The Sleuth Kit and Autopsy

From Just Solve the File Format Problem
Revision as of 07:03, 1 November 2012 by Pidge (Talk | contribs)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

The Sleuth Kit (TSK) is a C library and a set of command line tools for forensic analysis of filesystems and disk images. Autopsy is a graphical front end for TSK and provides some additional features on top of it, including extracting and searching the text contents from multiple file formats over an entire image.

Supported disk and file system image formats

  • raw (i.e. dd)
  • Expert Witness (i.e. EnCase)
  • AFF

Supported file systems:

Personal tools