Collection of command-line tools for disk image forensic analysis
The Sleuth Kit (TSK) is a library and collection of command-line tools for investigating disk images at the volume and filesystem level. It supports NTFS, FAT, Ext2/3/4, HFS+, UFS, and other filesystems, enabling analysis of file metadata, deleted file recovery, and timeline generation.