for extended functionality.
How do I recover deleted files using Autopsy?
To recover deleted files, first, mount the target storage media or image file in Autopsy. Navigate to the 'File System Analysis' module, select the drive or partition, and enable the 'Find Deleted Files' option. Autopsy will scan for files marked as deleted and display them in a list. Right-click on the desired file and choose 'Save As' to export it. For encrypted or fragmented files, additional modules or TSK commands may be required for full recovery.
How does Autopsy compare to commercial tools like EnCase or FTK?
Autopsy is an open-source alternative to commercial tools like EnCase or FTK, offering similar core forensic capabilities but with a different licensing model. Unlike EnCase or FTK, which are proprietary and require paid licenses, Autopsy is free to use and modify. It provides a flexible, extensible framework for digital forensics but lacks some advanced features found in commercial tools, such as real-time data processing, cloud integration, or enterprise-grade support. Autopsy is ideal for smaller teams or organizations with budget constraints, while commercial tools are often preferred for large-scale, high-stakes investigations.
How do I resolve an error during Autopsy installation?
Common installation errors include missing dependencies like The Sleuth Kit or Java. Verify that all required packages are installed by following the installation guide’s dependency checklist. For Linux users, ensure the system’s package manager is up to date and install any missing libraries. If the Sleuth Kit is not recognized, reconfigure the environment variables to include its installation path. For Windows users, check that Java is correctly installed and that the MSI installer has sufficient permissions. Consult the Autopsy GitHub repository’s issue tracker for error-specific solutions.