
Autopsy
Autopsy is a free open-source digital forensics platform with a graphical interface to The Sleuth Kit for disk and artefact investigation.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- WindowsLinuxmacOS
- License
- Open source
- Reviewed
- Last reviewed 2 October 2026
What it is
Autopsy is a free open-source digital forensics platform and graphical front end to The Sleuth Kit (autopsy.com / sleuthkit.org). Examiners use it to investigate disk images and related artefacts for incident response, law-enforcement and corporate investigations, including HTB Academy-style forensics labs.
What it helps with
- Ingesting disk images and browsing file systems, unallocated space and recovered artefacts in a guided UI.
- Running hash sets, keyword search, web artefact extraction and timeline views during investigations.
- Supporting multi-core background analysis so early findings appear before a full ingest finishes.
- Extending workflows with modules for carving, multimedia metadata and third-party add-ons.
- Training analysts on an accessible GUI forensics stack beside Volatility-style memory tools.
- Deploying without a commercial licence for the core Apache-licensed Autopsy platform.
Who it's for
Digital forensics examiners, DFIR analysts and students who need a free GUI investigation platform as a peer to commercial forensic suites and memory-focused tools such as Volatility.
Worth knowing
Autopsy is free and open source. Official sites: autopsy.com and sleuthkit.org/autopsy. Basis Technologies / Sleuth Kit community maintain the project; confirm current download channels on the official download page.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.