The Sleuth Kit logo

The Sleuth Kit

by Sleuth Kit Labs
No reviews yet
ActiveAvailable globallyFree tier
Quick facts
VendorSleuth Kit Labs
Year launchedN/A
StatusActive
LocationN/A
Countries servedGlobal
Languages1
IntegrationsN/A
Free tierYES
Free trialNO
Contact salesNO

About The Sleuth Kit

A C library and collection of open source command line tools for the forensic analysis of file systems like NTFS, FAT, EXT2FS, and FFS. It allows investigation of disk images and can be incorporated into larger digital forensics tools.

The Sleuth Kit (TSK) is an open-source digital forensics toolkit from Sleuth Kit Labs. It consists of a C library and a collection of command-line tools designed for in-depth analysis of disk images and file systems. TSK is a foundational engine that powers many other forensic tools, including the popular graphical interface Autopsy. It is aimed at digital investigators, law enforcement, and incident responders who need to perform detailed, low-level analysis of file systems such as NTFS, FAT, and ExtFS. As an open-source project, it is free to download and use. Support is available through community forums, with commercial training and support offered separately by Sleuth Kit Labs.

Pros & Cons

Pros
  • Completely open source and free to use for forensic analysis.
  • Provides a foundational C library for building custom forensic tools.
  • Supports a variety of common file systems for broad compatibility.
  • Serves as the underlying engine for the widely-used Autopsy GUI forensic tool.
Cons
  • The command-line interface can be challenging for users without a technical background.
  • Lacks a native graphical user interface; requires a separate tool like Autopsy for visual analysis.
  • Official support is primarily community-based, with paid options for dedicated support.

Features

Key features

File System Analysis

Analyzes volume and file system data from disk images.

Command Line Tools

Provides a collection of utilities for direct investigation of digital evidence.

C Library

Core functionality can be incorporated into larger custom digital forensics applications.

Multi-File System Support

Natively analyzes NTFS, FAT, EXT2FS, and FFS file systems.

Open Source

Freely available for use and integration into other forensic tools.

Additional features

Graphical User Interface

Autopsy offers a user-friendly visual environment for running forensic investigations.

Hard Drive Analysis

The software allows users to thoroughly examine physical hard drives for evidence.

Smartphone Forensics

Investigators can extract and analyze critical data from mobile devices.

Custom Plugins

Users can develop specialized add-on modules using Java or Python.

Command-Line Tools

The Sleuth Kit features a full suite of terminal-based utilities for deep file system analysis.

C Library Integration

A robust backend library allows developers to power external forensic programs.

File Recovery

The system can locate and rebuild deleted files from raw disk images.

BitLocker Support

Built-in capabilities allow investigators to decrypt and analyze BitLocker drives.

Experimental File Systems

The software features trial support for reading XFS and BtrFS Linux file systems.

Pricing

Free trial
Free version
Request a quote
Promo Offer

Countries & Languages

Global
Countries served
1
Interface languages
1
Billing currencies

Interface languages

English

Billing currencies

🇺🇸USD

No reviews yet

Be the first to drop a review

Alternatives to The Sleuth Kit

GeoShield logo

GeoShield

GeoShield is a policing software from GeoShield that provides solutions for command staff and crime…

Recoveryfix OST to PST Converter logo

Recoveryfix OST to PST Converter

Recoveryfix OST to PST Converter is a data recovery utility designed for IT administrators and…

Recoveryfix PST Password Recovery logo

Recoveryfix PST Password Recovery

Recoveryfix PST Password Recovery is an exceptionally reliable, lightweight tool built to handle a specific…

FARO Zone 3D (FARO.com) logo

FARO Zone 3D (FARO.com)

FARO Zone 3D is a forensic visualization software from FARO that supports the analysis, reconstruction,…

Autopsy logo

Autopsy

Autopsy is a digital forensics software from Sleuth Kit Labs that provides a comprehensive open-source…

Stellar Photo Recovery logo

Stellar Photo Recovery

Stellar Photo Recovery is a highly reliable data recovery application designed specifically for restoring lost,…

Spot something wrong or outdated?

Suggest a correction — a reviewer verifies every change.

Often compared with The Sleuth Kit

Compare any two tools →
GeoShield logo
GeoShield
Law Enforcement
0.0
Recoveryfix OST to PST Converter logo
Recoveryfix OST to PST Converter
Data Recovery
0.0
Recoveryfix PST Password Recovery logo
Recoveryfix PST Password Recovery
Password Management
0.0
FARO Zone 3D (FARO.com) logo
FARO Zone 3D (FARO.com)
Digital Forensics
0.0