Autopsy (software)
Autopsy is computer software that makes it simpler to deploy many of the open source programs and plugins used in The Sleuth Kit. The graphical user interface displays the results from the forensic search of the underlying volume, making it easier for investigators to flag pertinent sections of data. The tool is largely maintained by Basis Technology Corp. with the assistance of programmers from the community. The company sells support services and training for using the product.
The tool is designed with these principles in mind:
- Extensible — the user should be able to add new functionality by creating plugins that can analyze all or part of the underlying data source.
- Centralized — the tool must offer a standard and consistent mechanism for accessing all features and modules.
- Ease of Use — the Autopsy Browser must offer the wizards and historical tools to make it easier for users to repeat their steps without excessive reconfiguration.
- Multiple Users — the tool should be usable by one investigator or coordinate the work of a team.
The core browser can be extended by adding modules that help scan the files (called "ingesting"), browse the results (called "viewing"), or summarize results (called "reporting"). A collection of open-source modules allows customization.
Autopsy tool can be used to recover WannaCry-infected data as well.