Analyzing Apps and Communications with Autopsy

Track 2

Digital evidence from apps plays an increasingly important role in digital investigations. In this talk, we will discuss the capabilities of Autopsy to parse apps, analyze the results, and display communications. This has been a recent priority for Autopsy and we will also discuss how to add support for additional apps with minimal Python code.

Autopsy has long had support for basic Android databases and the number of support apps has recently increased quite a bit. This increase was enabled by a new way of locating and parsing databases. We’ll discuss those new apps and how you can contribute to the project.

Once you parse the data, you need to be able to see it. This talk will also show our new methods for displaying communications with recently added support for threading messages and correlating accounts.