Software Update: The Sleuth Kit 4.9.0

Spread the love

The program The Sleuth Kit is a collection of forensic tools that can be used to take a closer look at the hard drive. This makes it possible to recover or partially view deleted files. Support for ntfs, fat, exfat, ufs1, ufs2, ext2fs, ext3fs, etx4, hfs, yaffs2, and iso 9660 formats is provided. For more information, please refer to this page. The developers recently released version 4.9.0 with the following changes:

C/C++

  • Removed framework project. Use Autopsy instead if you need an analysis framework.
  • Various fixes from Google-based fuzzing.
  • Ensure all reads (even big ones) are sector aligned when reading from Windows device.
  • Ensure all command line tools support new pool command line arguments.
  • Create virtual files for APFS unallocated space
  • HFS fix to display type

Java:

  • More artifact helper methods
  • More artifacts and attributes for drones and GPS coordinates
  • Updated TimelineManager to insert GPS artifacts into events table

Version number 4.9.0
Release status Final
Operating systems Windows 7, Linux, BSD, macOS, Windows Server 2008, Windows Server 2012, Windows 8, Windows 10, Windows Server 2016
Website The Sleuth Kit
Download https://github.com/sleuthkit/sleuthkit/releases/tag/sleuthkit-4.9.0
File size 21.90MB
License type Conditions (GNU/BSD/etc.)
You might also like