Autopsy
Forensic tool for registry and file analysis
Description
As a forensic-grade application, Autopsy specializes in detailed registry analysis and comprehensive file system examination. The software processes evidence from multiple sources including disk images, local drives, and individual files, providing investigators with crucial insights into system activity and user behavior. Advanced features include automated artifact extraction, timeline reconstruction, and hash analysis. The integrated registry viewer enables deep inspection of Windows registry hives, revealing installed programs, user activity, and system configurations that are vital for digital investigations.
Screenshots

Click to view full size
