etch  ] [  etch-m68k  ] [  lenny  ] [  squeeze  ] [  sid  ]
[ Source: sleuthkit  ]

Package: sleuthkit (2.52-1)

Tools for forensics analysis

The Sleuth Kit (previously known as TASK) is a collection of UNIX-based command line file system and media management forensic analysis tools. The file system tools allow you to examine file systems of a suspect computer in a non-intrusive fashion. Because the tools do not rely on the operating system to process the file systems, deleted and hidden content is shown.

The media management tools allow you to examine the layout of disks and other media. The Sleuth Kit supports DOS partitions, BSD partitions (disk labels), Mac partitions, and Sun slices (Volume Table of Contents). With these tools, you can identify where partitions are located and extract them so that they can be analyzed with file system analysis tools.

When performing a complete analysis of a system, we all know that command line tools can become tedious. The Autopsy Forensic Browser is a graphical interface to the tools in The Sleuth Kit, which allows you to more easily conduct an investigation. Autopsy provides case management, image integrity, keyword searching, and other automated operations.

The Sleuth Kit's upstream homepage can be found at http://www.sleuthkit.org/sleuthkit/.

Tags: System Administration: Forensics and Recovery, Data Recovery, User Interface: Command Line, Role: Program, Scope: Utility

Other Packages Related to sleuthkit

  • depends
  • recommends
  • suggests
  • dep: file
    Determines file type using "magic" numbers
  • dep: libc6 (>= 2.7-1) [not alpha, ia64]
    GNU C Library: Shared libraries
    also a virtual package provided by libc6-udeb
  • dep: libc6.1 (>= 2.7-1) [alpha, ia64]
    GNU C Library: Shared libraries
    also a virtual package provided by libc6.1-udeb
  • dep: libdate-manip-perl
    a perl library for manipulating dates
  • dep: libgcc1 [alpha]
    GCC support library
    dep: libgcc1 (>= 1:4.1.1-21) [not alpha, arm, armel, hppa]
    dep: libgcc1 (>= 1:4.3) [arm, armel]
  • dep: libgcc4 (>= 4.1.1-21) [hppa]
    GCC support library
  • dep: libstdc++6 [arm, ia64]
    The GNU Standard C++ Library v3
    dep: libstdc++6 (>= 4.1.1) [hppa, i386, powerpc, sparc]
    dep: libstdc++6 (>= 4.1.1-21) [alpha, amd64, mips, mipsel, s390]
    dep: libstdc++6 (>= 4.3) [armel]
  • dep: libunwind7 (>= 0.98.5-6) [ia64]
    A library to determine the call-chain of a program - runtime

Download sleuthkit

Download for all available architectures
Architecture Package Size Installed Size Files
alpha 2,122.4 kB4996 kB [list of files]
amd64 1,704.1 kB4072 kB [list of files]
arm 2,196.6 kB4673 kB [list of files]
armel 2,241.8 kB4904 kB [list of files]
hppa 2,165.2 kB4828 kB [list of files]
i386 1,921.8 kB5008 kB [list of files]
ia64 2,574.6 kB7608 kB [list of files]
mips 1,874.1 kB4984 kB [list of files]
mipsel 1,870.8 kB4988 kB [list of files]
powerpc 1,959.7 kB4504 kB [list of files]
s390 2,190.2 kB5128 kB [list of files]
sparc 1,951.0 kB4792 kB [list of files]