Digital Forensics with The Sleuth Kit - fsstat

In The Sleuth Kit (TSK), “fsstat” is a command line tool that provides information about the file system structure and metadata of a given image or file system. The “fsstat” command works by analyzing the file system metadata, such as the file system’s superblock and inode tables, to extract information about the file system layout, block size, total size, and other relevant details.

This information is then displayed to the user, providing a high-level overview of the file system and its characteristics. “fsstat” is commonly used in digital forensics and incident response to quickly gain an understanding of the file system and to identify any unusual or suspicious characteristics that may indicate a security incident.

The Sleuth Kit Tools