ils
lists inode information from filesystem images
TLDR
List inodes
$ ils [image.dd]
Show allocated only$ ils -a [image.dd]
Show unallocated only$ ils -e [image.dd]
Specify offset$ ils -o [2048] [image.dd]
Machine output$ ils -m [image.dd]
SYNOPSIS
ils [options] image
DESCRIPTION
ils lists inode information from filesystem images. It's part of The Sleuth Kit for digital forensics.The tool shows inode metadata for allocated and deleted files. It's useful for file recovery and forensic analysis.
PARAMETERS
IMAGE
Disk or partition image.-a
Show allocated only.-e
Show unallocated only.-o OFFSET
Partition offset.-m
Machine-readable output.-f FSTYPE
Filesystem type.--help
Display help information.
INSTALL
sudo apt install sleuthkit
sudo dnf install sleuthkit
sudo pacman -S sleuthkit
sudo apk add sleuthkit
sudo zypper install sleuthkit
brew install sleuthkit
nix profile install nixpkgs#sleuthkit
CAVEATS
Part of sleuthkit. Forensic tool. Read-only analysis.
HISTORY
ils is part of The Sleuth Kit by Brian Carrier for filesystem forensics.