Re: [sleuthkit-users] extracting .E01 and .Ex01 metadata
Brought to you by:
carrier
From: Simson G. <si...@ac...> - 2013-09-12 12:17:18
|
Why do you want to use classes and methods? For #1 - what do you mean by "metadata"? Do you want to use ewfinfo? For #2 - Perhaps you want to use tsk_recover? On Sep 12, 2013, at 3:27 AM, "Bala" <bal...@cs...> wrote: > Hi Guys > > I’m a newbie to TSK. Could someone help me figure out which classes and methods that I need to use to get the following details from .E01 and Ex01 files > > 1. Extract metadata from the forensic image > 2. Iterate over files in the file structure on .E01 and .Ex01 images and read/copy the files. > > Environment > TSK Version 4.1.0 Core ( not the framework) > OS version window 7/ windows 2008 R2 > > > > Regards > Bala > > ------------------------------------------------------------------------------ > How ServiceNow helps IT people transform IT departments: > 1. Consolidate legacy IT systems to a single system of record for IT > 2. Standardize and globalize service processes across IT > 3. Implement zero-touch automation to replace manual, redundant tasks > http://pubads.g.doubleclick.net/gampad/clk?id=51271111&iu=/4140/ostg.clktrk_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |