All tools

Forensics

The Sleuth Kit

CLI tools for disk image forensic analysis.

intermediate
Linux
Forensics

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Scriptable disk forensics and learning filesystem internals.

How

fls, icat, mmls, tsk_recover on images.

Why

Understanding disks at the tool level.

Commands & usage

mmls disk.img
fls -r -o 2048 disk.img
icat -o 2048 disk.img <inode> > file

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

disk
cli
dfir

Related in Forensics