The Sleuth Kit and Autopsy
From Just Solve the File Format Problem
(Difference between revisions)
(Created page with "[http://www.sleuthkit.org/sleuthkit/ The Sleuth Kit] (TSK) is a C library and a set of command line tools for forensic analysis of filesystems and disk images. [http://www.sle...") |
(DEFAULTSORT) |
||
(2 intermediate revisions by 2 users not shown) | |||
Line 1: | Line 1: | ||
+ | {| | ||
+ | |[[Software]] | ||
+ | | > | ||
+ | |[[File rendering/interaction software]] | ||
+ | | > | ||
+ | |[[The Sleuth Kit and Autopsy]] | ||
+ | |} | ||
+ | |||
[http://www.sleuthkit.org/sleuthkit/ The Sleuth Kit] (TSK) is a C library and a set of command line tools for forensic analysis of filesystems and disk images. [http://www.sleuthkit.org/autopsy/ Autopsy] is a graphical front end for TSK and provides some additional features on top of it, including extracting and searching the text contents from multiple file formats over an entire image. | [http://www.sleuthkit.org/sleuthkit/ The Sleuth Kit] (TSK) is a C library and a set of command line tools for forensic analysis of filesystems and disk images. [http://www.sleuthkit.org/autopsy/ Autopsy] is a graphical front end for TSK and provides some additional features on top of it, including extracting and searching the text contents from multiple file formats over an entire image. | ||
Line 15: | Line 23: | ||
* [[HFS]] | * [[HFS]] | ||
* [[ISO 9660]] / CDFS (Compact Disc File System) | * [[ISO 9660]] / CDFS (Compact Disc File System) | ||
+ | |||
+ | {{DEFAULTSORT:Sleuth Kit and Autopsy, The}} | ||
+ | [[Category:Software]] | ||
+ | [[Category:Forensics and Law Enforcement]] |
Latest revision as of 20:31, 3 July 2015
Software | > | File rendering/interaction software | > | The Sleuth Kit and Autopsy |
The Sleuth Kit (TSK) is a C library and a set of command line tools for forensic analysis of filesystems and disk images. Autopsy is a graphical front end for TSK and provides some additional features on top of it, including extracting and searching the text contents from multiple file formats over an entire image.
Supported disk and file system image formats
- raw (i.e. dd)
- Expert Witness (i.e. EnCase)
- AFF
Supported file systems: