Sleuth Kit & Mac OS X Forensics

The Apple Examiner has posted an article written to show the power of Brian Carrier’s Sleuth Kit in creating timelines with HFS+ file systems. The Sleuth Kit includes several command line utilities that can give in-depth looks into many different file systems. This article looks at ‘fls’ and ‘mactime’ to create a timeline of events on an OS X live system. You can see the full article at

Leave a Comment

Latest Videos

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feeds settings page to add an API key after following these instructions.

Latest Articles