
Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.
Autopsy 4 http://www.sleuthkit.org/ 2016年3月15日
概述
Autopsy 是 The Sleuth Kit 及其他开源数字取证工具的图形界面。 Autopsy 3 是从 Autopsy 2 完全重写而来,使其基于 Java。 Autopsy 4 在 Autopsy 3 的基础上进行了改进,支持多个用户在同一案件上协作。
尽管 Autopsy 被设计为跨平台(Windows、Linux、MacOSX),但当前版本仅在 Windows 上功能完整且经过全面测试。 我们已在 XP、Vista 和 Windows 7 上运行过,未遇到任何问题。
Autopsy 4 根据 Apache 2.0 许可证发布。 Autopsy 使用的某些库可能采用不同但类似的开源许可证。
安装
对于 Windows 安装,所有 Autopsy 依赖项都已捆绑在所提供的安装程序中。 如果使用 Windows 安装程序,则无需手动安装其他依赖项。
如果您想要日语本地化版本,则必须安装日语语言包(http://support.microsoft.com/kb/972813),并将默认区域设置设为 JA。(http://windows.microsoft.com/en-us/windows/change-system-locale#1TC=windows-7)。
支持
启动 Autopsy 后,其中内置了帮助系统。安装程序还附带一份快速入门指南。
请将任何错误报告或功能请求发送至 sleuthkit-users 邮件列表。 http://www.sleuthkit.org/support.php
许可证
Autopsy 代码根据 Apache 许可证 2.0 版发布。详情请参阅 LICENSE-2.0.txt。
内嵌软件
本节列出了 Autopsy 所使用的软件组件和库。 除非另有说明,这些工具都随 Windows 安装程序捆绑提供。
JRE (Java Runtime Environment) 17
Netbeans 15 RCP 平台以及随该平台捆绑的 .jar 文件
用于分析磁盘镜像的 Sleuth Kit。
用于打开 E01 文件的 Libewf
用于打开 E01 文件的 zlib
用于关键词搜索的 Solr(包括 Lucene 和 TIKA)
用于查看视频文件的 GStreamer
用于查看视频文件的 GStreamer 1.x Java Core
用于提取近期活动的 Regripper (包括自定义插件)
用于提取 Internet Explorer 活动的 Pasco2
用于从 HTML 文件中提取内容的 Jericho
Advanced installer 9(免费软件) (未内嵌于 Autopsy 中,但用于生成 Autopsy 安装程序。)
用于提取 Exif 元数据的 Metadata Extractor 2.6.2
用于摄取模块加载的 Reflections 0.9.8
用于进程监控的 Sigar
用于 7Zip 提取器模块的 7Zip 和 7Zip java 绑定
用于在图像查看器中调整图像大小的 ImgScalr 4.2
ControlsFX JavaFX GUI 库
JFXtras JavaFX GUI 库
Mustache.java 模板系统
Joda-Time 日期与时间库
TwelveMonkeys ImageIO 插件
内嵌资源
本节列出了 Autopsy 所使用的其他资源,例如图标。
FAMFAMFAM Silk Icons v1.3
Fugue Icons v3.5.6
WebHostingHub Glyphs
Splashy Icons(完全免费)