Filtering Evidence by Age in Autopsy

Autopsy doesn't have a built-in feature called the Autopsy Age Limit. The tool focuses on file carving, timeline analysis, keyword searches, and hash matching. When people talk about age limits in Autopsy, they're usually referring to one of two things: filtering recovered files or images by estimated age based on timestamps, or using third-party plugins for age estimation from photos, mostly in child exploitation investigations. The standard approach uses the Timeline view. You set a date range in the filter bar and it pulls up events within those boundaries. For example, if you're looking for activity between January 2023 and March 2023, you enter those dates and the timeline updates. It's straightforward but limited because timestamps can be manipulated or inaccurate. Here's where it gets messy. I spent three days on a case where the suspect had changed their system clock back by several years. The timestamps on the files looked legitimate on the surface, but the registry history showed the clock was adjusted multiple times. I cross-referenced the USN journal entries with the filesystem metadata and compared them against the network logs from the router to establish the real timeline. The apparent age range was off by about fourteen months once I did that.

If you're dealing with images and need actual age estimation from the content itself, Autopsy alone won't do that. You'd need to export the relevant images and run them through something like SINE or other dedicated age estimation software. Those tools are still experimental and not admissible everywhere, so use them as investigative leads, not courtroom evidence unless you've verified the jurisdiction's stance on it. Another thing that catches people off guard is that the Autopsy Age Limit concept gets conflated with the Data Family filter. You can set age ranges for filtering results by file modification or creation dates, but this only works for artifacts that actually carry those timestamps. A lot of browser artifacts, for instance, store access times rather than creation times, and some P2P applications deliberately randomize or strip metadata entirely. In those cases, any age-based filter returns nothing useful because the underlying data is missing or corrupted. If your case involves a lot of deleted files where timestamps are unreliable, I recommend running TSK's mactime first as a pre-processing step. It generates a sorted timeline from raw disk analysis before you even open Autopsy, and it catches artifacts that the GUI sometimes misses. The whole process takes about twenty minutes on a typical 500GB image, and it surfaces discrepancies between filesystem timestamps and actual recovery dates that you wouldn't see otherwise.

The main bottleneck with age-based filtering in Autopsy is that it doesn't distinguish between a file created on the date shown and a file whose timestamp was modified after creation. That's a fundamental limitation of any filesystem analysis tool. You need corroborating evidence from logs, cloud records, or auxiliary artifacts to confirm the actual age of the evidence. No amount of filtering around the Autopsy Age Limit concept will solve that problem on its own.

Get the Full Details

Autopsies by age | Flourish
Autopsies by age | Flourish