The Sleuth Kit
Command-line tools and a C library for analysing disk images and recovering files in forensic work.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About The Sleuth Kit
The Sleuth Kit is a collection of command-line programs and a C library for examining disk images and file systems and recovering files from them. It is the engine behind the Autopsy graphical forensics program and is also used inside other open source and commercial forensics tools.
It suits investigators and analysts who prefer scripted, command-line analysis, or developers building forensics tooling. Version 4.15.0 was released in April 2026. Community mailing lists and forums provide support, and Sleuth Kit Labs sells training and support.
Strengths
- Analyses disk images and recovers files from the command line
- C library can be built into other tools
- Powers Autopsy and many other forensics programs
- Still receiving releases in 2026
Limitations
- Command-line only; use Autopsy for a graphical interface
- Requires familiarity with file system and forensics concepts
Details
- Pricing
- FreeFree and open source; commercial training and support are sold separately.
- License
- Open source, license not stated
- Developer
- Sleuth Kit Labs
- Platforms
- Command line
- How it runs
- Downloadable app
- Account
- Not required
- Works offline
- Yes
- Best suited for
- Forensic investigators who want scriptable disk image analysis
- Categories
- Disk tools, Security tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to The Sleuth Kit
Compare allSoftware that can replace The Sleuth Kit for an important use case, and what changes if you switch.
Autopsy
Digital forensics platform for disk, file and timeline analysis.
Autopsy puts a graphical case-management interface on The Sleuth Kit, adding keyword search, timelines and reporting, but ingesting large images takes hours.
Similar software
Related functionality, not necessarily a direct replacement.
CAINE
Ubuntu-based digital forensics live distribution.
OSFMount
A free Windows utility that mounts disk image files as drives and creates RAM disks.
Volatility 3
Memory forensics framework for extracting artefacts from RAM images.
Velociraptor
Endpoint monitoring and digital forensics platform driven by a query language.
unblob
Command-line extraction tool that finds and unpacks archives and compressed streams inside arbitrary binary files.
REMnux
Linux toolkit for reverse engineering and analysing malicious software.