Sleuth kit

License / Price: Free ware
Version: v4.2.0
Language: English
File size: 11.1MB
Developer: TSK Framework
OS: Windows ( XP or Later )
1 Star2 Stars3 Stars4 Stars5 Stars (3 votes, average: 5.00 out of 5)

The Sleuth Kit is a C++ library and collection of open source file system forensics tools that allow you to, among other things, view allocated and deleted data from NTFS, FAT, FFS, EXT2, Ext3, HFS+, and ISO9660 images.

Also added the following things ,

  • ExFAT support added
  • New database schema
  • New Sqlite hash database
  • Various bug fixes
  • NTFS pays more attention to sequence and loads metadata only if it matches.
  • Added secondary hash database index

Leave a Reply