Package sleuthkit
- blkcalc(1) β Converts between unallocated disk unit numbers and regular
- blkcat(1) β Display the contents of file system data unit in a disk image.
- blkls(1) β List or output file system data units.
- blkstat(1) β Display details of a file system data unit (i.e. block or sector)
- fcat(1) β Output the contents of a file based on its name.
- ffind(1) β Finds the name of the file or directory using a given inode
- fls(1) β List file and directory names in a disk image.
- fsstat(1) β Display general details of a file system
- hfind(1) β Lookup a hash value in a hash database
- icat(1) β Output the contents of a file based on its inode number.
- ifind(1) β Find the meta-data structure that has allocated a given
- ils(1) β List inode information
- img_cat(1) β Output contents of an image file.
- img_stat(1) β Display details of an image file
- istat(1) β Display details of a meta-data structure (i.e. inode)
- jcat(1) β Show the contents of a block in the file system journal.
- jls(1) β List the contents of a file system journal
- mactime(1) β Create an ASCII time line of file activity
- mmcat(1) β Output the contents of a partition to stdout
- mmls(1) β Display the partition layout of a volume system (partition tables)
- mmstat(1) β Display details about the volume system (partition tables)
- sigfind(1) β Find a binary signature in a file
- sorter(1) β Sort files in an image into categories based on file type
- tsk_comparedir(1)
- tsk_gettimes(1)
- tsk_loaddb(1)
- tsk_recover(1)
- usnjls(1) β List the contents of a NTFS Update Sequence Number journal