sleuthkit

Install command:
brew install sleuthkit

Forensic toolkit

https://www.sleuthkit.org/

License: IPL-1.0 AND CPL-1.0 AND GPL-2.0-or-later

Development: Pull requests

Formula JSON API: /api/formula/sleuthkit.json

Formula code: sleuthkit.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
golden gate
tahoe
sequoia
sonoma
macOS on
Intel
sonoma
Linux ARM64
x86_64

Current versions:

stable 4.15.0

Depends on:

afflib 3.7.22 Advanced Forensic Format
libewf 20140816 Library for support of the Expert Witness Compression Format
libpq 18.6 Postgres C API library
openjdk 26.0.2.1 Development kit for the Java programming language
openssl@3 3.6.4 Cryptography and SSL/TLS Toolkit
sqlite 3.53.4 Command-line interface for SQLite

Depends on when building from source:

ant 1.10.18 Java build tool

Conflicts with: ffind (because both install a `ffind` executable)

Binaries: blkcalc, blkcat, blkls, blkstat, fcat, ffind, fiwalk, fls, fsstat, hfind, icat, ifind, ils, img_cat, img_stat, istat, jcat, jls, jpeg_extract, mactime, mmcat, mmls, mmstat, pstat, sigfind, sorter, srch_strings, tsk_comparedir, tsk_gettimes, tsk_imageinfo, tsk_loaddb, tsk_recover, usnjls

Analytics:

30 days90 days365 days
Installs4001,2664,312
Installs (--HEAD)004
Installs on Request3971,2383,992
Installs on Request (--HEAD)004
Build Errors1