Result for 17BF5883636D996D611268C861F281A0B004032B

Query result

Key Value
FileName./usr/bin/tsk_recover
FileSize23508
MD594C77AA9375EC9F9E7F33EBF7995EF02
SHA-117BF5883636D996D611268C861F281A0B004032B
SHA-2569ADF65689A7BA6BE16473FE9EA4BF32412F0D94028B3A1142A7527354603C0C1
SSDEEP384:fzis0VxnR5P9GqxbsjGiX096v5lk9rYOFsd0VbLsRmIC:riFR5FGegy2ak4+ys6
TLSHT16FB20802F689D876F84301B07107CB5169A8D885E66FDE3774AE2BF87CA135D9C133A2
hashlookup:parent-total1
hashlookup:trust55

Network graph view

Parents (Total: 1)

The searched file hash is included in 1 parent files which include package known and seen by metalookup. A sample is included below:

Key Value
MD575D5019F16E1254DFAC390DB60216CB4
PackageArchi586
PackageDescriptionThe Sleuth Kit (previously known as TASK) is a collection of UNIX-based command line file system forensic tools that allow an investigator to examine NTFS, FAT, FFS, EXT2FS, EXT3FS and ExFAT file systems of a suspect computer in a non-intrusive fashion. The tools have a layer-based design and can extract data from internal file system structures. Because the tools do not rely on the operating system to process the file systems, deleted and hidden content is shown. When performing a complete analysis of a system, command line tools can become tedious. The Autopsy Forensic Browser is a graphical interface to the tools in The Sleuth Kit, which allows one to more easily conduct an investigation. Autopsy provides case management, image integrity, keyword searching, and other automated operations.
PackageMaintainerdaviddavid <daviddavid>
PackageNamesleuthkit
PackageRelease1.mga9
PackageVersion4.11.1
SHA-1805231C5D5D4BA4F682A5DC456283D10F0131A77
SHA-2569F5E1D51871ECAFA718AECFD739AE947F30D4914AAAD39B3DB0C7B9E9A4AA5B3