Keyword Search Configuration Dialog

The keyword search configuration dialog is used to add, remove, and modify keyword search lists.

To begin, select the 'New List' button and choose a name for the new Keyword List. Once the list has been created, keywords can be added to it. Regular expressions are supported using Java Regex Syntax. Lists can be added to the keyword search ingest process; searches will happen at regular intervals as content is added to the index.

List Import and Export

Autopsy supports importing Encase tab-delimited lists as well as lists created previously with Autopsy. For Encase lists, folder structure and hierarchy is currently ignored. This will be fixed in a future version. There is currently no way to export lists for use with Encase. This will also be added in future releases.

NIST NSRL Support

The hash database ingest service can be configured to use the NIST NSRL hash database of known files. The keyword search configuration dialog contains an option to skip keyword indexing and search on files found in the NSRL.

Keyword Search Configuration Dialog