I love using Sleuthkit tools fls and mactime to produce a timeline for file system analysis. But what if you are not compiler friendly and have a mac as your forensics workstation? Here is the quick and easy way to get Sleuthkit installed so you can run it against raw disc images.
- Get macports from macports.org It is a simple install from dmg.
- Once installed, get a terminal session opened.
- execute the command: sudo port -d selfupdate
- execute the command: sudo port install sleuthkit
It will take a while for sleuthkit and all the dependancies to install. Once done you should be able to do “man fls” and “man mactime” to see the manual pages for the tools and start using them.