P2P forensic is a plugin developed for Autopsy Version 4.1.1.
The main purpose of this plugin is try to get usage information of P2P Windows programs in a forensics environment.
The current version has been developed using the following P2P programs:
- Emule v0.50a
- uTorrent 3.4.8
- bitTorrent 7.9.9
From a forensic view could be useful get information about the usage of P2P clients. Files downloaded or shared could change the sentence in court.
P2P forensic has been written in Python for installation you just need to place the folder inside the Python Module directory