autopsy
« Back to VersTracker
Description:
Graphical interface to Sleuth Kit investigation tools
Type: Formula  |  Latest Version: 2.24@0  |  Tracked Since: Dec 17, 2025
Links: Homepage  |  formulae.brew.sh
Category: Security
Tags: forensics security investigation disk-analysis gui
Install: brew install autopsy
About:
Autopsy provides a graphical front-end for the Sleuth Kit and other digital investigation tools. It enables investigators to analyze disk images and file systems to recover artifacts and timeline data. The interface streamlines the process of carving files, viewing metadata, and generating reports.
Key Features:
  • Timeline analysis for visualizing events across the file system
  • File carving and hash filtering to identify known files or suspicious content
  • Extensible modular architecture for adding new analysis capabilities
  • Integrated reporting tools to document findings
Use Cases:
  • Digital forensics investigations and incident response
  • Data recovery and artifact extraction from disk images
  • Academic or training exercises in cybersecurity
Alternatives:
  • Sleuth Kit (CLI) – Autopsy provides a GUI on top of Sleuth Kit's command-line tools for easier analysis and visualization.
  • FTK Imager – A proprietary alternative focused on imaging and preview; Autopsy is open-source and offers deeper analysis workflows.
License: GPL-2.0-or-later
Dependencies: sleuthkit, file-formula, grep, md5sha1sum
Bottles available for: arm64_sequoia, arm64_sonoma, arm64_ventura, arm64_monterey, arm64_big_sur, sonoma, ventura, monterey, big_sur, catalina, x86_64_linux
Important Notes:
By default, the evidence locker is in:
  $HOMEBREW_PREFIX/var/lib/autopsy
Version History
Detected Version Rev Change Commit
Sep 14, 2024 10:42pm 0 VERSION_BUMP 78040545