Forensics
The Sleuth Kit
CLI tools for disk image forensic analysis.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Scriptable disk forensics and learning filesystem internals.
How
fls, icat, mmls, tsk_recover on images.
Why
Understanding disks at the tool level.
Commands & usage
mmls disk.img
fls -r -o 2048 disk.img
icat -o 2048 disk.img <inode> > file
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Forensics
Volatility 3
Memory forensics framework for RAM dumps.
Autopsy
GUI digital forensics platform on The Sleuth Kit.
Wireshark / tshark
World-class packet capture and protocol analysis tool.
tcpdump
CLI packet capture utility.
ExifTool
Read/write metadata in files (images, docs, etc.).
steghide / zsteg / steghide tools
Steganography detection and extraction tools for CTFs and investigations.