Disk Forensics

Powered by The Sleuth Kit (TSK) - Professional Digital Forensics

Analyze disk images, recover deleted files, generate timelines, and extract evidence

⚠️ Legal Notice: Only analyze disk images you own or have legal authorization to examine. Unauthorized computer forensics is illegal. This tool is for authorized investigations only.
🔐 Authentication Required: This tool requires a VeriBits account for security and compliance. Sign up free

📤 Upload Disk Image

Upload a disk image for forensic analysis. Max 2GB for web upload. For larger images, use the System Client.

💾

Drop disk image here or click to browse

Supported: .dd, .raw, .img, .E01, .aff, .vhd, .vhdx, .vmdk

Maximum file size: 2GB

About Disk Forensics

The Sleuth Kit (TSK)

The Sleuth Kit is an industry-standard collection of command-line digital forensics tools used worldwide. It enables analysis of disk images and file systems from various operating systems.

Supported File Systems

  • Windows: NTFS, FAT12/16/32, exFAT
  • Linux: Ext2/3/4, XFS, BtrFS
  • macOS: HFS+, APFS (limited)
  • Other: ISO9660, UFS, YAFFS2

Use Cases

  • Law Enforcement: Analyze seized hard drives and extract evidence
  • Incident Response: Investigate security breaches and data theft
  • Data Recovery: Recover accidentally deleted files
  • Compliance: Forensic audits and investigations

For Large Images

Web upload is limited to 2GB. For larger disk images (10GB, 100GB+), use the VeriBits System Client which can process images locally and send results to VeriBits.