I am new here and this is completely new for me. Somebody had access to my computer about 15 months ago. He used his USB flash drive to print something but after printing that person spent maybe another 15 oder 20 minutes on the computer.
After I found out what kind of person that is, I am suspecting he stole data from my computer by copying to his usb flash drive. Is it possible with autopsy to know if that person did copy anything to his usb flash drive from my computer?
Buko1996, The answer to your questions is there is a probability to find the answer you seek. There are a lot of variables and without knowing more would be reckless to blindly answer your question. So…
After creating an image of the hard drive you can load it into Autopsy, process it and look at the timeline around the time you suspect. You can also look at the UserClass.dat file and pars it with Zimmermans tools to see what folders were previewed. My recommendation is to hire an examiner to seek the answers you want so if you plan on taking this person to court, you have a good case.