Sleuth Kit & Mac OS X Forensics

The Apple Examiner has posted an article written to show the power of Brian Carrier’s Sleuth Kit in creating timelines with HFS+ file systems. The Sleuth Kit includes several command line utilities that can give in-depth looks into many different file systems. This article looks at ‘fls’ and ‘mactime’ to create a timeline of events on an OS X live system. You can see the full article at

Leave a Comment