This skill provides a structured framework for forensic investigators to analyze disk images (raw, E01, AFF) using Autopsy and command-line Sleuth Kit tools. It guides users through the entire forensic lifecycle, including case creation, ingest module configuration, deleted file recovery, keyword searching, and timeline reconstruction. Whether you are conducting an internal corporate investigation, incident response, or preparing legal evidence, this skill helps you uncover hidden artifacts and document findings professionally.
主要功能
01Chronological timeline reconstruction of system and user events
02Full-text keyword indexing and regex-based sensitive data searching
030 GitHub stars
04Comprehensive ingest module configuration for automated artifact extraction
05Automated deleted file recovery and file system metadata analysis
06Standardized forensic reporting and evidence tagging workflows