The Sleuth Kit 4.1.3 Description:
The Sleuth Kit (previously known as TASK) is an open source, freely distributed and multiplatform software project implemented in C/C++ and comprises of a set of utilities for investigating UNIX-like file systems. In other words, it is a collection of file system forensics tools that allow users to view deleted and allocated data from various Linux, Mac, BSD, Solaris or Windows file systems, including EXT2, EXT3, EXT4, NTFS, FAT16, FAT32, HFS+, ISO9660, UFS 1, UFS 2, and FFS. The Sleuth Kit is engineered in such a way that it allows the analization of raw, Expert Witness and AFF disk images and file systems. In addition, it creates time lines of file activity, displays details and contents of all NTFS attributes, and much more.