The Sleuth Kit

The Sleuth Kit (TSK) is a digital forensics library and collection of command line tools that enable you to analyze disk images. The TSK Framework makes it easier to build end-to-end digital forensics solutions. TSK can be used in isolation, with the Autopsy user interface, or with one of the many Tools Using TSK or Autopsy.

You can get the official list of features at the sleuthkit.org site.

Capabilities

A summary of the tools contained in TSK can be found on the TSK Tool Overview page. Currently, TSK supports the following file systems:

Additional Information

General Information


Last modified: 2014-01-15