The Sleuth Kit is a collection of command line tools and a C library that allows you to analyze disk images and recover files from them. Autopsy is an easy to use, GUI-based program that allows you to efficiently analyze hard drives and smart phones, with a plug-in architecture for add-on modules in Java or Python.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A library for read-only access to QEMU Copy-On-Write (QCOW) image files, supporting multiple versions and compression formats for digital forensics analysis.
A library for accessing and parsing Microsoft Internet Explorer cache files (index.dat) to extract URLs, timestamps, and cached content for digital forensic analysis.
A library for accessing and parsing Windows NT Registry File (REGF) format files, designed for digital forensics and registry analysis applications.
Stegextract is a Bash script that extracts hidden files and strings from images, supporting PNG, JPG, and GIF formats.
A library and set of tools for accessing and analyzing storage media devices and partitions for forensic analysis and investigation.
Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.
Exterro is a data risk management platform that optimizes e-discovery, digital forensics, and cybersecurity compliance operations.
A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.
A PowerShell-based incident response and live forensic data acquisition tool for Windows hosts.