Sleuth Kit & Autopsy Browser
July 11, 2006
Open source/Brian CarrierProduct:
- Ease of Use:
- Value for Money:
- Overall Rating:
- Strengths: Surprisingly good documentation and support.
- Weaknesses: Being Unix-based, it requires some special skills from users.
- Verdict: Solid, well crafted and supported freeware computer forensic tool.
Sleuth Kit and Autopsy Browser are excellent examples of what happens when a talented developer builds on good prior work. These products, used together, are freeware open-source computer forensic tools built on the Coroner’s Toolkit. But the developer, Brian Carrier, has taken his considerable expertise in file systems of all kinds and applied it here.
The products are very straightforward to use and will feel familiar to anyone comfortable in Unix file systems. However, the products can analyse non-Unix file systems with ease. Both the Sleuth Kit and the browser run in Unix/Linux and the browser can run on any html environment and connect to the Autopsy server.
Because the underlying tool set is solid, the resulting Sleuth Kit is, likewise, highly competent. However, the developer has added significant functionality to the original Coroner’s Toolkit and the further addition of the browser brings this product set very close to commercial quality.
Indeed, the features for analysis and case management are just what one would expect from a competent commercial computer forensic tool.
Sleuth Kit performed in every respect as we expected. It is rather more difficult to use than many commercial products, but once the user has become comfortable with operating in a Unix environment, performance is quite acceptable.
For an open-source tool, Sleuth Kit/Autopsy sports remarkable documentation. As well as the expected Unix man pages, there are application notes (Sleuth Kit Implementation Notes or “SKINs”), mail lists, reference documents and a bi-monthly newsletter called the Sleuth Kit Informer.
Support is rather better than is typical of open-source tools. Although there is no direct support, the developer makes his email address available and there is a forum specifically for support issues. The products are well-supported in terms of ongoing upgrades and bug fixes. It is clear that the developer intends Sleuth Kit to be an acceptable and accepted computer forensic tool.
Sleuth Kit is a solid product with a well-known and respected developer behind it. More importantly, it has become firmly accepted in the computer forensic community, adding to its value.
Sign up to our newsletters
SC Magazine Articles
- Microsoft report explores dangers of running expired security software
- Survey: real-time SIEM solutions help orgs detect attacks within minutes
- Vulnerabilities identified in three Advantech products
- Android malware 'NotCompatible' evolves, spawns resilient botnet
- State Department hack may be tied to White House network breach
- Operators disable firewall features to increase network performance, survey finds
- Waste no time patching Windows Schannel, OLE bugs, experts warn
- Study: 68 percent of healthcare breaches caused by loss or theft of devices, files
- Spin.com redirects to Rig Exploit Kit, infects users with malware, Symantec observes
- Upping the ante: PCI Security Standard
- Study: Third of employees use company devices for social media and online shopping
- 'DoubleDirect' MitM attack affects iOS, Android and OS X users
- Swedish appeals court nixes Assange's plea
- Critical XSS vulnerability addressed in WordPress
- The Internet of Things (IoT) will fail if security has no context