A C library and collection of open source command line tools for the forensic analysis of file systems like NTFS, FAT, EXT2FS, and FFS. It allows investigation of disk images and can be incorporated into larger digital forensics tools.
The Sleuth Kit (TSK) is an open-source digital forensics toolkit from Sleuth Kit Labs. It consists of a C library and a collection of command-line tools designed for in-depth analysis of disk images and file systems. TSK is a foundational engine that powers many other forensic tools, including the popular graphical interface Autopsy. It is aimed at digital investigators, law enforcement, and incident responders who need to perform detailed, low-level analysis of file systems such as NTFS, FAT, and ExtFS. As an open-source project, it is free to download and use. Support is available through community forums, with commercial training and support offered separately by Sleuth Kit Labs.
Analyzes volume and file system data from disk images.
Provides a collection of utilities for direct investigation of digital evidence.
Core functionality can be incorporated into larger custom digital forensics applications.
Natively analyzes NTFS, FAT, EXT2FS, and FFS file systems.
Freely available for use and integration into other forensic tools.
Autopsy offers a user-friendly visual environment for running forensic investigations.
The software allows users to thoroughly examine physical hard drives for evidence.
Investigators can extract and analyze critical data from mobile devices.
Users can develop specialized add-on modules using Java or Python.
The Sleuth Kit features a full suite of terminal-based utilities for deep file system analysis.
A robust backend library allows developers to power external forensic programs.
The system can locate and rebuild deleted files from raw disk images.
Built-in capabilities allow investigators to decrypt and analyze BitLocker drives.
The software features trial support for reading XFS and BtrFS Linux file systems.
Be the first to drop a review
GeoShield is a policing software from GeoShield that provides solutions for command staff and crime…
Recoveryfix OST to PST Converter is a data recovery utility designed for IT administrators and…
Recoveryfix PST Password Recovery is an exceptionally reliable, lightweight tool built to handle a specific…
FARO Zone 3D is a forensic visualization software from FARO that supports the analysis, reconstruction,…
Spot something wrong or outdated?
Suggest a correction — a reviewer verifies every change.
A C library and collection of open source command line tools for the forensic analysis of file systems like NTFS, FAT, EXT2FS, and FFS. It allows investigation of disk images and can be incorporated into larger digital forensics tools.
Does The Sleuth Kit have an in-app market place?
Yes
How many Mini-Apps in the marketplace?
1
NO
USD
Community Forums
http://forum.sleuthkit.org/GeoShield is a policing software from GeoShield that provides solutions for command staff and crime…
Recoveryfix OST to PST Converter is a data recovery utility designed for IT administrators and…
Recoveryfix PST Password Recovery is an exceptionally reliable, lightweight tool built to handle a specific…
FARO Zone 3D is a forensic visualization software from FARO that supports the analysis, reconstruction,…