2.1.1 release OCFA

This new release of the Open Computer Forensics Architecture (OCFA) adds the following new features:

* Routing on evidence global metadata. This makes tool chain preparation in the router rulelist much more manageable.
* A photorec module for carving in unallocated data.
* A more comprehensive router rulelist.
* The smarter data store module (dsm2) is now default. This way the forensic metadata database will maintain proper typing for metadata.

Next to new features, this release also has some important changes that existing users should be aware of:

* The old data store module (dsm1) has been deprecated.
* As a result of this, makeoverview has been depricated.
* staticmounts are no longer the default. If you want to kickstart mounted images or disk partitions and are planning to change it back for your config, please make sure the open computer forensics architecture can count on the mounts being truly static. We have seen very exotic problems with users using the formerly default static mounts on non static mount points. For this reason we switched defaults here.

Posted by KLPD TDE development team 2008-12-04

Log in to post a comment.

Get latest updates about Open Source Projects, Conferences and News.

Sign up for the SourceForge newsletter:

JavaScript is required for this form.





No, thanks