The Sleuth Kit (TSK) & Autopsy
Open source digital forensics tools for analyzing hard drives, smartphones, and disk image
The Sleuth Kit (TSK) and Autopsy are open source digital forensics tools from Sleuth Kit Labs. Autopsy is a GUI-based program for analyzing hard drives and smartphones, while The Sleuth Kit is a collection of command-line tools and a C library for analyzing disk images and recovering files. Together, they support disk image analysis, file recovery, and investigation workflows, and The Sleuth Kit also powers other forensics tools.
Autopsy includes multi-user cases, timeline analysis, keyword search, web artifacts, registry analysis, LNK file analysis, email parsing, EXIF extraction, file type sorting, media playback, hash set filtering, tags, Unicode strings extraction, and Android data extraction. It analyzes disk images, local drives, or folders of files, including raw/dd and E01 formats, and generates HTML, Excel, and Body File reports. The Sleuth Kit supports common file systems including NTFS, FAT variants, ExFAT, HFS+, ISO9660, Ext2/3/4, Yaffs2, and UFS. Autopsy uses a plug-in architecture for add-on modules or custom development in Java or Python.
These tools are intended for investigators and analysts working on digital forensics cases. They are open source and available for download, with community support through email lists and forums. Sleuth Kit Labs also offers commercial training, support, and custom development.
4 alternatives to The Sleuth Kit (TSK) & Autopsy
Ranked by how well each tool replaces The Sleuth Kit (TSK) & Autopsy: shared features, audience, price and popularity.
Digital investigation for a new era – extract forensic data from computers, quicker and
Covers 1 of 15 key features and has a free plan.
Free plan51 out of 100 match$78.75/moOpen source security automation platform for teams and AI agents
Covers 0 of 15 key features and has a free plan.
Free planOpen source35 out of 100 matchFree