Autopsy | Tryhackme Walkthrough

Rahul Kumar
3 min readApr 30, 2023

--

What is Autopsy?

“Autopsy is the premier open-source forensics platform which is fast, easy-to-use, and capable of analysing all types of mobile devices and digital media. Its plug-in architecture enables extensibility from community-developed or custom-built modules. Autopsy evolves to meet the needs of hundreds of thousands of professionals in law enforcement, national security, litigation support, and corporate investigation.”

Workflow Overview and Case Analysis:

Ques 1: What is the file extension of the Autopsy files?

Ans: .aut

Data Sources:

Ques 1: What is the disk image name of the “e01” format?

Ans: encase

The User Interface I:

Ques 1: Expand the “Data Sources” option; what is the number of available sources?

Ans: 4

Ques 2: What is the number of the detected “Removed” files?

Ans: 10

Check Recycle bin, which is under the Results, Extracted Contents section.

Ques 3: What is the filename found under the “Interesting Files” section?

Ans: googledrivesync.exe

The User Interface II:

Ques 1: What is the full name of the operating system version?

Ans: windows 7 ultimate service pack 1

Ques 2: What percentage of the drive are documents? Include the % in your answer.

Ans: 40.8%

Ques 3: Generate an HTML report as shown in the task and view the “Case Summary” section.
What is the job number of the “Interesting Files Identifier” module?

Ans: 10

Data Analysis:

Ques1: What is the name of an Installed Program with the version number of 6.2.0.2962?

Ans: ERASER

Ques 2: A user has a Password Hint. What is the value?

Ans: IAMAN

Hint: check “Operating System User Account”

Ques 3:Numerous SECRET files were accessed from a network drive. What was the IP address?

Ans: 10.11.11.128

Ques 4: What web search term has the most entries?

Ans: Information Leakage Case

Hint: Check “Web Searches”

Ques 5: What was the web search conducted on 3/25/2015 21:46:44?

Ans:anti-forensic tools

Ques 6: What MD5 hash value of the binary is listed as an Interesting File?

Ans: fe18b02e890f7a789c576be8abccdc99

Ques 7: What self-assuring message did the ‘Informant’ write for himself on a Sticky Note? (no spaces)

Ans: Tomorrow…Everything will be OK…

Visualisation Tools:

Ques 1: Using the Timeline, how many results were there on 2015–01–12?

Ans: 46

Ques 2: The majority of file events occurred on what date? (MONTH DD, YYYY)

Ans: March 25, 2015

Thank You!

Resources: https://tryhackme.com/room/btautopsye0

--

--

Rahul Kumar
Rahul Kumar

Written by Rahul Kumar

Cybersecurity Enthusiast!! | COMPTIA SEC+ | CCSK | CEH | MTA S&N | Cybersecurity Analyst | Web Application Security

No responses yet