Autopsy是数字取证工具"The Sleuth Kit(TSK)"的图形界面,一款用来分析磁盘镜像和数据恢复的开源取证工具。开提供在磁盘镜像中进行字符串提取,恢复文件,时间轴分析,浏览器等浏览历史分析,关键字搜索和邮件分析等功能,现在新增了输入BitLocker恢复密钥解密镜像和Cyber Triage插件协作分析功能---【蘇小沐】
Autopsy难得更新一次,作为一款开源免费的计算机取证软件一直坚持到现在实属不易,点赞!!!
晚上冷不丁的收到Autopsy更新邮件,没想到啊!终于更新了。
Hello su,
Autopsy 4.22.0 is available.
Big features:
-
-
Ability to run with Cyber Triage.
-
Lower-level libraries updates.
Important links:
-
Download the release here.
-
Get the full release notes here.
-
Download an evaluation copy of Cyber Triage here.
-
Register for an intrusions webinar with Brian Carrier here.
BitLocker
If you have a BitLocker encrypted drive, you can enter the recovery key when you add the drive and Autopsy (via The Sleuth Kit) will be able to decrypt it.
Run Alongside Cyber Triage
You can now run Autopsy and Cyber Triage at the same time. This scenario would come about when investigators would first use Cyber Triage to get a basic understanding of what happened on a host, then pivot to Autopsy to perform a deeper dive.
About Cyber Triage
Cyber Triage is built by the same engineers as Autopsy. It is focused on computer intrusions and remote access. Its main benefit is the automated analysis that allows you to focus on a subset of artifacts instead of forcing you to review thousands.
Use cases include:
-
Corporate security team investigating a host after an EDR alert.
-
Incident response teams investigating an entire network.
-
Law enforcement looking for remote access on CSAM cases in response to Trojan Defense.
You can get a free 7-day evaluation from here.
Intrusions Webinar with Brian Carrier
If you work in corporate security, Brian Carrier and Markus Schober are hosting a webinar on March 27th you might want to attend. It’s all about the attacker activity EDRs miss before the alert and how to find it.
They will cover:
-
-
-
How attacks are detected.
-
How to find pre-alert activity.
You can register here.
Download Autopsy
You can download the latest Autopsy from here. |
Sleuth Kit Labs, 1070 Broadway, Somerville, MA 02144, United States
UnsubscribeManage preferences |
|
|
主要新增两点功能:支持输入BitLocker恢复密钥解密硬盘和Cyber Triage协作分析功能。
对于BitLocker加密的驱动器,可以在添加驱动器时输入恢复密钥,Autopsy(通过侦察工具包)将能够解密它。
![【电子取证篇】Autopsy数字取证开源软件2025年更新]()
同时运行Autopsy和Cyber Triage,与网络罪犯并肩作战。
Cyber Triage专注于计算机入侵和远程访问。它的主要好处是自动化分析,使您能够专注于工件的一个子集,而不是强迫您审查数千个工件。当调查人员首先使用网络分类来基本了解主机上发生的事情,然后转向Autopsy进行更深入的调查。(商业插件,可免费申请的7天评估试用)
注意,虽然Autopsy是免费软件,但里面集成了部分商用的插件,所以取证的时候默认勾选的就行。
用例包括:
公司安全团队在EDR警报后调查主机。
事故响应小组调查整个网络。
执法部门正在寻找对CSAM案件的远程访问,以应对特洛伊木马防御。
Brian Carrier的入侵网络研讨会,如果你从事企业安全工作,Brian Carrier和Markus Schober将于3月27日举办一场网络研讨会,你可能会想参加。这一切都是关于EDR在警报之前错过的攻击者活动以及如何找到它。
它们将涵盖:攻击生命周期,EDR规避策略,如何检测攻击。
同时运行Autopsy和Cyber Triage,与网络罪犯并肩作战。
Cyber Triage专注于计算机入侵和远程访问。它的主要好处是自
【https://www.autopsy.com/download/】
【https://github.com/sleuthkit/autopsy】
【https://www.sleuthkit.org/autopsy/】
【https://www.cybertriage.com/】
评论