Autopsy | Tryhackme Walkthrough
What is Autopsy?
“Autopsy is the premier open-source forensics platform which is fast, easy-to-use, and capable of analysing all types of mobile devices and digital media. Its plug-in architecture enables extensibility from community-developed or custom-built modules. Autopsy evolves to meet the needs of hundreds of thousands of professionals in law enforcement, national security, litigation support, and corporate investigation.”
Workflow Overview and Case Analysis:
Ques 1: What is the file extension of the Autopsy files?
Ans: .aut
Data Sources:
Ques 1: What is the disk image name of the “e01” format?
Ans: encase
The User Interface I:
Ques 1: Expand the “Data Sources” option; what is the number of available sources?
Ans: 4
Ques 2: What is the number of the detected “Removed” files?
Ans: 10
Check Recycle bin, which is under the Results, Extracted Contents section.
Ques 3: What is the filename found under the “Interesting Files” section?
Ans: googledrivesync.exe
The User Interface II:
Ques 1: What is the full name of the operating system version?
Ans: windows 7 ultimate service pack 1
Ques 2: What percentage of the drive are documents? Include the % in your answer.
Ans: 40.8%
Ques 3: Generate an HTML report as shown in the task and view the “Case Summary” section.
What is the job number of the “Interesting Files Identifier” module?
Ans: 10
Data Analysis:
Ques1: What is the name of an Installed Program with the version number of 6.2.0.2962?
Ans: ERASER
Ques 2: A user has a Password Hint. What is the value?
Ans: IAMAN
Hint: check “Operating System User Account”
Ques 3:Numerous SECRET files were accessed from a network drive. What was the IP address?
Ans: 10.11.11.128
Ques 4: What web search term has the most entries?
Ans: Information Leakage Case
Hint: Check “Web Searches”
Ques 5: What was the web search conducted on 3/25/2015 21:46:44?
Ans:anti-forensic tools
Ques 6: What MD5 hash value of the binary is listed as an Interesting File?
Ans: fe18b02e890f7a789c576be8abccdc99
Ques 7: What self-assuring message did the ‘Informant’ write for himself on a Sticky Note? (no spaces)
Ans: Tomorrow…Everything will be OK…
Visualisation Tools:
Ques 1: Using the Timeline, how many results were there on 2015–01–12?
Ans: 46
Ques 2: The majority of file events occurred on what date? (MONTH DD, YYYY)
Ans: March 25, 2015
Thank You!
Resources: https://tryhackme.com/room/btautopsye0