Sleuth Kit & Mac OS X Forensics

The Apple Examiner has posted an article written to show the power of Brian Carrier’s Sleuth Kit in creating timelines with HFS+ file systems. The Sleuth Kit includes several command line utilities that can give in-depth looks into many different file systems. This article looks at ‘fls’ and ‘mactime’ to create a timeline of events on an OS X live system. You can see the full article at

Leave a Comment

Latest Videos

Quantifying Data Volatility for IoT Forensics With Examples From Contiki OS

Forensic Focus 22nd June 2022 5:00 am

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles

Share to...