{"schema_version":1,"metadata":{"branch":"current","release":"7.9","architecture":"amd64","generated_at":"2026-09-09T04:04:41.004595+00:00","source_url":"https://cdn.openbsd.org/pub/OpenBSD/snapshots/packages/amd64/sqlports-7.55.tgz","source_sha256":"fcdbba1b9df747882aa9bab4af20ebec8dac10655069c90f1cd4145c06e1235e","package_count":12031,"source_kind":"sqlports"},"package":{"name":"sleuthkit-4.15.0","path":"sysutils/sleuthkit","url":"/packages/current/sysutils/sleuthkit/","comment":"forensic toolkit based on TCT","homepage":"https://www.sleuthkit.org/","maintainer":"Sebastian Reitenbach <sebastia@openbsd.org>","description":"The Sleuth Kit (previously known as TASK) is the only open\nsource forensic toolkit for a complete analysis of Microsoft\nand UNIX file systems.\nIt enables investigators to identify and recover evidence from\nimages acquired during incident response or from live systems.\n\nSome of its features:\n\n* Analyzes images generated by the open source 'dd' utility,\n  found on all UNIX systems and available for Windows systems.\n* Supports the NTFS, FAT, FFS, and EXT2FS file systems. Images\n  of a different endian ordering than the analysis system can\n  be used.\n* The tools are organized in a layered approach, where the names\n  in each layer start with the same letter to help the user identify\n  the function of the tool. The layers include File System, File\n  Name (directory entries and NTFS index trees), Meta-Data (UNIX\n  inodes and NTFS MFT entries), and Content (blocks and clusters).\n* Identifies deleted files by name and location.\n* Identifies the status of content units (blocks and clusters)\n  and meta-data structures.\n* Maps the relationship of objects across different layers.\n","package_architecture":"amd64","stem":"sleuthkit","readme":null,"dependencies":[{"path":"databases/sqlite3","type":"library","package_spec":"","url":"/packages/current/databases/sqlite3/"},{"path":"devel/libbfio","type":"library","package_spec":"","url":"/packages/current/devel/libbfio/"},{"path":"sysutils/afflib3","type":"library","package_spec":"","url":"/packages/current/sysutils/afflib3/"},{"path":"sysutils/libvhdi","type":"library","package_spec":"","url":"/packages/current/sysutils/libvhdi/"},{"path":"sysutils/libvmdk","type":"library","package_spec":"","url":"/packages/current/sysutils/libvmdk/"},{"path":"sysutils/libvslvm","type":"library","package_spec":"","url":"/packages/current/sysutils/libvslvm/"},{"path":"security/libewf","type":"library","package_spec":"","url":"/packages/current/security/libewf/"},{"path":"converters/p5-DateManip","type":"runtime","package_spec":"","url":"/packages/current/converters/p5-DateManip/"},{"path":"devel/metaauto","type":"build","package_spec":"","url":"/packages/current/devel/metaauto/"},{"path":"devel/autoconf/2.69","type":"build","package_spec":"","url":"/packages/current/devel/autoconf/2.69/"},{"path":"devel/automake/1.15","type":"build","package_spec":"","url":"/packages/current/devel/automake/1.15/"},{"path":"devel/libtool","type":"build","package_spec":"","url":"/packages/current/devel/libtool/"},{"path":"devel/gmake","type":"build","package_spec":"","url":"/packages/current/devel/gmake/"}],"reverse_dependencies":{"count":0,"url":null},"categories":["sysutils","security"],"flavors":[],"only_for_architectures":["aarch64","amd64","arm","i386","mips64","mips64el","powerpc","powerpc64","riscv64","sparc64","alpha","hppa"],"not_for_architectures":[]}}
