Dear forensics enthusiasts!
Soon I will have to go out in the field and perform live forensics. I will have to perform keyword search and look for various documents.
I have a live Linux system on a USB stick with various utilities, including the latest version of Autopsy and I’m wondering how exactly does the keyword search works.
Time will be of an essence and thus I’m wondering how to approach this task. I intend to run the “Indexing and keyword search” module but I am wondering will it provide me with keyword hits from .docx and similar documents if I do not run the “Embedded file extractor” module beforehand?
Looking forward to your insight and thoughts on how to approache this task in the best possible way