hfsleuth
« Back to VersTracker
Description:
HFS+/HFSX file system inspection tool
Type: Cask  |  Tracked Since: Dec 28, 2025
Links: Homepage  |  formulae.brew.sh
Category: System utilities
Tags: hfs forensics filesystem macos recovery
Install: brew install --cask hfsleuth
About:
HFSleuth is a command-line utility for inspecting and analyzing HFS+ and HFSX file systems. It provides low-level access to volume structures, enabling users to examine metadata, recover information, and troubleshoot corruption. The tool is valuable for forensic analysis and advanced system administration on macOS.
Key Features:
  • Inspect HFS+ and HFSX volume headers and metadata
  • Browse catalog B-trees to view files and directories
  • Recover deleted file entries and examine extents
  • Command-line interface for scripting and automation
Use Cases:
  • Digital forensics and data recovery on Mac disks
  • Debugging file system corruption or mounting issues
  • Educational exploration of HFS+ internals
Alternatives:
  • fsck_hfs – Built-in macOS tool for verifying and repairing HFS+ volumes, but lacks deep inspection features.
  • The Sleuth Kit – General forensic framework supporting multiple file systems; HFS+ support is broader but less HFS-specific than HFSleuth.
Version History
Detected Version Rev Change Commit