The basic use of Autopsy and FTK Imager is essential for anyone beginning in computer forensics. These tools help you examine digital devices and gather important data for investigations. This guide will explain their main features and steps to use them practically.

Autopsy is a free, open-source forensic tool that works through a graphical interface. It helps examine hard drives, memory cards, and other storage devices. Autopsy can recover deleted files, view internet history, check emails, and find hidden evidence. It organises findings in an easy-to-understand report.
Autopsy is user-friendly and good for beginners. It supports multiple file systems like FAT, NTFS, and exFAT, common in South African computers and devices.
FTK Imager is a free tool that creates forensic images of storage devices. An image is an exact copy of the data on the device. This tool is often used before analysis, so the original evidence stays safe. FTK Imager can also preview files on a device without changing them.
FTK Imager is important because it protects the original evidence. Only work on copies to avoid changing or damaging data.
First, use FTK Imager to create a full copy of the digital device you want to investigate. This keeps the original safe and untouched. Then, open the image copy with Autopsy to start your forensic examination. Combining these tools helps ensure you follow a proper process that is accepted in courts and legal situations.
These tools are easy to learn and widely used by forensic investigators worldwide, making them perfect starting points for beginners in computer forensics in South Africa.
Live Scenario • Active Situation
You are a junior digital forensic analyst tasked with examining a seized laptop using Autopsy and FTK Imager to find evidence of data theft before a deadline.
There is no single perfect answer. Choose what you would do in this situation.