sift icon indicating copy to clipboard operation
sift copied to clipboard

Autopsy 4?

Open salty4n6 opened this issue 1 year ago • 9 comments

Hi, Is Autopsy 4 on the roadmap? Autopsy 2.24 is a bit long in the tooth. ~Salty

salty4n6 avatar Oct 12 '22 23:10 salty4n6

I'm sure this should be possible. Right now we're installing it through the Ubuntu PPA, and that's pinned at 2.24. We'll likely have to build from source, so I'll take a look at what it'll take to get it working.

digitalsleuth avatar Oct 13 '22 20:10 digitalsleuth

Thank you.

salty4n6 avatar Oct 13 '22 22:10 salty4n6

Hi digitalsleuth,

I found this project over the weekend.

https://github.com/labcif/autopsy-packager

~Salty

salty4n6 avatar Oct 17 '22 12:10 salty4n6

Hey @salty4n6 , sorry for the delay, but I'm looking at this right now. It looks promising, but I need to confirm some dependency issues which seem to be popping up. I'll keep you posted.

digitalsleuth avatar Oct 22 '22 23:10 digitalsleuth

Hi @salty4n6 , I've taken a great deal of time trying to find a workaround with getting this into SIFT, however the primary issue is that Autopsy depends on certain older versions of libvmdk libewf and libvhdi, which have since been updated by Joachim Metz under the GIFT Repo.

The newer versions are already installed in SIFT, as is Sleuthkit, and this causes a conflict when trying to install Autopsy.

As a workaround, I've created a simple Autopsy docker which can be used within SIFT. If you'd like, you can take a look at it here. The instructions can be found in the repo, and the docker is already built and available on the Docker Hub.

Hopefully, until we find a more permanent solution, I hope this helps.

digitalsleuth avatar Feb 02 '23 21:02 digitalsleuth

@digitalsleuth - Looks awesome! Much appreciated. I'll kick the tires more soon but from what I've tested so far, it's great.

~Salty

salty4n6 avatar Feb 21 '23 19:02 salty4n6

@digitalsleuth want to sync on this issue at some point. Might be a good time to try and solve it. I've had at least one other request as of late.

ekristen avatar Aug 14 '23 20:08 ekristen

Sounds good to me. I'm away on vacation this week, but will be available this weekend!

digitalsleuth avatar Aug 14 '23 22:08 digitalsleuth

Hey @ekristen , I'm back from vacation and ready to take a look at this whenever you are.

digitalsleuth avatar Aug 20 '23 16:08 digitalsleuth