Autopsy 4: The Sleuth Kit's Java Forensics GUI, and What It Costs to Run
Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.
At a glance
- What is it?
- Autopsy is a graphical front end to The Sleuth Kit and other open source forensics tools, written in Java and released under Apache 2.0. It is built for examiners who need to investigate disk images, and its Windows installer is the only path the README describes as fully tested.
- Who is it for?
- Autopsy fits examiners who work on Windows and want a GUI over The Sleuth Kit plus ingest modules for keyword search, recent activity and carving. It does not fit anyone who needs a fully tested Linux or macOS build, or who expects a documented rollback when an ingest run goes wrong.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Yes. The repository last received commits 103 days ago.
- What is it written in?
- Mainly Java, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Autopsy is for, and who actually runs it
Autopsy is a graphical interface to The Sleuth Kit and other open source digital forensics tools. The README names its audience directly: law enforcement, military, and corporate examiners investigating what happened on a computer. The same document notes a consumer use case, recovering photos from a camera's memory card, which tells you the tool spans from hobbyist recovery to casework.
The design assumption is that the examiner wants a windowed application rather than a command line. The Sleuth Kit itself is a set of libraries and command line tools for file system analysis; Autopsy wraps that in a Java desktop application and adds ingest modules that run automatically against an image. Autopsy 3 was a complete rewrite from Autopsy 2 to make it Java-based, and Autopsy 4 improves on Autopsy 3 by supporting collaboration on a single case by multiple users. That collaboration point is the main reason to prefer 4 over 3.
If your work is scripted, headless, or driven from CI, the GUI is overhead. If your work is a case folder, a disk image, and a report you have to explain to someone else, the GUI is the point.
How the pipeline runs: image in, ingest modules out
The flow visible in the repository is: a disk image is opened, The Sleuth Kit parses the file system, and ingest modules process the resulting content in the background. The top level of the repository shows the module families as directories: KeywordSearch, RecentActivity, ImageGallery, Tika, ScalpelCarver, thunderbirdparser, and InternalPythonModules. Each is a separate concern rather than one monolith.
The embedded software list explains what sits underneath. Sleuth Kit handles disk image analysis. Libewf and zlib open E01 files, the forensic imaging format. Solr, including Lucene and TIKA, backs keyword search. Regripper pulls recent activity, Pasco2 pulls Internet Explorer activity, and Metadata Extractor 2.6.2 handles Exif metadata. GStreamer is there for viewing video files. Reflections 0.9.8 loads ingest modules, which is how the module directories above get wired in at runtime.
That layering matters when something fails. A keyword search that returns nothing points at Solr and the index, not at the file system parser. A file that will not open points at libewf or the image format. The README does not document a rollback path for a completed ingest run, so treat ingest as a one-way step on a case until you have verified otherwise.
Installing Autopsy on Windows and running a first case
The README is explicit that for a Windows installation, all Autopsy dependencies are bundled with the installer provided, and there is no need for manual installation of additional dependencies if the Windows installer is used. That includes the Java Runtime Environment 17 listed under embedded software. So the install is a download and a run, not a package manager command.
If you want the Japanese localized version, the README requires the Japanese language pack installed and the default locale set to JA. That is a Windows system setting, not an Autopsy setting, so it has to be in place before you start the application.
# The README gives no command line install. On Windows, run the provided installer.
# Dependencies, including JRE 17, are bundled with it.Once the application starts, the README points to two sources of instruction: a built-in help system and a QuickStart Guide that comes with the installer. A first case follows the GUI: create a case, add a disk image or the contents of a memory card, and let the ingest modules run. The repository also ships pythonExamples and InternalPythonModules, so the scripting surface exists, but the README does not document it and the QuickStart Guide is the place to look.
For a non-Windows build the repository provides Running_Linux_OSX.md, unix_setup.sh, and build-unix.xml. The README says Autopsy is designed to be cross-platform across Windows, Linux and MacOSX, then states that the current version is fully functional and fully tested only on Windows. Take that sentence literally: the Unix path exists in the tree, but the README does not claim it is tested to the same standard.
Where Autopsy stops being the right tool
The clearest limitation is stated by the project itself: the current version is fully functional and fully tested only on Windows. The README also lists XP, Vista, and Windows 7 as the environments where it was run without problems, which is a much older baseline than the Java 17 runtime listed under embedded software. An examiner on Linux or macOS is building from source with unix_setup.sh and build-unix.xml and accepting that the README does not vouch for the result.
The second limitation is the ingest model. Modules run against the image and produce derived data, and the README does not describe how to undo that. On a case where you need to demonstrate that the analysis is reproducible from the original image, an undocumented rollback is a real gap. Budget for re-running ingest from a clean case rather than assuming you can reverse a misconfigured run.
The third is scope. Autopsy is a desktop GUI over a set of bundled tools. If your requirement is a headless pipeline that processes hundreds of images on a schedule, the GUI is the wrong shape, and the right shape is The Sleuth Kit's own command line tools, which Autopsy is built on top of. Autopsy is also not a write blocker and not an acquisition tool; it analyzes images you already have.
Autopsy against command line The Sleuth Kit
The honest alternative is not a different vendor, it is The Sleuth Kit itself, used directly. Autopsy is a graphical interface to The Sleuth Kit and other open source digital forensics tools, so the underlying analysis engine is the same. The difference is what you get on top: a case database, a GUI, ingest modules that run automatically, and multi-user collaboration on a single case, which the README lists as the headline improvement in Autopsy 4.
Choosing between them comes down to whether you want the module pipeline. If you need keyword search over an image with the index built for you, RecentActivity parsing, image gallery extraction, and a Tika pass over documents, Autopsy assembles those for you and The Sleuth Kit alone does not. If you need to script a specific extraction across many images and you already know which TSK command you want, the GUI adds a case database and a Java runtime you do not need.
A second practical difference is packaging. The Windows installer bundles everything, including JRE 17. A command line TSK install is a package manager concern on Linux and macOS. That is the trade: Autopsy gives you a tested Windows bundle and a heavier runtime; TSK gives you a smaller footprint and no GUI.
Maintenance, releases and the licence position
The repository is not archived, and the last push was on 2026-06-20. Recent releases are autopsy-4.23.1 on 2026-05-07, autopsy-4.23.0 on 2026-04-15, and autopsy-4.22.1 on 2025-04-15. That gap between 4.22.1 and 4.23.0 is roughly a year, so the release cadence is not monthly and you should not plan around frequent updates. The develop branch is the default branch, which means the default checkout is not a release tag; pin to a release if you are deploying.
On licensing: the README states that Autopsy 4 is released under the Apache 2.0 license, and the repository contains LICENSE-2.0.txt. The same README adds a caveat that some libraries Autopsy uses may have different, but similar, open source licenses. The embedded software list shows that caveat is real: Regripper and Pasco2 are listed under GPL, Libewf and GStreamer under LGPL, and Jericho under LGPL. Those components are bundled with the Windows installer unless specified otherwise. If your organisation has rules about which licences may ship in a distributed product, that bundled set is what you need to review. This is a description of what the README says, not legal advice.
Upgrade cost is mostly the Java runtime. Autopsy 4 embeds JRE 17, so moving between releases moves the runtime with it. Verify the runtime version after any upgrade rather than assuming your system Java is used.
Editorial conclusion
Autopsy fits examiners who work on Windows and want a GUI over The Sleuth Kit plus ingest modules for keyword search, recent activity and carving. It does not fit anyone who needs a fully tested Linux or macOS build, or who expects a documented rollback when an ingest run goes wrong. Before committing, verify three things on your own hardware: that the Windows installer is the build you intend to deploy, that the Java 17 runtime bundled with it matches your environment, and that the ingest modules you rely on are present in the release you download. The repository's Running_Linux_OSX.md and unix_setup.sh are the starting point for a non-Windows build, and the README's own support channel is the sleuthkit-users mailing list.
Frequently asked questions
How do I install Autopsy on Windows?
Use the Windows installer provided by the project. The README states that all Autopsy dependencies are bundled with it, including the Java 17 runtime, so no manual dependency installation is needed. The installer also includes a QuickStart Guide.
How do I use Autopsy to recover deleted files?
The README describes Autopsy as a graphical interface to The Sleuth Kit and other open source digital forensics tools, and gives recovering photos from a camera's memory card as a use case. In practice you create a case, add the image or card contents, and let the ingest modules run. The README does not give step by step recovery instructions; the built-in help system and the QuickStart Guide that ships with the installer are the documented sources.
Can I run Autopsy on Linux or macOS?
The README says Autopsy is designed to be cross-platform across Windows, Linux and MacOSX, but that the current version is fully functional and fully tested only on Windows. The repository provides Running_Linux_OSX.md, unix_setup.sh and build-unix.xml for a non-Windows build. The README does not claim the Unix path is tested to the same standard.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/sleuthkit-autopsy)