Posted in

The Sleuth Kit

The Sleuth Kit (TSK) is an open-source command-line digital forensics toolkit for analyzing disk images and file systems at a low level. It is the modern successor to The Coroner’s Toolkit (TCT) and provides significantly expanded file system support and functionality.

Supported File Systems

  • Windows: NTFS, FAT (12/16/32), exFAT
  • Linux: EXT (2/3/4), XFS
  • macOS: HFS+
  • Unix: UFS (1/2)

Key Functions & Tools

ToolDescription
File System Layer
fsstatDisplays file system details (layout, size, metadata structures).
flsLists files and directories, including deleted entries, from a disk image.
istatDisplays detailed metadata (inode/MFT entry) for a specific file or directory.
icatExtracts the content of a file using its inode or MFT reference number (useful for recovering deleted files).
findSimilar to Unix find, but operates on the image and can filter by timestamps, size, or inode values.
File Content Layer
blkcalcConverts between file system block addresses and disk sector addresses.
blklsExtracts unallocated space (data not assigned to any file) and outputs it for analysis or carving.
dlsList unallocated disk blocks (data not assigned to a file system).
sorterClassifies files by type (e.g., images, documents, executables) based on file signatures, or filters by extension.
Timeline & Search
mactimeGenerates a timeline of file system events (MAC: modification, access, change) from a body file.
hfindPerforms hash lookups against databases (e.g., NIST NSRL) to identify known files.
sigfindSearches for a specific binary pattern (like a file signature) within the image.

Basic Workflow

  1. Obtain a forensic image (dd or dcfldd).
  2. Use fsstat to confirm the file system structure.
  3. Run fls to list files and note deleted entries.
  4. Use istat on suspicious inodes for metadata (timestamps, size).
  5. Extract deleted files with icat.
  6. Generate a mactime timeline for activity mapping.
  7. Extract unallocated space (blkls) and run carving tools like foremost or scalpel.

Important Notes

  • TSK is a command-line toolkit, but the Autopsy GUI provides a web interface over TSK.
  • All TSK tools operate on a forensic image (E01, dd, raw) and should not be run on a mounted live system.
  • It is cross-platform: Linux, macOS, and Windows (via Cygwin or WSL).
  • Development is active, with regular updates for newer file system versions.

Leave a Reply

๐Ÿ’ 

๐Ÿ”ต Best-selling hard drives, USB flash drives & SSDs everyone's buying.

Fast, reliable, and on sale now. Thousands pick these weekly โ€” don't miss Amazon's lowest storage prices.

โšก Top 10 Bestsellers
๐Ÿ† 4.7โ˜…+ Reviews
๐Ÿ“ฆ Prime Shipping
๐Ÿ‘‰ See today's best-selling Data storage on Amazon.com HDD ยท USB Flash Drives ยท SSD ยท External Drives
๐Ÿ›’
โœ… Updated hourly โ€” Amazon real-time ranking ๐Ÿ”ฅ Limited stock deals ๐Ÿ”— Affiliate
โญ Click to see complete best-selling list โญ