Autopsy (website, GitHub) is a Digital Forensics and Incident Response (DFIR) tool that allows users to process data sources (i.e. logical file sets, disk images, local disks, etc.), analyze the files in the file system, and view files and artifacts on the file system.
I would like to request the following for auto-connection for autopsy:
-
dm-crypt
,block-devices
,fuse-support
,removable-media
,mount-observe
, andsystem-files-dev
(system-files
read access to/dev
) to find and ingest data sources. -
system-files-hugepages
(system-files
read access to/sys/kernel/mm/hugepages
),hugepages-control
because we run Solr locally for indexing keywords in files, which in turn uses hugepages for performance implications. -
desktop-launch
to launch file manager to view autopsy log folders, web browsers online/offline help, and user default applications for opening extracted files in external applications.