The Sleuth Kit (previously known as TSK) is a collection of UNIX-based command line file and volume system forensic analysis tools. The file system tools allow you to examine file systems of a suspect computer in a non-intrusive fashion. Because the tools do not rely on the operating system to process the file systems, deleted and hidden content is shown. A graphical interface to the tools called Autopsy is available.
For downloads and more information,
visit the The Sleuth Kit homepage.
Great tool. Utilizing TSK along with Autopsy for forensics is my tool of choice. I'm surprised it's not higher up in the rankings. Fairly easy to use and the developers seem very interested in suggestions to add new features.
As far i concern i check this tool this is best if you are looking for free tools, its not very jazzy but at the time process consuming, yes but you can tweak it as per your requirement.. over all good while testing...