The Sleuth Kit (TSK) is a collection of command-line tools that allow you to analyze disk images and recover digital evidence. Here's a step-by-step guide to using Sleuth Kit on a Windows machine to analyze digital evidence.
-
Visit the official Sleuth Kit website or the provided Google Drive link:
https://drive.google.com/drive/u/1/folders/1iISFY7Tqn2L7AjQGhg8yJ8kixc_xTU-v
-
Download the latest version for Windows.
- Run the installer and follow the instructions to install Sleuth Kit on your Windows machine.
The downloaded Sleuth Kit directory contains folders and files such as:
binliblicensesREADMEREADME-win32
Before analysis, you need a disk image of the evidence. This can be an image of a hard drive, memory card, or any other storage device.
- Use a tool like FTK Imager or
ddto create a bit-by-bit copy of the storage device. - Ensure the image is in a format supported by Sleuth Kit, such as:
.dd.raw.img.E01
Download the following files from the provided Google Drive:
The disk image files are stored in the Downloads directory.
Mounting the disk image makes it easier to analyze the file system.
- You can use a tool like OSFMount to mount the image as a virtual drive on your Windows system.
- This step is optional but helps with navigating the file system easily.
Use Sleuth Kit tools to analyze the file system and locate evidence.

- Open the Command Prompt.
- Navigate to the directory where Sleuth Kit is installed.
Example:
cd C:\Users\chaithu\Downloads\sleuthkit-4.14.0-win32\sleuthkit-4.14.0-win32\bin
