Sleuth kit
License / Price: Free ware
Version: v4.2.0
Language: English
File size: 11.1MB
Developer: TSK Framework
OS: Windows ( XP or Later )
9,487 views
The Sleuth Kit is a C++ library and collection of open source file system forensics tools that allow you to, among other things, view allocated and deleted data from NTFS, FAT, FFS, EXT2, Ext3, HFS+, and ISO9660 images.
Also added the following things ,
- ExFAT support added
- New database schema
- New Sqlite hash database
- Various bug fixes
- NTFS pays more attention to sequence and loads metadata only if it matches.
- Added secondary hash database index