The Sleuth Kit (TSK) & Autopsy Logo

The Sleuth Kit (TSK) & Autopsy

0
Free
Visit Website

The Sleuth Kit is a collection of command line tools and a C library that allows you to analyze disk images and recover files from them. Autopsy is an easy to use, GUI-based program that allows you to efficiently analyze hard drives and smart phones, with a plug-in architecture for add-on modules in Java or Python.

FEATURES

ALTERNATIVES

An anti-forensic Linux Kernel Module kill-switch for USB ports.

A recognition framework for identifying products, services, operating systems, and hardware by matching fingerprints against network probes.

A community-sourced repository of digital forensic artifacts in YAML format.

Dump the contents of the location database files on iOS and macOS with output options like KML and CSV.

A network forensics tool for visualizing packet captures as network diagrams with detailed analysis.

Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.

Modern digital forensics and incident response platform with comprehensive tools.

Turbinia is an open-source framework for automating the running of common forensic processing tools to help with processing evidence in the Cloud.