[sleuthkit-users] Autopsy file analysis problem
Brought to you by:
carrier
From: Brad C. <bra...@gm...> - 2010-04-01 22:40:33
|
I am quite new to Linux forensics, but I have quickly developed a deep appreciation for how versatile many of the available tools are and how knowledgeable many of the people using them are. I recently downloaded the SIFT 2.0 workstation from SANS.org which has sleuthkit and autopsy 2.22 built into a VMware virtual machine. I also installed Fedora 12 and the latest version of autopsy as a second OS. Utilizing both of these I have been able to import a raw and an E01 image into the program, but when I go to the analyze screen the *File Analysis, File Type, and Meta Data* tabs are grayed out. Additionally, when I go to *Create Data File* under *File Activity Timelines* there are no images available for me to select. What am I missing? Thanks, Brad Celestin |