Криминалистический анализ дисковых образов с Autopsy

★ 8.4 · security

analyzing-disk-image-with-autopsy is a Claude Code skill that performs comprehensive forensic analysis of raw (dd), E01 (EnCase), and AFF disk images using Autopsy 4.x and The Sleuth Kit. It walks through the full investigation workflow: creating an Autopsy case, enabling ingest modules such as Recent Activity, Hash Lookup, Keyword Search, Exif Parser, and Encryption Detection, recovering deleted files with fls, icat, and tsk_recover, running regex searches for PII like credit card numbers and SSNs, and building investigation timelines with visual reports. The skill is designed for digital forensics examiners who need structured evidence analysis across multiple disk images or must present findings to non-technical stakeholders.