Ross ROSS = Recommend OSS · open-source software intelligence for agents

The Sleuth Kit

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence. observed · 2026-08-28

github.com/sleuthkit/sleuthkit · homepage · C observed · 2026-08-28

Health v2 · maintenance only

81/100

  • Activity 98
  • Release rhythm 47
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 199.5
  • age_days: 5439
  • days_rel: 140
  • days_push: 14
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

3137 stars · 704 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Autopsy is a Java-based digital forensics platform providing a graphical interface to The Sleuth Kit and other open-source forensic tools for investigating disk images, local drives, and mobile devices. The Sleuth Kit itself is a C library and collection of command-line tools for volume and file system analysis that can be embedded into larger forensic applications.

Use cases

  • investigate a disk image for evidence of a security incident
  • recover deleted photos from a camera memory card
  • analyze web browsing history and registry activity on a seized computer
  • extract SMS and call logs from an Android phone
  • build a timeline of system activity during a forensic case
  • search disk images for keywords or regex patterns
  • filter known good files using NSRL hash sets
  • embed file system analysis into a custom forensic tool

When to choose

  • you need a full-featured open-source forensic workbench with timeline, keyword search, and artifact analysis
  • you are a law enforcement, corporate, or independent examiner analyzing disk images or mobile devices
  • you want a scriptable C library and CLI tools for file system forensics to integrate into your own tooling

When to avoid

  • you need a fully supported cross-platform GUI - Autopsy is only fully tested on Windows
  • you need real-time network intrusion detection rather than offline disk analysis
  • you require commercial support or certified forensic tooling for court proceedings

Facets

application · maturity active

search-engine image-processing file-system parser gui cli plugin-system security developer-tools files windows jvm cross-platform cli digital-forensics disk-image-analysis incident-response file-system-analysis mobile-forensics timeline-analysis keyword-search registry-analysis forensics linux macos

6 sources

Member repositories

RepositoryRoleHealth v2
sleuthkit/sleuthkitmain81
sleuthkit/autopsyfrontend84

For agents

markdown · JSON · MCP: product_card(name="sleuthkit/sleuthkit")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem