# The Sleuth Kit

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

Repository: https://github.com/sleuthkit/sleuthkit
Canonical: https://ross.abutalabs.com/products/the-sleuth-kit
Homepage: http://www.sleuthkit.org/sleuthkit/
Language: C
License Family: other
Topics: sleuthkit, tct, ntfs, forensics, incident-response
Last push: 2026-08-19T03:11:29+00:00
Link (homepage): http://www.sleuthkit.org/sleuthkit/
Link (site_page): http://www.sleuthkit.org/autopsy/features.php
Link (site_page): http://www.sleuthkit.org/autopsy/docs.php
Link (site_page): http://www.sleuthkit.org/sleuthkit/docs.php
Link (site_page): http://www.sleuthkit.org/about.php

## Health v2 (maintenance only)
Score: 81/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 98, release rhythm 47, longevity 100
- inputs: {"age_days": 5439, "days_push": 14, "days_rel": 140, "gap_med": 199.5, "n_releases_24m": 3}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3137, forks 704 (observed 2026-08-28T04:07:45.723669+00:00)

## What it is
Autopsy is a Java-based digital forensics platform providing a graphical interface to The Sleuth Kit and other open-source forensic tools for investigating disk images, local drives, and mobile devices. The Sleuth Kit itself is a C library and collection of command-line tools for volume and file system analysis that can be embedded into larger forensic applications.

## Use cases
- investigate a disk image for evidence of a security incident
- recover deleted photos from a camera memory card
- analyze web browsing history and registry activity on a seized computer
- extract SMS and call logs from an Android phone
- build a timeline of system activity during a forensic case
- search disk images for keywords or regex patterns
- filter known good files using NSRL hash sets
- embed file system analysis into a custom forensic tool

## When to choose
- you need a full-featured open-source forensic workbench with timeline, keyword search, and artifact analysis
- you are a law enforcement, corporate, or independent examiner analyzing disk images or mobile devices
- you want a scriptable C library and CLI tools for file system forensics to integrate into your own tooling

## When to avoid
- you need a fully supported cross-platform GUI - Autopsy is only fully tested on Windows
- you need real-time network intrusion detection rather than offline disk analysis
- you require commercial support or certified forensic tooling for court proceedings

## Facets
- artifact type: application
- maturity: active
- function: search-engine, image-processing, file-system, parser, gui, cli, plugin-system
- domain: security, developer-tools, files
- platform: windows, jvm, cross-platform, cli
- tags: digital-forensics, disk-image-analysis, incident-response, file-system-analysis, mobile-forensics, timeline-analysis, keyword-search, registry-analysis, forensics, linux, macos

## Member repositories
- sleuthkit/sleuthkit (main) score 81
- sleuthkit/autopsy (frontend) score 84

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:45.723669+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:22:41.729508+00:00, confidence not recorded.
  - readme: https://github.com/sleuthkit/sleuthkit (fetched 2026-08-28T04:07:45.723669+00:00, sha b26da2a87e8f)
  - homepage: http://www.sleuthkit.org/sleuthkit/ (fetched 2026-08-29T09:35:35.718067+00:00, sha f2dbce254be9)
  - site_page: http://www.sleuthkit.org/autopsy/features.php (fetched 2026-08-29T09:35:35.720980+00:00, sha d27059bde7ed)
  - site_page: http://www.sleuthkit.org/autopsy/docs.php (fetched 2026-08-29T09:35:35.722730+00:00, sha dc02e55aa739)
  - site_page: http://www.sleuthkit.org/sleuthkit/docs.php (fetched 2026-08-29T09:35:35.724369+00:00, sha eba3525a0a45)
  - site_page: http://www.sleuthkit.org/about.php (fetched 2026-08-29T09:35:35.726072+00:00, sha c4dfddcab92c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
