Extensible Open Source Investigations

Sleuth Kit LABS makes both closed and open source tools. This site has our open source tools.
Our automated incident response tool can be found at CyberTriage.com.

Our Open Source Tools

Two complementary tools covering GUI-based investigations and command-line forensic analysis.

Autopsy

Autopsy®

An easy-to-use, GUI-based program for efficiently analyzing hard drives and smartphones. Features a plug-in architecture for add-on modules or custom development in Java or Python.

Learn More Download (autopsy.com)
The Sleuth Kit

The Sleuth Kit®

A collection of command-line tools and a C library for analyzing disk images and recovering files. Powers Autopsy and many other open source and commercial forensics tools.

Learn More Download

Trusted by Thousands Worldwide

These tools are used by thousands of investigators and analysts around the globe. Community-based e-mail lists and forums are available for support. Commercial training, support, and custom development is available from Sleuth Kit Labs.

Latest News

Apr 15 2025
Autopsy 4.22.1 released

Fixes Excel bug — reverts TSK version.

Apr 15 2025
Sleuth Kit 4.14.0 released

Reverts to be more close to 4.12.1.

Mar 11 2025
Autopsy 4.22.0 released

BitLocker and side-by-side Cyber Triage.

Mar 11 2025
Sleuth Kit 4.13.0 released

BitLocker and experimental XFS and BtrFS.

Cyber Triage®

Sleuth Kit Labs also builds automated investigation tools. Cyber Triage automatically scores intrusion-related data to help you quickly identify evidence. It has its own advanced remote collection tool and imports EDR telemetry and disk images. It allows even Jr analysts to quickly identify lateral movement, remote access, and malware.

Learn More Download
Cyber Triage screenshot