2011-10-12 04:13:57 +02:00
|
|
|
The Sleuth Kit (TSK) is a library and collection of command line tools that
|
2012-11-30 08:53:56 +01:00
|
|
|
allow you to investigate volume and file system data. The library can be
|
|
|
|
incorporated into larger digital forensics tools and the command line tools
|
|
|
|
can be directly used to find evidence.
|
2003-09-08 13:24:01 +02:00
|
|
|
|
2012-11-30 08:53:56 +01:00
|
|
|
The media management tools allow you to examine the layout of disks and
|
|
|
|
other media. The Sleuth Kit supports DOS partitions, BSD partitions (disk
|
|
|
|
labels), Mac partitions, Sun slices (Volume Table of Contents), and GPT
|
|
|
|
disks. With these tools, you can identify where partitions are located and
|
|
|
|
extract them so that they can be analyzed with file system analysis tools.
|
2005-01-20 11:38:42 +01:00
|
|
|
|
2007-06-05 18:14:44 +02:00
|
|
|
WWW: http://www.sleuthkit.org/sleuthkit/
|