etch  ] [  etch-m68k  ] [  lenny  ] [  squeeze  ] [  sid  ]
[ Source: sleuthkit  ]

Package: sleuthkit (2.06-3etch1)

Tools for forensics analysis

The Sleuth Kit (previously known as TASK) is a collection of UNIX-based command line file system and media management forensic analysis tools. The file system tools allow you to examine file systems of a suspect computer in a non-intrusive fashion. Because the tools do not rely on the operating system to process the file systems, deleted and hidden content is shown.

The media management tools allow you to examine the layout of disks and other media. The Sleuth Kit supports DOS partitions, BSD partitions (disk labels), Mac partitions, and Sun slices (Volume Table of Contents). With these tools, you can identify where partitions are located and extract them so that they can be analyzed with file system analysis tools.

When performing a complete analysis of a system, we all know that command line tools can become tedious. The Autopsy Forensic Browser is a graphical interface to the tools in The Sleuth Kit, which allows you to more easily conduct an investigation. Autopsy provides case management, image integrity, keyword searching, and other automated operations.

The Sleuth Kit's upstream homepage can be found at http://www.sleuthkit.org/sleuthkit/.

Tags: System Administration: Forensics and Recovery, User Interface: Command Line, Role: Program, Scope: Utility

Other Packages Related to sleuthkit

  • depends
  • recommends
  • suggests
  • dep: file
    Determines file type using "magic" numbers
  • dep: libc6 (>= 2.3.5-1) [not alpha, i386, ia64]
    GNU C Library: Shared libraries
    also a virtual package provided by libc6-udeb
    dep: libc6 (>= 2.3.6-6) [i386]
  • dep: libc6.1 (>= 2.3.5-1) [alpha, ia64]
    GNU C Library: Shared libraries
    also a virtual package provided by libc6.1-udeb
  • dep: libdate-manip-perl
    a perl library for manipulating dates
  • dep: libgcc1 (>= 1:4.1.1-12) [not hppa]
    GCC support library
  • dep: libgcc4 (>= 4.1.1-12) [hppa]
    GCC support library
  • dep: libssl0.9.8 (>= 0.9.8c-1)
    SSL shared libraries
    also a virtual package provided by libcrypto0.9.8-udeb
  • dep: libstdc++6 (>= 4.1.1-12)
    The GNU Standard C++ Library v3
  • dep: libunwind7 (>= 0.98.5-6) [ia64]
    A library to determine the call-chain of a program - runtime
  • dep: zlib1g (>= 1:1.2.1)
    compression library - runtime
    also a virtual package provided by zlib1g-udeb

Download sleuthkit

Download for all available architectures
Architecture Package Size Installed Size Files
alpha 2,321.3 kB7356 kB [list of files]
amd64 2,022.7 kB5568 kB [list of files]
arm 2,109.9 kB6108 kB [list of files]
hppa 2,302.1 kB6668 kB [list of files]
i386 2,120.1 kB5872 kB [list of files]
ia64 3,068.9 kB12596 kB [list of files]
mips 2,319.3 kB8676 kB [list of files]
mipsel 2,311.0 kB8676 kB [list of files]
powerpc 2,081.3 kB6476 kB [list of files]
s390 2,251.9 kB6660 kB [list of files]
sparc 1,989.9 kB6300 kB [list of files]