sleuthkit-users Mailing List for The Sleuth Kit (Page 28)
Brought to you by:
carrier
You can subscribe to this list here.
2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(11) |
Oct
(5) |
Nov
(4) |
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2003 |
Jan
(1) |
Feb
(20) |
Mar
(60) |
Apr
(40) |
May
(24) |
Jun
(28) |
Jul
(18) |
Aug
(27) |
Sep
(6) |
Oct
(14) |
Nov
(15) |
Dec
(22) |
2004 |
Jan
(34) |
Feb
(13) |
Mar
(28) |
Apr
(23) |
May
(27) |
Jun
(26) |
Jul
(37) |
Aug
(19) |
Sep
(20) |
Oct
(39) |
Nov
(17) |
Dec
(9) |
2005 |
Jan
(45) |
Feb
(43) |
Mar
(66) |
Apr
(36) |
May
(19) |
Jun
(64) |
Jul
(10) |
Aug
(11) |
Sep
(35) |
Oct
(6) |
Nov
(4) |
Dec
(13) |
2006 |
Jan
(52) |
Feb
(34) |
Mar
(39) |
Apr
(39) |
May
(37) |
Jun
(15) |
Jul
(13) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(47) |
Dec
(13) |
2007 |
Jan
(25) |
Feb
(4) |
Mar
(2) |
Apr
(29) |
May
(11) |
Jun
(19) |
Jul
(13) |
Aug
(15) |
Sep
(30) |
Oct
(12) |
Nov
(10) |
Dec
(13) |
2008 |
Jan
(2) |
Feb
(54) |
Mar
(58) |
Apr
(43) |
May
(10) |
Jun
(27) |
Jul
(25) |
Aug
(27) |
Sep
(48) |
Oct
(69) |
Nov
(55) |
Dec
(43) |
2009 |
Jan
(26) |
Feb
(36) |
Mar
(28) |
Apr
(27) |
May
(55) |
Jun
(9) |
Jul
(19) |
Aug
(16) |
Sep
(15) |
Oct
(17) |
Nov
(70) |
Dec
(21) |
2010 |
Jan
(56) |
Feb
(59) |
Mar
(53) |
Apr
(32) |
May
(25) |
Jun
(31) |
Jul
(36) |
Aug
(11) |
Sep
(37) |
Oct
(19) |
Nov
(23) |
Dec
(6) |
2011 |
Jan
(21) |
Feb
(20) |
Mar
(30) |
Apr
(30) |
May
(74) |
Jun
(50) |
Jul
(34) |
Aug
(34) |
Sep
(12) |
Oct
(33) |
Nov
(10) |
Dec
(8) |
2012 |
Jan
(23) |
Feb
(57) |
Mar
(26) |
Apr
(14) |
May
(27) |
Jun
(27) |
Jul
(60) |
Aug
(88) |
Sep
(13) |
Oct
(36) |
Nov
(97) |
Dec
(85) |
2013 |
Jan
(60) |
Feb
(24) |
Mar
(43) |
Apr
(32) |
May
(22) |
Jun
(38) |
Jul
(51) |
Aug
(50) |
Sep
(76) |
Oct
(65) |
Nov
(25) |
Dec
(30) |
2014 |
Jan
(19) |
Feb
(41) |
Mar
(43) |
Apr
(28) |
May
(61) |
Jun
(12) |
Jul
(10) |
Aug
(37) |
Sep
(76) |
Oct
(31) |
Nov
(41) |
Dec
(12) |
2015 |
Jan
(33) |
Feb
(28) |
Mar
(53) |
Apr
(22) |
May
(29) |
Jun
(20) |
Jul
(15) |
Aug
(17) |
Sep
(52) |
Oct
(3) |
Nov
(18) |
Dec
(21) |
2016 |
Jan
(20) |
Feb
(8) |
Mar
(21) |
Apr
(7) |
May
(13) |
Jun
(35) |
Jul
(34) |
Aug
(11) |
Sep
(14) |
Oct
(22) |
Nov
(31) |
Dec
(23) |
2017 |
Jan
(20) |
Feb
(7) |
Mar
(5) |
Apr
(6) |
May
(6) |
Jun
(22) |
Jul
(11) |
Aug
(16) |
Sep
(8) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
2018 |
Jan
|
Feb
|
Mar
(16) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(4) |
Oct
|
Nov
(16) |
Dec
(13) |
2019 |
Jan
|
Feb
(1) |
Mar
(25) |
Apr
(9) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2020 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(3) |
Jul
(2) |
Aug
|
Sep
|
Oct
(5) |
Nov
|
Dec
|
2021 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
2022 |
Jan
|
Feb
(2) |
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2023 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
2024 |
Jan
|
Feb
(3) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2025 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: Vaine B. <vlb...@gm...> - 2015-04-01 23:21:09
|
In previous releases, you could extract a file informing the sector start and the end sector, "Data Unit" menu. How to make the same version in version 3.1.2 Autopsy? Where is "Data Unit" menu? Thanks. Vaine Barreira Brazil vlb...@gm... |
From: Sam K <sku...@gm...> - 2015-04-01 15:51:46
|
Thanks, that makes sense. Calculating is not a problem - but I can't seem to find where the data run information is stored for this file. I was expecting tsk_file_layout, but no joy. Is there an API call or somewhere else in the SQLite tables it could live? On Wed, Apr 1, 2015 at 11:26 AM, ade <adr...@nt...> wrote: > Hi Sam > > The metadata you have presented is the data-runs, which are the block (or > cluster) numbers, parsed from the inode information . AFAIK, tsk doesn't > get the starting sector number for files as this is not maintained by any > structures on the disk. You would have to calculate the sector number > based > on the first cluster number in the data run, taking into account the > partition > start sector and the number of sectors per cluster. > > Stumpy > > On Wednesday 01 Apr 2015 11:17:32 Sam K wrote: > > Good morning: > > > > Can anyone shed light on where Autopsy 3.1.2 would store the starting > > physical sector for a file, if that information is *not *contained in the > > tsk_file_layout table? I'm guessing it must be stored somewhere (and not > > re-parsed from the MFT every time I view the file), but have been > > unsuccessful in finding it. > > > > Based on the output in the Metadata tab, Autopsy does store the > > information. I've confirmed with another tool that 118341 is indeed the > > starting physical sector. I want this information included with a report > > module I'm working on, and can't seem to reference it anywhere in the API > > or database (there's no entry for the file in tsk_file_layout, perhaps > > because it's contiguous and not fragmented). > > > > Attributes: > > Type: ? (16-0) Name: N/A Resident size: 72 > > Type: ? (48-6) Name: N/A Resident size: 90 > > Type: ? (48-5) Name: N/A Resident size: 110 > > Type: ? (128-4) Name: N/A Non-Resident size: 25600 init_size: > 25600 > > 118341 118342 118343 118344 118345 118346 118347 118348 > > 118349 118350 118351 118352 118353 118354 118355 118356 > > 118357 118358 118359 118360 118361 118362 118363 118364 > > 118365 118366 118367 118368 118369 118370 118371 118372 > > 118373 118374 118375 118376 118377 118378 118379 118380 > > 118381 118382 118383 118384 118385 118386 118387 118388 > > 118389 118390 > > > > Thanks in advance for any feedback. > > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for > all > things parallel software development, from weekly thought leadership blogs > to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |
From: ade <adr...@nt...> - 2015-04-01 15:27:09
|
Hi Sam The metadata you have presented is the data-runs, which are the block (or cluster) numbers, parsed from the inode information . AFAIK, tsk doesn't get the starting sector number for files as this is not maintained by any structures on the disk. You would have to calculate the sector number based on the first cluster number in the data run, taking into account the partition start sector and the number of sectors per cluster. Stumpy On Wednesday 01 Apr 2015 11:17:32 Sam K wrote: > Good morning: > > Can anyone shed light on where Autopsy 3.1.2 would store the starting > physical sector for a file, if that information is *not *contained in the > tsk_file_layout table? I'm guessing it must be stored somewhere (and not > re-parsed from the MFT every time I view the file), but have been > unsuccessful in finding it. > > Based on the output in the Metadata tab, Autopsy does store the > information. I've confirmed with another tool that 118341 is indeed the > starting physical sector. I want this information included with a report > module I'm working on, and can't seem to reference it anywhere in the API > or database (there's no entry for the file in tsk_file_layout, perhaps > because it's contiguous and not fragmented). > > Attributes: > Type: ? (16-0) Name: N/A Resident size: 72 > Type: ? (48-6) Name: N/A Resident size: 90 > Type: ? (48-5) Name: N/A Resident size: 110 > Type: ? (128-4) Name: N/A Non-Resident size: 25600 init_size: 25600 > 118341 118342 118343 118344 118345 118346 118347 118348 > 118349 118350 118351 118352 118353 118354 118355 118356 > 118357 118358 118359 118360 118361 118362 118363 118364 > 118365 118366 118367 118368 118369 118370 118371 118372 > 118373 118374 118375 118376 118377 118378 118379 118380 > 118381 118382 118383 118384 118385 118386 118387 118388 > 118389 118390 > > Thanks in advance for any feedback. |
From: Sam K <sku...@gm...> - 2015-04-01 15:17:39
|
Good morning: Can anyone shed light on where Autopsy 3.1.2 would store the starting physical sector for a file, if that information is *not *contained in the tsk_file_layout table? I'm guessing it must be stored somewhere (and not re-parsed from the MFT every time I view the file), but have been unsuccessful in finding it. Based on the output in the Metadata tab, Autopsy does store the information. I've confirmed with another tool that 118341 is indeed the starting physical sector. I want this information included with a report module I'm working on, and can't seem to reference it anywhere in the API or database (there's no entry for the file in tsk_file_layout, perhaps because it's contiguous and not fragmented). Attributes: Type: ? (16-0) Name: N/A Resident size: 72 Type: ? (48-6) Name: N/A Resident size: 90 Type: ? (48-5) Name: N/A Resident size: 110 Type: ? (128-4) Name: N/A Non-Resident size: 25600 init_size: 25600 118341 118342 118343 118344 118345 118346 118347 118348 118349 118350 118351 118352 118353 118354 118355 118356 118357 118358 118359 118360 118361 118362 118363 118364 118365 118366 118367 118368 118369 118370 118371 118372 118373 118374 118375 118376 118377 118378 118379 118380 118381 118382 118383 118384 118385 118386 118387 118388 118389 118390 Thanks in advance for any feedback. |
From: Simson G. <si...@ac...> - 2015-03-28 12:12:17
|
The problem is that the information is inside the ntfs implementation but there is no API to get it out. > On Mar 28, 2015, at 7:23 AM, Atila <ati...@dp...> wrote: > > That reminds me of one more suggestion of improvement (unrelated to the current topic), but this time on Sleuthkit not Autopsy: tsk_loaddb could fill tsk_file_layout with byte_start for NTFS resident files, pointing to the appropriate position (and size, of course) inside MFT. Today, only a portion of the files (the non-resident ones) get they positions recorded in the DB. > > On 27-03-2015 18:32, Simson Garfinkel wrote: >> It seems that the main reason people are running fiwalk at this point is so that they can run identify_filenames.py with bulk_extractor. However, fiwalk is a bit of a mess and it doesn't fit in well with the sleuthkit tool suite. tsk_loaddb does a good job with most of what fiwalk does, but it doesn't support plugins and it doesn't export XML. >> >> Options: >> >> 1 - Modify tsk_loaddb to output DFXML. >> 2 - Have a Python script that takes a tsk_loaddb Sqlite3 database and outputs DFXML. >> 3 - Modify identify_filenames.py to read the Sqlite3 database produced by tsk_loaddb. >> >> I think that #2 and #3 are the right options, in that order, provided that nobody is making use of the fiwalk plugins (or provided that they can migrate to something else). Does anyone on the list of a dependency on dfxml or fiwalk plug-ins? >> >> Simson >> >> There are two ways to move forward on this. >> >>> On Mar 27, 2015, at 4:01 PM, Jeff Scarborough <jef...@gm... <mailto:jef...@gm...>> wrote: >>> >>> Thank you all for your reply. >>> >>> @Alex -- I believe you are correct in that fiwalk wants one file. Fortunately, Jason Wright had a workable idea for that. >>> >>> @Brian Carrier -- Using tsk_gettimes on the image does seem to run through the data. The process ran for several minutes before I stopped the program. It seem the data would be more than what would be found in a single file. >>> >>> @Simson Garfinkel -- I have a few drive images that I am attempting to extract data using Bulk Extractor. According to a presentation you had given on Bulk Extractor, I am using fiwalk to extract DFXML data and will then run identify_filesnames.py in hopes of linking the data with the files. >>> >>> @Jason Wright -- Thanks. Using the affuse worked, once I had the commands down correctly. Below are the commands I used for reference. >>> >>> affuse path/to/image.001 /mnt/combine >>> fiwalk -X report.xml /mnt/combine/image.001.raw >>> >>> Thanks again, >>> >>> Jeff Scarborough >>> >>> On Fri, Mar 27, 2015 at 1:58 PM, Simson Garfinkel <si...@ac... <mailto:si...@ac...>> wrote: >>> With the fiwalk rewrite, it's using standard Sleuthkit image processing. >>> >>> However, Jeff, what are you using fiwalk for? What's your interest in DFXML? >>> >>> Simson >>> >>> >>> > On Mar 27, 2015, at 2:07 PM, Brian Carrier <ca...@sl... <mailto:ca...@sl...>> wrote: >>> > >>> > TSK commands should find the remaining files if you give it just the ".001" file. Not sure about fiwalk's usage. >>> > >>> > Jeff, if you run tsk_gettimes on the image, then does it find all of them? >>> > >>> > >>> > >>> > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough <jef...@gm... <mailto:jef...@gm...>> wrote: >>> > >>> >> I am a new user to SleuthKit and I am attempting to run fiwalk on an image and output a dfxml file. The image is, I believe called a split raw since it is in the form of filename.001, filename.002, filename.003 etc. I am having an issue with the command line to output the file. >>> >> >>> >> The below command is the example i usually run across. >>> >> >>> >> fiwalk -X path/report.xml path/image.raw >>> >> >>> >> >>> >> I need to use fiwalk with split files. I used the examples below with limited luck. >>> >> >>> >> fiwalk -X path/report.xml path/image.dd -- this one said it had trouble opening the file >>> >> >>> >> fiwalk -X path/report.xml path/image.* -- this one also has trouble >>> >> >>> >> >>> >> The command line below seems to start the process but as far as I can see only processes the first file in the list and none of the others. >>> >> >>> >> fiwalk -X path/report.xml path/image.001 >>> >> >>> >> >>> >> Am I missing something in the command line that will process all of the files? >>> >> >>> >> I am using a virtual machine to run linux with SleuthKit installed and the image is on a USB drive. >>> >> >>> >> Thanks, >>> >> Jeff Scarborough >>> >> ------------------------------------------------------------------------------ >>> >> Dive into the World of Parallel Programming The Go Parallel Website, sponsored >>> >> by Intel and developed in partnership with Slashdot Media, is your hub for all >>> >> things parallel software development, from weekly thought leadership blogs to >>> >> news, videos, case studies, tutorials and more. Take a look and join the >>> >> conversation now. http://goparallel.sourceforge.net/_______________________________________________ <http://goparallel.sourceforge.net/_______________________________________________> >>> >> sleuthkit-users mailing list >>> >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> >>> >> http://www.sleuthkit.org <http://www.sleuthkit.org/> >>> > >>> > >>> > ------------------------------------------------------------------------------ >>> > Dive into the World of Parallel Programming The Go Parallel Website, sponsored >>> > by Intel and developed in partnership with Slashdot Media, is your hub for all >>> > things parallel software development, from weekly thought leadership blogs to >>> > news, videos, case studies, tutorials and more. Take a look and join the >>> > conversation now. http://goparallel.sourceforge.net/ <http://goparallel.sourceforge.net/> >>> > _______________________________________________ >>> > sleuthkit-users mailing list >>> > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> >>> > http://www.sleuthkit.org <http://www.sleuthkit.org/> >>> >>> >> >> >> >> ------------------------------------------------------------------------------ >> Dive into the World of Parallel Programming The Go Parallel Website, sponsored >> by Intel and developed in partnership with Slashdot Media, is your hub for all >> things parallel software development, from weekly thought leadership blogs to >> news, videos, case studies, tutorials and more. Take a look and join the >> conversation now. http://goparallel.sourceforge.net/ <http://goparallel.sourceforge.net/> >> >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> >> http://www.sleuthkit.org <http://www.sleuthkit.org/> > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Atila <ati...@dp...> - 2015-03-28 11:23:35
|
That reminds me of one more suggestion of improvement (unrelated to the current topic), but this time on Sleuthkit not Autopsy: tsk_loaddb could fill tsk_file_layout with byte_start for NTFS resident files, pointing to the appropriate position (and size, of course) inside MFT. Today, only a portion of the files (the non-resident ones) get they positions recorded in the DB. On 27-03-2015 18:32, Simson Garfinkel wrote: > It seems that the main reason people are running fiwalk at this point > is so that they can run identify_filenames.py with bulk_extractor. > However, fiwalk is a bit of a mess and it doesn't fit in well with > the sleuthkit tool suite. tsk_loaddb does a good job with most of what > fiwalk does, but it doesn't support plugins and it doesn't export XML. > > Options: > > 1 - Modify tsk_loaddb to output DFXML. > 2 - Have a Python script that takes a tsk_loaddb Sqlite3 database and > outputs DFXML. > 3 - Modify identify_filenames.py to read the Sqlite3 database produced > by tsk_loaddb. > > I think that #2 and #3 are the right options, in that order, provided > that nobody is making use of the fiwalk plugins (or provided that they > can migrate to something else). Does anyone on the list of a > dependency on dfxml or fiwalk plug-ins? > > Simson > > There are two ways to move forward on this. > >> On Mar 27, 2015, at 4:01 PM, Jeff Scarborough >> <jef...@gm... <mailto:jef...@gm...>> wrote: >> >> Thank you all for your reply. >> >> @Alex -- I believe you are correct in that fiwalk wants one file. >> Fortunately, Jason Wright had a workable idea for that. >> >> @Brian Carrier -- Using tsk_gettimes on the image does seem to run >> through the data. The process ran for several minutes before I >> stopped the program. It seem the data would be more than what would >> be found in a single file. >> >> @Simson Garfinkel -- I have a few drive images that I am attempting >> to extract data using Bulk Extractor. According to a presentation >> you had given on Bulk Extractor, I am using fiwalk to extract DFXML >> data and will then run identify_filesnames.py in hopes of linking the >> data with the files. >> >> @Jason Wright -- Thanks. Using the affuse worked, once I had the >> commands down correctly. Below are the commands I used for reference. >> >> affuse path/to/image.001 /mnt/combine >> fiwalk -X report.xml /mnt/combine/image.001.raw >> >> Thanks again, >> >> Jeff Scarborough >> >> On Fri, Mar 27, 2015 at 1:58 PM, Simson Garfinkel <si...@ac... >> <mailto:si...@ac...>> wrote: >> >> With the fiwalk rewrite, it's using standard Sleuthkit image >> processing. >> >> However, Jeff, what are you using fiwalk for? What's your >> interest in DFXML? >> >> Simson >> >> >> > On Mar 27, 2015, at 2:07 PM, Brian Carrier >> <ca...@sl... <mailto:ca...@sl...>> wrote: >> > >> > TSK commands should find the remaining files if you give it >> just the ".001" file. Not sure about fiwalk's usage. >> > >> > Jeff, if you run tsk_gettimes on the image, then does it find >> all of them? >> > >> > >> > >> > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough >> <jef...@gm... <mailto:jef...@gm...>> >> wrote: >> > >> >> I am a new user to SleuthKit and I am attempting to run fiwalk >> on an image and output a dfxml file. The image is, I believe >> called a split raw since it is in the form of filename.001, >> filename.002, filename.003 etc. I am having an issue with the >> command line to output the file. >> >> >> >> The below command is the example i usually run across. >> >> >> >> fiwalk -X path/report.xml path/image.raw >> >> >> >> >> >> I need to use fiwalk with split files. I used the examples >> below with limited luck. >> >> >> >> fiwalk -X path/report.xml path/image.dd -- this one said it >> had trouble opening the file >> >> >> >> fiwalk -X path/report.xml path/image.* -- this one also has >> trouble >> >> >> >> >> >> The command line below seems to start the process but as far >> as I can see only processes the first file in the list and none >> of the others. >> >> >> >> fiwalk -X path/report.xml path/image.001 >> >> >> >> >> >> Am I missing something in the command line that will process >> all of the files? >> >> >> >> I am using a virtual machine to run linux with SleuthKit >> installed and the image is on a USB drive. >> >> >> >> Thanks, >> >> Jeff Scarborough >> >> >> ------------------------------------------------------------------------------ >> >> Dive into the World of Parallel Programming The Go Parallel >> Website, sponsored >> >> by Intel and developed in partnership with Slashdot Media, is >> your hub for all >> >> things parallel software development, from weekly thought >> leadership blogs to >> >> news, videos, case studies, tutorials and more. Take a look >> and join the >> >> conversation now. >> http://goparallel.sourceforge.net/_______________________________________________ >> >> sleuthkit-users mailing list >> >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> >> http://www.sleuthkit.org <http://www.sleuthkit.org/> >> > >> > >> > >> ------------------------------------------------------------------------------ >> > Dive into the World of Parallel Programming The Go Parallel >> Website, sponsored >> > by Intel and developed in partnership with Slashdot Media, is >> your hub for all >> > things parallel software development, from weekly thought >> leadership blogs to >> > news, videos, case studies, tutorials and more. Take a look and >> join the >> > conversation now. http://goparallel.sourceforge.net/ >> > _______________________________________________ >> > sleuthkit-users mailing list >> > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> > http://www.sleuthkit.org <http://www.sleuthkit.org/> >> >> > > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > > > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Simson G. <si...@ac...> - 2015-03-27 22:43:14
|
Hi Alan. There's no active development happening on fiwalk. On the other hand, there's no active development happening on many other SleuthKit tools. The issue is that fiwalk replicates tools that are being actively developed, like tsk_loaddb. In many cases it is faster to store things in the SQLite3 database than to generate and consume DFXML. You are correct that DFXML is more applicable to mapping inside of files than the SQLite3 schema is. However, there are other XML standards as well, and my goal is to merge DFXML with one of those standards, rather than maintain a complete separate set of definitions. > On Mar 27, 2015, at 5:59 PM, Alan Browne <ala...@gm...> wrote: > > Simson > Is the development of fiwalk still being continued. I use fiwalk to map a drive rather than tsk as I find it produces more info. If it is being further developed, would it be possible to map inside archived files as well > Regards > Alan > > On 27 Mar 2015 21:33, <sle...@li... <mailto:sle...@li...>> wrote: > Send sleuthkit-users mailing list submissions to > sle...@li... <mailto:sle...@li...> > > To subscribe or unsubscribe via the World Wide Web, visit > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > or, via email, send a message with subject or body 'help' to > sle...@li... <mailto:sle...@li...> > > You can reach the person managing the list at > sle...@li... <mailto:sle...@li...> > > When replying, please edit your Subject line so it is more specific > than "Re: Contents of sleuthkit-users digest..." > > > Today's Topics: > > 1. Re: Attempting to use fiwalk (Simson Garfinkel) > 2. Re: Attempting to use fiwalk (Jeff Scarborough) > 3. Re: Attempting to use fiwalk (Simson Garfinkel) > > > ---------------------------------------------------------------------- > > Message: 1 > Date: Fri, 27 Mar 2015 14:58:30 -0400 > From: Simson Garfinkel <si...@ac... <mailto:si...@ac...>> > Subject: Re: [sleuthkit-users] Attempting to use fiwalk > To: Brian Carrier <ca...@sl... <mailto:ca...@sl...>> > Cc: sle...@li... <mailto:sle...@li...> > Message-ID: <E4E...@ac... <mailto:E4E...@ac...>> > Content-Type: text/plain; charset=us-ascii > > With the fiwalk rewrite, it's using standard Sleuthkit image processing. > > However, Jeff, what are you using fiwalk for? What's your interest in DFXML? > > Simson > > > > On Mar 27, 2015, at 2:07 PM, Brian Carrier <ca...@sl... <mailto:ca...@sl...>> wrote: > > > > TSK commands should find the remaining files if you give it just the ".001" file. Not sure about fiwalk's usage. > > > > Jeff, if you run tsk_gettimes on the image, then does it find all of them? > > > > > > > > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough <jef...@gm... <mailto:jef...@gm...>> wrote: > > > >> I am a new user to SleuthKit and I am attempting to run fiwalk on an image and output a dfxml file. The image is, I believe called a split raw since it is in the form of filename.001, filename.002, filename.003 etc. I am having an issue with the command line to output the file. > >> > >> The below command is the example i usually run across. > >> > >> fiwalk -X path/report.xml path/image.raw > >> > >> > >> I need to use fiwalk with split files. I used the examples below with limited luck. > >> > >> fiwalk -X path/report.xml path/image.dd -- this one said it had trouble opening the file > >> > >> fiwalk -X path/report.xml path/image.* -- this one also has trouble > >> > >> > >> The command line below seems to start the process but as far as I can see only processes the first file in the list and none of the others. > >> > >> fiwalk -X path/report.xml path/image.001 > >> > >> > >> Am I missing something in the command line that will process all of the files? > >> > >> I am using a virtual machine to run linux with SleuthKit installed and the image is on a USB drive. > >> > >> Thanks, > >> Jeff Scarborough > >> ------------------------------------------------------------------------------ > >> Dive into the World of Parallel Programming The Go Parallel Website, sponsored > >> by Intel and developed in partnership with Slashdot Media, is your hub for all > >> things parallel software development, from weekly thought leadership blogs to > >> news, videos, case studies, tutorials and more. Take a look and join the > >> conversation now. http://goparallel.sourceforge.net/_______________________________________________ <http://goparallel.sourceforge.net/_______________________________________________> > >> sleuthkit-users mailing list > >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > >> http://www.sleuthkit.org <http://www.sleuthkit.org/> > > > > > > ------------------------------------------------------------------------------ > > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > > by Intel and developed in partnership with Slashdot Media, is your hub for all > > things parallel software development, from weekly thought leadership blogs to > > news, videos, case studies, tutorials and more. Take a look and join the > > conversation now. http://goparallel.sourceforge.net/ <http://goparallel.sourceforge.net/> > > _______________________________________________ > > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > > http://www.sleuthkit.org <http://www.sleuthkit.org/> > > > > > ------------------------------ > > Message: 2 > Date: Fri, 27 Mar 2015 15:01:37 -0500 > From: Jeff Scarborough <jef...@gm... <mailto:jef...@gm...>> > Subject: Re: [sleuthkit-users] Attempting to use fiwalk > To: Simson Garfinkel <si...@ac... <mailto:si...@ac...>>, > sle...@li... <mailto:sle...@li...> > Cc: Brian Carrier <ca...@sl... <mailto:ca...@sl...>> > Message-ID: > <CAGzbUa9TgJRO=6U7PwJi=vGg...@ma... <mailto:vGg...@ma...>> > Content-Type: text/plain; charset="utf-8" > > Thank you all for your reply. > > @Alex -- I believe you are correct in that fiwalk wants one file. > Fortunately, Jason Wright had a workable idea for that. > > @Brian Carrier -- Using tsk_gettimes on the image does seem to run through > the data. The process ran for several minutes before I stopped the > program. It seem the data would be more than what would be found in a > single file. > > @Simson Garfinkel -- I have a few drive images that I am attempting to > extract data using Bulk Extractor. According to a presentation you had > given on Bulk Extractor, I am using fiwalk to extract DFXML data and will > then run identify_filesnames.py in hopes of linking the data with the files. > > @Jason Wright -- Thanks. Using the affuse worked, once I had the commands > down correctly. Below are the commands I used for reference. > > affuse path/to/image.001 /mnt/combine > fiwalk -X report.xml /mnt/combine/image.001.raw > > Thanks again, > > Jeff Scarborough > > On Fri, Mar 27, 2015 at 1:58 PM, Simson Garfinkel <si...@ac... <mailto:si...@ac...>> wrote: > > > With the fiwalk rewrite, it's using standard Sleuthkit image processing. > > > > However, Jeff, what are you using fiwalk for? What's your interest in > > DFXML? > > > > Simson > > > > > > > On Mar 27, 2015, at 2:07 PM, Brian Carrier <ca...@sl... <mailto:ca...@sl...>> > > wrote: > > > > > > TSK commands should find the remaining files if you give it just the > > ".001" file. Not sure about fiwalk's usage. > > > > > > Jeff, if you run tsk_gettimes on the image, then does it find all of > > them? > > > > > > > > > > > > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough < > > jef...@gm... <mailto:jef...@gm...>> wrote: > > > > > >> I am a new user to SleuthKit and I am attempting to run fiwalk on an > > image and output a dfxml file. The image is, I believe called a split raw > > since it is in the form of filename.001, filename.002, filename.003 etc. I > > am having an issue with the command line to output the file. > > >> > > >> The below command is the example i usually run across. > > >> > > >> fiwalk -X path/report.xml path/image.raw > > >> > > >> > > >> I need to use fiwalk with split files. I used the examples below with > > limited luck. > > >> > > >> fiwalk -X path/report.xml path/image.dd -- this one said it had > > trouble opening the file > > >> > > >> fiwalk -X path/report.xml path/image.* -- this one also has trouble > > >> > > >> > > >> The command line below seems to start the process but as far as I can > > see only processes the first file in the list and none of the others. > > >> > > >> fiwalk -X path/report.xml path/image.001 > > >> > > >> > > >> Am I missing something in the command line that will process all of the > > files? > > >> > > >> I am using a virtual machine to run linux with SleuthKit installed and > > the image is on a USB drive. > > >> > > >> Thanks, > > >> Jeff Scarborough > > >> > > ------------------------------------------------------------------------------ > > >> Dive into the World of Parallel Programming The Go Parallel Website, > > sponsored > > >> by Intel and developed in partnership with Slashdot Media, is your hub > > for all > > >> things parallel software development, from weekly thought leadership > > blogs to > > >> news, videos, case studies, tutorials and more. Take a look and join the > > >> conversation now. > > http://goparallel.sourceforge.net/_______________________________________________ <http://goparallel.sourceforge.net/_______________________________________________> > > >> sleuthkit-users mailing list > > >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > > >> http://www.sleuthkit.org <http://www.sleuthkit.org/> > > > > > > > > > > > ------------------------------------------------------------------------------ > > > Dive into the World of Parallel Programming The Go Parallel Website, > > sponsored > > > by Intel and developed in partnership with Slashdot Media, is your hub > > for all > > > things parallel software development, from weekly thought leadership > > blogs to > > > news, videos, case studies, tutorials and more. Take a look and join the > > > conversation now. http://goparallel.sourceforge.net/ <http://goparallel.sourceforge.net/> > > > _______________________________________________ > > > sleuthkit-users mailing list > > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > > > http://www.sleuthkit.org <http://www.sleuthkit.org/> > > > > > -------------- next part -------------- > An HTML attachment was scrubbed... > > ------------------------------ > > Message: 3 > Date: Fri, 27 Mar 2015 17:32:03 -0400 > From: Simson Garfinkel <si...@ac... <mailto:si...@ac...>> > Subject: Re: [sleuthkit-users] Attempting to use fiwalk > To: Jeff Scarborough <jef...@gm... <mailto:jef...@gm...>> > Cc: Brian Carrier <ca...@sl... <mailto:ca...@sl...>>, > "sle...@li... <mailto:sle...@li...> users" > <sle...@li... <mailto:sle...@li...>> > Message-ID: <171...@ac... <mailto:171...@ac...>> > Content-Type: text/plain; charset="us-ascii" > > It seems that the main reason people are running fiwalk at this point is so that they can run identify_filenames.py with bulk_extractor. However, fiwalk is a bit of a mess and it doesn't fit in well with the sleuthkit tool suite. tsk_loaddb does a good job with most of what fiwalk does, but it doesn't support plugins and it doesn't export XML. > > Options: > > 1 - Modify tsk_loaddb to output DFXML. > 2 - Have a Python script that takes a tsk_loaddb Sqlite3 database and outputs DFXML. > 3 - Modify identify_filenames.py to read the Sqlite3 database produced by tsk_loaddb. > > I think that #2 and #3 are the right options, in that order, provided that nobody is making use of the fiwalk plugins (or provided that they can migrate to something else). Does anyone on the list of a dependency on dfxml or fiwalk plug-ins? > > Simson > > There are two ways to move forward on this. > > > On Mar 27, 2015, at 4:01 PM, Jeff Scarborough <jef...@gm... <mailto:jef...@gm...>> wrote: > > > > Thank you all for your reply. > > > > @Alex -- I believe you are correct in that fiwalk wants one file. Fortunately, Jason Wright had a workable idea for that. > > > > @Brian Carrier -- Using tsk_gettimes on the image does seem to run through the data. The process ran for several minutes before I stopped the program. It seem the data would be more than what would be found in a single file. > > > > @Simson Garfinkel -- I have a few drive images that I am attempting to extract data using Bulk Extractor. According to a presentation you had given on Bulk Extractor, I am using fiwalk to extract DFXML data and will then run identify_filesnames.py in hopes of linking the data with the files. > > > > @Jason Wright -- Thanks. Using the affuse worked, once I had the commands down correctly. Below are the commands I used for reference. > > > > affuse path/to/image.001 /mnt/combine > > fiwalk -X report.xml /mnt/combine/image.001.raw > > > > Thanks again, > > > > Jeff Scarborough > > > > On Fri, Mar 27, 2015 at 1:58 PM, Simson Garfinkel <si...@ac... <mailto:si...@ac...> <mailto:si...@ac... <mailto:si...@ac...>>> wrote: > > With the fiwalk rewrite, it's using standard Sleuthkit image processing. > > > > However, Jeff, what are you using fiwalk for? What's your interest in DFXML? > > > > Simson > > > > > > > On Mar 27, 2015, at 2:07 PM, Brian Carrier <ca...@sl... <mailto:ca...@sl...> <mailto:ca...@sl... <mailto:ca...@sl...>>> wrote: > > > > > > TSK commands should find the remaining files if you give it just the ".001" file. Not sure about fiwalk's usage. > > > > > > Jeff, if you run tsk_gettimes on the image, then does it find all of them? > > > > > > > > > > > > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough <jef...@gm... <mailto:jef...@gm...> <mailto:jef...@gm... <mailto:jef...@gm...>>> wrote: > > > > > >> I am a new user to SleuthKit and I am attempting to run fiwalk on an image and output a dfxml file. The image is, I believe called a split raw since it is in the form of filename.001, filename.002, filename.003 etc. I am having an issue with the command line to output the file. > > >> > > >> The below command is the example i usually run across. > > >> > > >> fiwalk -X path/report.xml path/image.raw > > >> > > >> > > >> I need to use fiwalk with split files. I used the examples below with limited luck. > > >> > > >> fiwalk -X path/report.xml path/image.dd -- this one said it had trouble opening the file > > >> > > >> fiwalk -X path/report.xml path/image.* -- this one also has trouble > > >> > > >> > > >> The command line below seems to start the process but as far as I can see only processes the first file in the list and none of the others. > > >> > > >> fiwalk -X path/report.xml path/image.001 > > >> > > >> > > >> Am I missing something in the command line that will process all of the files? > > >> > > >> I am using a virtual machine to run linux with SleuthKit installed and the image is on a USB drive. > > >> > > >> Thanks, > > >> Jeff Scarborough > > >> ------------------------------------------------------------------------------ > > >> Dive into the World of Parallel Programming The Go Parallel Website, sponsored > > >> by Intel and developed in partnership with Slashdot Media, is your hub for all > > >> things parallel software development, from weekly thought leadership blogs to > > >> news, videos, case studies, tutorials and more. Take a look and join the > > >> conversation now. http://goparallel.sourceforge.net/_______________________________________________ <http://goparallel.sourceforge.net/_______________________________________________> <http://goparallel.sourceforge.net/_______________________________________________ <http://goparallel.sourceforge.net/_______________________________________________>> > > >> sleuthkit-users mailing list > > >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users>> > > >> http://www.sleuthkit.org <http://www.sleuthkit.org/> <http://www.sleuthkit.org/ <http://www.sleuthkit.org/>> > > > > > > > > > ------------------------------------------------------------------------------ > > > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > > > by Intel and developed in partnership with Slashdot Media, is your hub for all > > > things parallel software development, from weekly thought leadership blogs to > > > news, videos, case studies, tutorials and more. Take a look and join the > > > conversation now. http://goparallel.sourceforge.net/ <http://goparallel.sourceforge.net/> <http://goparallel.sourceforge.net/ <http://goparallel.sourceforge.net/>> > > > _______________________________________________ > > > sleuthkit-users mailing list > > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users>> > > > http://www.sleuthkit.org <http://www.sleuthkit.org/> <http://www.sleuthkit.org/ <http://www.sleuthkit.org/>> > > > > > > -------------- next part -------------- > An HTML attachment was scrubbed... > > ------------------------------ > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ <http://goparallel.sourceforge.net/> > > ------------------------------ > > _______________________________________________ > sleuthkit-users mailing list > sle...@li... <mailto:sle...@li...> > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > > > End of sleuthkit-users Digest, Vol 105, Issue 17 > ************************************************ > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Alan B. <ala...@gm...> - 2015-03-27 21:59:27
|
Simson Is the development of fiwalk still being continued. I use fiwalk to map a drive rather than tsk as I find it produces more info. If it is being further developed, would it be possible to map inside archived files as well Regards Alan On 27 Mar 2015 21:33, <sle...@li...> wrote: > Send sleuthkit-users mailing list submissions to > sle...@li... > > To subscribe or unsubscribe via the World Wide Web, visit > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > or, via email, send a message with subject or body 'help' to > sle...@li... > > You can reach the person managing the list at > sle...@li... > > When replying, please edit your Subject line so it is more specific > than "Re: Contents of sleuthkit-users digest..." > > > Today's Topics: > > 1. Re: Attempting to use fiwalk (Simson Garfinkel) > 2. Re: Attempting to use fiwalk (Jeff Scarborough) > 3. Re: Attempting to use fiwalk (Simson Garfinkel) > > > ---------------------------------------------------------------------- > > Message: 1 > Date: Fri, 27 Mar 2015 14:58:30 -0400 > From: Simson Garfinkel <si...@ac...> > Subject: Re: [sleuthkit-users] Attempting to use fiwalk > To: Brian Carrier <ca...@sl...> > Cc: sle...@li... > Message-ID: <E4E...@ac...> > Content-Type: text/plain; charset=us-ascii > > With the fiwalk rewrite, it's using standard Sleuthkit image processing. > > However, Jeff, what are you using fiwalk for? What's your interest in > DFXML? > > Simson > > > > On Mar 27, 2015, at 2:07 PM, Brian Carrier <ca...@sl...> > wrote: > > > > TSK commands should find the remaining files if you give it just the > ".001" file. Not sure about fiwalk's usage. > > > > Jeff, if you run tsk_gettimes on the image, then does it find all of > them? > > > > > > > > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough < > jef...@gm...> wrote: > > > >> I am a new user to SleuthKit and I am attempting to run fiwalk on an > image and output a dfxml file. The image is, I believe called a split raw > since it is in the form of filename.001, filename.002, filename.003 etc. I > am having an issue with the command line to output the file. > >> > >> The below command is the example i usually run across. > >> > >> fiwalk -X path/report.xml path/image.raw > >> > >> > >> I need to use fiwalk with split files. I used the examples below with > limited luck. > >> > >> fiwalk -X path/report.xml path/image.dd -- this one said it had > trouble opening the file > >> > >> fiwalk -X path/report.xml path/image.* -- this one also has trouble > >> > >> > >> The command line below seems to start the process but as far as I can > see only processes the first file in the list and none of the others. > >> > >> fiwalk -X path/report.xml path/image.001 > >> > >> > >> Am I missing something in the command line that will process all of the > files? > >> > >> I am using a virtual machine to run linux with SleuthKit installed and > the image is on a USB drive. > >> > >> Thanks, > >> Jeff Scarborough > >> > ------------------------------------------------------------------------------ > >> Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > >> by Intel and developed in partnership with Slashdot Media, is your hub > for all > >> things parallel software development, from weekly thought leadership > blogs to > >> news, videos, case studies, tutorials and more. Take a look and join the > >> conversation now. > http://goparallel.sourceforge.net/_______________________________________________ > >> sleuthkit-users mailing list > >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > >> http://www.sleuthkit.org > > > > > > > ------------------------------------------------------------------------------ > > Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > > by Intel and developed in partnership with Slashdot Media, is your hub > for all > > things parallel software development, from weekly thought leadership > blogs to > > news, videos, case studies, tutorials and more. Take a look and join the > > conversation now. http://goparallel.sourceforge.net/ > > _______________________________________________ > > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > http://www.sleuthkit.org > > > > > ------------------------------ > > Message: 2 > Date: Fri, 27 Mar 2015 15:01:37 -0500 > From: Jeff Scarborough <jef...@gm...> > Subject: Re: [sleuthkit-users] Attempting to use fiwalk > To: Simson Garfinkel <si...@ac...>, > sle...@li... > Cc: Brian Carrier <ca...@sl...> > Message-ID: > <CAGzbUa9TgJRO=6U7PwJi= > vGg...@ma...> > Content-Type: text/plain; charset="utf-8" > > Thank you all for your reply. > > @Alex -- I believe you are correct in that fiwalk wants one file. > Fortunately, Jason Wright had a workable idea for that. > > @Brian Carrier -- Using tsk_gettimes on the image does seem to run through > the data. The process ran for several minutes before I stopped the > program. It seem the data would be more than what would be found in a > single file. > > @Simson Garfinkel -- I have a few drive images that I am attempting to > extract data using Bulk Extractor. According to a presentation you had > given on Bulk Extractor, I am using fiwalk to extract DFXML data and will > then run identify_filesnames.py in hopes of linking the data with the > files. > > @Jason Wright -- Thanks. Using the affuse worked, once I had the commands > down correctly. Below are the commands I used for reference. > > affuse path/to/image.001 /mnt/combine > fiwalk -X report.xml /mnt/combine/image.001.raw > > Thanks again, > > Jeff Scarborough > > On Fri, Mar 27, 2015 at 1:58 PM, Simson Garfinkel <si...@ac...> wrote: > > > With the fiwalk rewrite, it's using standard Sleuthkit image processing. > > > > However, Jeff, what are you using fiwalk for? What's your interest in > > DFXML? > > > > Simson > > > > > > > On Mar 27, 2015, at 2:07 PM, Brian Carrier <ca...@sl...> > > wrote: > > > > > > TSK commands should find the remaining files if you give it just the > > ".001" file. Not sure about fiwalk's usage. > > > > > > Jeff, if you run tsk_gettimes on the image, then does it find all of > > them? > > > > > > > > > > > > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough < > > jef...@gm...> wrote: > > > > > >> I am a new user to SleuthKit and I am attempting to run fiwalk on an > > image and output a dfxml file. The image is, I believe called a split > raw > > since it is in the form of filename.001, filename.002, filename.003 > etc. I > > am having an issue with the command line to output the file. > > >> > > >> The below command is the example i usually run across. > > >> > > >> fiwalk -X path/report.xml path/image.raw > > >> > > >> > > >> I need to use fiwalk with split files. I used the examples below with > > limited luck. > > >> > > >> fiwalk -X path/report.xml path/image.dd -- this one said it had > > trouble opening the file > > >> > > >> fiwalk -X path/report.xml path/image.* -- this one also has trouble > > >> > > >> > > >> The command line below seems to start the process but as far as I can > > see only processes the first file in the list and none of the others. > > >> > > >> fiwalk -X path/report.xml path/image.001 > > >> > > >> > > >> Am I missing something in the command line that will process all of > the > > files? > > >> > > >> I am using a virtual machine to run linux with SleuthKit installed and > > the image is on a USB drive. > > >> > > >> Thanks, > > >> Jeff Scarborough > > >> > > > ------------------------------------------------------------------------------ > > >> Dive into the World of Parallel Programming The Go Parallel Website, > > sponsored > > >> by Intel and developed in partnership with Slashdot Media, is your hub > > for all > > >> things parallel software development, from weekly thought leadership > > blogs to > > >> news, videos, case studies, tutorials and more. Take a look and join > the > > >> conversation now. > > > http://goparallel.sourceforge.net/_______________________________________________ > > >> sleuthkit-users mailing list > > >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > >> http://www.sleuthkit.org > > > > > > > > > > > > ------------------------------------------------------------------------------ > > > Dive into the World of Parallel Programming The Go Parallel Website, > > sponsored > > > by Intel and developed in partnership with Slashdot Media, is your hub > > for all > > > things parallel software development, from weekly thought leadership > > blogs to > > > news, videos, case studies, tutorials and more. Take a look and join > the > > > conversation now. http://goparallel.sourceforge.net/ > > > _______________________________________________ > > > sleuthkit-users mailing list > > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > > http://www.sleuthkit.org > > > > > -------------- next part -------------- > An HTML attachment was scrubbed... > > ------------------------------ > > Message: 3 > Date: Fri, 27 Mar 2015 17:32:03 -0400 > From: Simson Garfinkel <si...@ac...> > Subject: Re: [sleuthkit-users] Attempting to use fiwalk > To: Jeff Scarborough <jef...@gm...> > Cc: Brian Carrier <ca...@sl...>, > "sle...@li... users" > <sle...@li...> > Message-ID: <171...@ac...> > Content-Type: text/plain; charset="us-ascii" > > It seems that the main reason people are running fiwalk at this point is > so that they can run identify_filenames.py with bulk_extractor. However, > fiwalk is a bit of a mess and it doesn't fit in well with the sleuthkit > tool suite. tsk_loaddb does a good job with most of what fiwalk does, but > it doesn't support plugins and it doesn't export XML. > > Options: > > 1 - Modify tsk_loaddb to output DFXML. > 2 - Have a Python script that takes a tsk_loaddb Sqlite3 database and > outputs DFXML. > 3 - Modify identify_filenames.py to read the Sqlite3 database produced by > tsk_loaddb. > > I think that #2 and #3 are the right options, in that order, provided that > nobody is making use of the fiwalk plugins (or provided that they can > migrate to something else). Does anyone on the list of a dependency on > dfxml or fiwalk plug-ins? > > Simson > > There are two ways to move forward on this. > > > On Mar 27, 2015, at 4:01 PM, Jeff Scarborough < > jef...@gm...> wrote: > > > > Thank you all for your reply. > > > > @Alex -- I believe you are correct in that fiwalk wants one file. > Fortunately, Jason Wright had a workable idea for that. > > > > @Brian Carrier -- Using tsk_gettimes on the image does seem to run > through the data. The process ran for several minutes before I stopped the > program. It seem the data would be more than what would be found in a > single file. > > > > @Simson Garfinkel -- I have a few drive images that I am attempting to > extract data using Bulk Extractor. According to a presentation you had > given on Bulk Extractor, I am using fiwalk to extract DFXML data and will > then run identify_filesnames.py in hopes of linking the data with the files. > > > > @Jason Wright -- Thanks. Using the affuse worked, once I had the > commands down correctly. Below are the commands I used for reference. > > > > affuse path/to/image.001 /mnt/combine > > fiwalk -X report.xml /mnt/combine/image.001.raw > > > > Thanks again, > > > > Jeff Scarborough > > > > On Fri, Mar 27, 2015 at 1:58 PM, Simson Garfinkel <si...@ac... > <mailto:si...@ac...>> wrote: > > With the fiwalk rewrite, it's using standard Sleuthkit image processing. > > > > However, Jeff, what are you using fiwalk for? What's your interest in > DFXML? > > > > Simson > > > > > > > On Mar 27, 2015, at 2:07 PM, Brian Carrier <ca...@sl... > <mailto:ca...@sl...>> wrote: > > > > > > TSK commands should find the remaining files if you give it just the > ".001" file. Not sure about fiwalk's usage. > > > > > > Jeff, if you run tsk_gettimes on the image, then does it find all of > them? > > > > > > > > > > > > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough < > jef...@gm... <mailto:jef...@gm...>> wrote: > > > > > >> I am a new user to SleuthKit and I am attempting to run fiwalk on an > image and output a dfxml file. The image is, I believe called a split raw > since it is in the form of filename.001, filename.002, filename.003 etc. I > am having an issue with the command line to output the file. > > >> > > >> The below command is the example i usually run across. > > >> > > >> fiwalk -X path/report.xml path/image.raw > > >> > > >> > > >> I need to use fiwalk with split files. I used the examples below > with limited luck. > > >> > > >> fiwalk -X path/report.xml path/image.dd -- this one said it had > trouble opening the file > > >> > > >> fiwalk -X path/report.xml path/image.* -- this one also has trouble > > >> > > >> > > >> The command line below seems to start the process but as far as I can > see only processes the first file in the list and none of the others. > > >> > > >> fiwalk -X path/report.xml path/image.001 > > >> > > >> > > >> Am I missing something in the command line that will process all of > the files? > > >> > > >> I am using a virtual machine to run linux with SleuthKit installed > and the image is on a USB drive. > > >> > > >> Thanks, > > >> Jeff Scarborough > > >> > ------------------------------------------------------------------------------ > > >> Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > > >> by Intel and developed in partnership with Slashdot Media, is your > hub for all > > >> things parallel software development, from weekly thought leadership > blogs to > > >> news, videos, case studies, tutorials and more. Take a look and join > the > > >> conversation now. > http://goparallel.sourceforge.net/_______________________________________________ > < > http://goparallel.sourceforge.net/_______________________________________________ > > > > >> sleuthkit-users mailing list > > >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users < > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > > >> http://www.sleuthkit.org <http://www.sleuthkit.org/> > > > > > > > > > > ------------------------------------------------------------------------------ > > > Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > > > by Intel and developed in partnership with Slashdot Media, is your hub > for all > > > things parallel software development, from weekly thought leadership > blogs to > > > news, videos, case studies, tutorials and more. Take a look and join > the > > > conversation now. http://goparallel.sourceforge.net/ < > http://goparallel.sourceforge.net/> > > > _______________________________________________ > > > sleuthkit-users mailing list > > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users < > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > > > http://www.sleuthkit.org <http://www.sleuthkit.org/> > > > > > > -------------- next part -------------- > An HTML attachment was scrubbed... > > ------------------------------ > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for > all > things parallel software development, from weekly thought leadership blogs > to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > > ------------------------------ > > _______________________________________________ > sleuthkit-users mailing list > sle...@li... > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > > End of sleuthkit-users Digest, Vol 105, Issue 17 > ************************************************ > |
From: Simson G. <si...@ac...> - 2015-03-27 21:32:12
|
It seems that the main reason people are running fiwalk at this point is so that they can run identify_filenames.py with bulk_extractor. However, fiwalk is a bit of a mess and it doesn't fit in well with the sleuthkit tool suite. tsk_loaddb does a good job with most of what fiwalk does, but it doesn't support plugins and it doesn't export XML. Options: 1 - Modify tsk_loaddb to output DFXML. 2 - Have a Python script that takes a tsk_loaddb Sqlite3 database and outputs DFXML. 3 - Modify identify_filenames.py to read the Sqlite3 database produced by tsk_loaddb. I think that #2 and #3 are the right options, in that order, provided that nobody is making use of the fiwalk plugins (or provided that they can migrate to something else). Does anyone on the list of a dependency on dfxml or fiwalk plug-ins? Simson There are two ways to move forward on this. > On Mar 27, 2015, at 4:01 PM, Jeff Scarborough <jef...@gm...> wrote: > > Thank you all for your reply. > > @Alex -- I believe you are correct in that fiwalk wants one file. Fortunately, Jason Wright had a workable idea for that. > > @Brian Carrier -- Using tsk_gettimes on the image does seem to run through the data. The process ran for several minutes before I stopped the program. It seem the data would be more than what would be found in a single file. > > @Simson Garfinkel -- I have a few drive images that I am attempting to extract data using Bulk Extractor. According to a presentation you had given on Bulk Extractor, I am using fiwalk to extract DFXML data and will then run identify_filesnames.py in hopes of linking the data with the files. > > @Jason Wright -- Thanks. Using the affuse worked, once I had the commands down correctly. Below are the commands I used for reference. > > affuse path/to/image.001 /mnt/combine > fiwalk -X report.xml /mnt/combine/image.001.raw > > Thanks again, > > Jeff Scarborough > > On Fri, Mar 27, 2015 at 1:58 PM, Simson Garfinkel <si...@ac... <mailto:si...@ac...>> wrote: > With the fiwalk rewrite, it's using standard Sleuthkit image processing. > > However, Jeff, what are you using fiwalk for? What's your interest in DFXML? > > Simson > > > > On Mar 27, 2015, at 2:07 PM, Brian Carrier <ca...@sl... <mailto:ca...@sl...>> wrote: > > > > TSK commands should find the remaining files if you give it just the ".001" file. Not sure about fiwalk's usage. > > > > Jeff, if you run tsk_gettimes on the image, then does it find all of them? > > > > > > > > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough <jef...@gm... <mailto:jef...@gm...>> wrote: > > > >> I am a new user to SleuthKit and I am attempting to run fiwalk on an image and output a dfxml file. The image is, I believe called a split raw since it is in the form of filename.001, filename.002, filename.003 etc. I am having an issue with the command line to output the file. > >> > >> The below command is the example i usually run across. > >> > >> fiwalk -X path/report.xml path/image.raw > >> > >> > >> I need to use fiwalk with split files. I used the examples below with limited luck. > >> > >> fiwalk -X path/report.xml path/image.dd -- this one said it had trouble opening the file > >> > >> fiwalk -X path/report.xml path/image.* -- this one also has trouble > >> > >> > >> The command line below seems to start the process but as far as I can see only processes the first file in the list and none of the others. > >> > >> fiwalk -X path/report.xml path/image.001 > >> > >> > >> Am I missing something in the command line that will process all of the files? > >> > >> I am using a virtual machine to run linux with SleuthKit installed and the image is on a USB drive. > >> > >> Thanks, > >> Jeff Scarborough > >> ------------------------------------------------------------------------------ > >> Dive into the World of Parallel Programming The Go Parallel Website, sponsored > >> by Intel and developed in partnership with Slashdot Media, is your hub for all > >> things parallel software development, from weekly thought leadership blogs to > >> news, videos, case studies, tutorials and more. Take a look and join the > >> conversation now. http://goparallel.sourceforge.net/_______________________________________________ <http://goparallel.sourceforge.net/_______________________________________________> > >> sleuthkit-users mailing list > >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > >> http://www.sleuthkit.org <http://www.sleuthkit.org/> > > > > > > ------------------------------------------------------------------------------ > > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > > by Intel and developed in partnership with Slashdot Media, is your hub for all > > things parallel software development, from weekly thought leadership blogs to > > news, videos, case studies, tutorials and more. Take a look and join the > > conversation now. http://goparallel.sourceforge.net/ <http://goparallel.sourceforge.net/> > > _______________________________________________ > > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users <https://lists.sourceforge.net/lists/listinfo/sleuthkit-users> > > http://www.sleuthkit.org <http://www.sleuthkit.org/> > > |
From: Jeff S. <jef...@gm...> - 2015-03-27 20:01:44
|
Thank you all for your reply. @Alex -- I believe you are correct in that fiwalk wants one file. Fortunately, Jason Wright had a workable idea for that. @Brian Carrier -- Using tsk_gettimes on the image does seem to run through the data. The process ran for several minutes before I stopped the program. It seem the data would be more than what would be found in a single file. @Simson Garfinkel -- I have a few drive images that I am attempting to extract data using Bulk Extractor. According to a presentation you had given on Bulk Extractor, I am using fiwalk to extract DFXML data and will then run identify_filesnames.py in hopes of linking the data with the files. @Jason Wright -- Thanks. Using the affuse worked, once I had the commands down correctly. Below are the commands I used for reference. affuse path/to/image.001 /mnt/combine fiwalk -X report.xml /mnt/combine/image.001.raw Thanks again, Jeff Scarborough On Fri, Mar 27, 2015 at 1:58 PM, Simson Garfinkel <si...@ac...> wrote: > With the fiwalk rewrite, it's using standard Sleuthkit image processing. > > However, Jeff, what are you using fiwalk for? What's your interest in > DFXML? > > Simson > > > > On Mar 27, 2015, at 2:07 PM, Brian Carrier <ca...@sl...> > wrote: > > > > TSK commands should find the remaining files if you give it just the > ".001" file. Not sure about fiwalk's usage. > > > > Jeff, if you run tsk_gettimes on the image, then does it find all of > them? > > > > > > > > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough < > jef...@gm...> wrote: > > > >> I am a new user to SleuthKit and I am attempting to run fiwalk on an > image and output a dfxml file. The image is, I believe called a split raw > since it is in the form of filename.001, filename.002, filename.003 etc. I > am having an issue with the command line to output the file. > >> > >> The below command is the example i usually run across. > >> > >> fiwalk -X path/report.xml path/image.raw > >> > >> > >> I need to use fiwalk with split files. I used the examples below with > limited luck. > >> > >> fiwalk -X path/report.xml path/image.dd -- this one said it had > trouble opening the file > >> > >> fiwalk -X path/report.xml path/image.* -- this one also has trouble > >> > >> > >> The command line below seems to start the process but as far as I can > see only processes the first file in the list and none of the others. > >> > >> fiwalk -X path/report.xml path/image.001 > >> > >> > >> Am I missing something in the command line that will process all of the > files? > >> > >> I am using a virtual machine to run linux with SleuthKit installed and > the image is on a USB drive. > >> > >> Thanks, > >> Jeff Scarborough > >> > ------------------------------------------------------------------------------ > >> Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > >> by Intel and developed in partnership with Slashdot Media, is your hub > for all > >> things parallel software development, from weekly thought leadership > blogs to > >> news, videos, case studies, tutorials and more. Take a look and join the > >> conversation now. > http://goparallel.sourceforge.net/_______________________________________________ > >> sleuthkit-users mailing list > >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > >> http://www.sleuthkit.org > > > > > > > ------------------------------------------------------------------------------ > > Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > > by Intel and developed in partnership with Slashdot Media, is your hub > for all > > things parallel software development, from weekly thought leadership > blogs to > > news, videos, case studies, tutorials and more. Take a look and join the > > conversation now. http://goparallel.sourceforge.net/ > > _______________________________________________ > > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > http://www.sleuthkit.org > > |
From: Simson G. <si...@ac...> - 2015-03-27 18:58:38
|
With the fiwalk rewrite, it's using standard Sleuthkit image processing. However, Jeff, what are you using fiwalk for? What's your interest in DFXML? Simson > On Mar 27, 2015, at 2:07 PM, Brian Carrier <ca...@sl...> wrote: > > TSK commands should find the remaining files if you give it just the ".001" file. Not sure about fiwalk's usage. > > Jeff, if you run tsk_gettimes on the image, then does it find all of them? > > > > On Mar 27, 2015, at 1:27 PM, Jeff Scarborough <jef...@gm...> wrote: > >> I am a new user to SleuthKit and I am attempting to run fiwalk on an image and output a dfxml file. The image is, I believe called a split raw since it is in the form of filename.001, filename.002, filename.003 etc. I am having an issue with the command line to output the file. >> >> The below command is the example i usually run across. >> >> fiwalk -X path/report.xml path/image.raw >> >> >> I need to use fiwalk with split files. I used the examples below with limited luck. >> >> fiwalk -X path/report.xml path/image.dd -- this one said it had trouble opening the file >> >> fiwalk -X path/report.xml path/image.* -- this one also has trouble >> >> >> The command line below seems to start the process but as far as I can see only processes the first file in the list and none of the others. >> >> fiwalk -X path/report.xml path/image.001 >> >> >> Am I missing something in the command line that will process all of the files? >> >> I am using a virtual machine to run linux with SleuthKit installed and the image is on a USB drive. >> >> Thanks, >> Jeff Scarborough >> ------------------------------------------------------------------------------ >> Dive into the World of Parallel Programming The Go Parallel Website, sponsored >> by Intel and developed in partnership with Slashdot Media, is your hub for all >> things parallel software development, from weekly thought leadership blogs to >> news, videos, case studies, tutorials and more. Take a look and join the >> conversation now. http://goparallel.sourceforge.net/_______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Jason W. <jwr...@gm...> - 2015-03-27 18:11:26
|
best way to concatenate them is to use affuse affuse /path/to/image.001 /mnt/aff it will virtualize the split dd's into one raw file in the /mnt/aff directory. takes a second, then you can run fiwalk against it. On Fri, Mar 27, 2015 at 1:33 PM, Alex Nelson <ajn...@cs...> wrote: > Hi Jeff, > > As I recall, as a regular Fiwalk user, the split-files code is just for > the split Encase format files. Split raw files aren't recognized by the > TSK libraries. > > You'll either have to concatenate them, or gerry-rig some way of treating > them as one big virtual file. > > --Alex > > > > On Fri, Mar 27, 2015 at 1:27 PM, Jeff Scarborough < > jef...@gm...> wrote: > >> I am a new user to SleuthKit and I am attempting to run fiwalk on an >> image and output a dfxml file. The image is, I believe called a split raw >> since it is in the form of filename.001, filename.002, filename.003 etc. I >> am having an issue with the command line to output the file. >> >> The below command is the example i usually run across. >> >> fiwalk -X path/report.xml path/image.raw >> >> >> I need to use fiwalk with split files. I used the examples below with >> limited luck. >> >> fiwalk -X path/report.xml path/image.dd -- this one said it had trouble >> opening the file >> >> fiwalk -X path/report.xml path/image.* -- this one also has trouble >> >> >> The command line below seems to start the process but as far as I can see >> only processes the first file in the list and none of the others. >> >> fiwalk -X path/report.xml path/image.001 >> >> >> Am I missing something in the command line that will process all of the >> files? >> >> I am using a virtual machine to run linux with SleuthKit installed and >> the image is on a USB drive. >> >> Thanks, >> Jeff Scarborough >> >> >> ------------------------------------------------------------------------------ >> Dive into the World of Parallel Programming The Go Parallel Website, >> sponsored >> by Intel and developed in partnership with Slashdot Media, is your hub >> for all >> things parallel software development, from weekly thought leadership >> blogs to >> news, videos, case studies, tutorials and more. Take a look and join the >> conversation now. http://goparallel.sourceforge.net/ >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org >> >> > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for > all > things parallel software development, from weekly thought leadership blogs > to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: Brian C. <ca...@sl...> - 2015-03-27 18:07:09
|
TSK commands should find the remaining files if you give it just the ".001" file. Not sure about fiwalk's usage. Jeff, if you run tsk_gettimes on the image, then does it find all of them? On Mar 27, 2015, at 1:27 PM, Jeff Scarborough <jef...@gm...> wrote: > I am a new user to SleuthKit and I am attempting to run fiwalk on an image and output a dfxml file. The image is, I believe called a split raw since it is in the form of filename.001, filename.002, filename.003 etc. I am having an issue with the command line to output the file. > > The below command is the example i usually run across. > > fiwalk -X path/report.xml path/image.raw > > > I need to use fiwalk with split files. I used the examples below with limited luck. > > fiwalk -X path/report.xml path/image.dd -- this one said it had trouble opening the file > > fiwalk -X path/report.xml path/image.* -- this one also has trouble > > > The command line below seems to start the process but as far as I can see only processes the first file in the list and none of the others. > > fiwalk -X path/report.xml path/image.001 > > > Am I missing something in the command line that will process all of the files? > > I am using a virtual machine to run linux with SleuthKit installed and the image is on a USB drive. > > Thanks, > Jeff Scarborough > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: RB <ao...@gm...> - 2015-03-27 18:05:36
|
On Fri, Mar 27, 2015 at 11:33 AM, Alex Nelson <ajn...@cs...> wrote: > You'll either have to concatenate them, or gerry-rig some way of treating > them as one big virtual file. xmount will help with that. |
From: Alex N. <ajn...@cs...> - 2015-03-27 17:59:33
|
Hi Jeff, As I recall, as a regular Fiwalk user, the split-files code is just for the split Encase format files. Split raw files aren't recognized by the TSK libraries. You'll either have to concatenate them, or gerry-rig some way of treating them as one big virtual file. --Alex On Fri, Mar 27, 2015 at 1:27 PM, Jeff Scarborough < jef...@gm...> wrote: > I am a new user to SleuthKit and I am attempting to run fiwalk on an image > and output a dfxml file. The image is, I believe called a split raw since > it is in the form of filename.001, filename.002, filename.003 etc. I am > having an issue with the command line to output the file. > > The below command is the example i usually run across. > > fiwalk -X path/report.xml path/image.raw > > > I need to use fiwalk with split files. I used the examples below with > limited luck. > > fiwalk -X path/report.xml path/image.dd -- this one said it had trouble > opening the file > > fiwalk -X path/report.xml path/image.* -- this one also has trouble > > > The command line below seems to start the process but as far as I can see > only processes the first file in the list and none of the others. > > fiwalk -X path/report.xml path/image.001 > > > Am I missing something in the command line that will process all of the > files? > > I am using a virtual machine to run linux with SleuthKit installed and the > image is on a USB drive. > > Thanks, > Jeff Scarborough > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for > all > things parallel software development, from weekly thought leadership blogs > to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: Jeff S. <jef...@gm...> - 2015-03-27 17:27:52
|
I am a new user to SleuthKit and I am attempting to run fiwalk on an image and output a dfxml file. The image is, I believe called a split raw since it is in the form of filename.001, filename.002, filename.003 etc. I am having an issue with the command line to output the file. The below command is the example i usually run across. fiwalk -X path/report.xml path/image.raw I need to use fiwalk with split files. I used the examples below with limited luck. fiwalk -X path/report.xml path/image.dd -- this one said it had trouble opening the file fiwalk -X path/report.xml path/image.* -- this one also has trouble The command line below seems to start the process but as far as I can see only processes the first file in the list and none of the others. fiwalk -X path/report.xml path/image.001 Am I missing something in the command line that will process all of the files? I am using a virtual machine to run linux with SleuthKit installed and the image is on a USB drive. Thanks, Jeff Scarborough |
From: Simson G. <si...@ac...> - 2015-03-26 10:05:36
|
How about this: Add New Source Dialogue: * Specify Source * Specify immediate start (default) or start when START button is pressed. Queued Sources Dialogue: * Shows all sources and current state of each * Allows them to be re-ordered * Each source has multiple actions that are initially grouped, but can be separated, e.g.: - file system parsing - file processing - unallocated processing - end of image processing > On Mar 25, 2015, at 11:15 PM, Brian Carrier <ca...@sl...> wrote: > > Starting a new thread for one of the topics brought up today. A couple of people mentioned variations on queueing up multiple images into Autopsy or processing multiple images. > > The current behavior is: > - A single case can be opened at a time. > - You can add multiple data sources to a case (which is a process to scan the media to enumerate the files - no content analysis is performed), though only one is added at a time. You'll need to wait several minutes before you can add the next one though. > - After a data source has been added, the ingest modules are kicked off and you can add a 2nd data source. > - Because of the prioritization methods in Autopsy, processing of the first data source may stop for a while after the 2nd data source is added. This is because there is a prioritized list of folders and folders in the 2nd data source may have a higher priority than the remaining folders in data source 1. > > So, what do you want to change / expand? There seem to be two ideas that I could infer from the comments: > > 1) While you are waiting for the file system structure of data source one to finish, you can browse to additional data sources so that they are immediately added after the first one is and the rest of the process is as it is now. You just don't need to wait around for a few minutes. > > 2) Or we change the prioritization approach so that the first data source finishes sooner than it will with the current approach. > > Or, is it something else that is wanted? > > thanks, > brian > > > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Ketil F. <ke...@fr...> - 2015-03-26 09:16:40
|
I agree with Derrick. I think each image should finish processing before continuing. I have seen images take a long time to add, if I could just queue more images that's not a problem. Or even multiprocessing, my workstation has 16 cores and a big NAS backing my disk images, so if autopsy's database can handle it, I'm all for having several workers in parallel. :) But I also think this should cover ingest modules. Running ingests also has to be done manually after the image is added, and unless I'm mistaken, running ingest on multiple images at the same time is probably not a good idea. If I could set up a sort of "ingest profile" for my case, then all the images could be ingested with my case options as soon as each image is added and ingest resources are ready, and I can just fire up a big load/ingest and walk away until it's all done. I figure that if I add several images, I'm not in a great big rush to see the results of the fifth image. Regards, Ketil On 26 March 2015 at 06:51, Derrick Karpo <dk...@gm...> wrote: > Hi Brian. > > I would like to see a version of #1 where images can be added to the > queue at any time without waiting for ingest to occur. I often find > myself adding an image and then thinking, "Doh! I should have also > added image X!", and then I have to wait. I then get consumed by > something else since I have a few minutes to spare but then don't get > back to adding the other image for an hour, or two, or eight. So, I > think Autopsy should be changed to cater to my poor multitasking > abilities. :) > > The current prioritization approach works for getting usable results > faster to the user and I don't think changing that is beneficial. If > we could just have the ability to queue images at any time in the > Autopsy processing chain that would be slick. > > Derrick > > > On Wed, Mar 25, 2015 at 9:15 PM, Brian Carrier <ca...@sl...> wrote: >> Starting a new thread for one of the topics brought up today. A couple of people mentioned variations on queueing up multiple images into Autopsy or processing multiple images. >> >> The current behavior is: >> - A single case can be opened at a time. >> - You can add multiple data sources to a case (which is a process to scan the media to enumerate the files - no content analysis is performed), though only one is added at a time. You'll need to wait several minutes before you can add the next one though. >> - After a data source has been added, the ingest modules are kicked off and you can add a 2nd data source. >> - Because of the prioritization methods in Autopsy, processing of the first data source may stop for a while after the 2nd data source is added. This is because there is a prioritized list of folders and folders in the 2nd data source may have a higher priority than the remaining folders in data source 1. >> >> So, what do you want to change / expand? There seem to be two ideas that I could infer from the comments: >> >> 1) While you are waiting for the file system structure of data source one to finish, you can browse to additional data sources so that they are immediately added after the first one is and the rest of the process is as it is now. You just don't need to wait around for a few minutes. >> >> 2) Or we change the prioritization approach so that the first data source finishes sooner than it will with the current approach. >> >> Or, is it something else that is wanted? >> >> thanks, >> brian >> >> >> >> >> ------------------------------------------------------------------------------ >> Dive into the World of Parallel Programming The Go Parallel Website, sponsored >> by Intel and developed in partnership with Slashdot Media, is your hub for all >> things parallel software development, from weekly thought leadership blogs to >> news, videos, case studies, tutorials and more. Take a look and join the >> conversation now. http://goparallel.sourceforge.net/ >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org -- -Ketil |
From: Derrick K. <dk...@gm...> - 2015-03-26 05:51:51
|
Hi Brian. I would like to see a version of #1 where images can be added to the queue at any time without waiting for ingest to occur. I often find myself adding an image and then thinking, "Doh! I should have also added image X!", and then I have to wait. I then get consumed by something else since I have a few minutes to spare but then don't get back to adding the other image for an hour, or two, or eight. So, I think Autopsy should be changed to cater to my poor multitasking abilities. :) The current prioritization approach works for getting usable results faster to the user and I don't think changing that is beneficial. If we could just have the ability to queue images at any time in the Autopsy processing chain that would be slick. Derrick On Wed, Mar 25, 2015 at 9:15 PM, Brian Carrier <ca...@sl...> wrote: > Starting a new thread for one of the topics brought up today. A couple of people mentioned variations on queueing up multiple images into Autopsy or processing multiple images. > > The current behavior is: > - A single case can be opened at a time. > - You can add multiple data sources to a case (which is a process to scan the media to enumerate the files - no content analysis is performed), though only one is added at a time. You'll need to wait several minutes before you can add the next one though. > - After a data source has been added, the ingest modules are kicked off and you can add a 2nd data source. > - Because of the prioritization methods in Autopsy, processing of the first data source may stop for a while after the 2nd data source is added. This is because there is a prioritized list of folders and folders in the 2nd data source may have a higher priority than the remaining folders in data source 1. > > So, what do you want to change / expand? There seem to be two ideas that I could infer from the comments: > > 1) While you are waiting for the file system structure of data source one to finish, you can browse to additional data sources so that they are immediately added after the first one is and the rest of the process is as it is now. You just don't need to wait around for a few minutes. > > 2) Or we change the prioritization approach so that the first data source finishes sooner than it will with the current approach. > > Or, is it something else that is wanted? > > thanks, > brian > > > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Brian C. <ca...@sl...> - 2015-03-26 03:15:20
|
Starting a new thread for one of the topics brought up today. A couple of people mentioned variations on queueing up multiple images into Autopsy or processing multiple images. The current behavior is: - A single case can be opened at a time. - You can add multiple data sources to a case (which is a process to scan the media to enumerate the files - no content analysis is performed), though only one is added at a time. You'll need to wait several minutes before you can add the next one though. - After a data source has been added, the ingest modules are kicked off and you can add a 2nd data source. - Because of the prioritization methods in Autopsy, processing of the first data source may stop for a while after the 2nd data source is added. This is because there is a prioritized list of folders and folders in the 2nd data source may have a higher priority than the remaining folders in data source 1. So, what do you want to change / expand? There seem to be two ideas that I could infer from the comments: 1) While you are waiting for the file system structure of data source one to finish, you can browse to additional data sources so that they are immediately added after the first one is and the rest of the process is as it is now. You just don't need to wait around for a few minutes. 2) Or we change the prioritization approach so that the first data source finishes sooner than it will with the current approach. Or, is it something else that is wanted? thanks, brian |
From: Sean M. <mcl...@in...> - 2015-03-25 23:21:37
|
> I think that it would be very useful for Autopsy to run > on another platform—either Linux or Mac, but probably Linux. > That would allow it to be used on bootable CDs without > requiring a full Windows environment. I would agree with this whole heartedly. I practical never used Windows as my primary analysis system (and when I do it is because certain tools ONLY run in Windows but those tools are becoming much less relevant to my work). Most of the triage and early processing is OS X or, more commonly, Linux, where I am relatively certain that the image that I am analyzing is not going to corrupt my analysis system. Sean McLinden -- NOTICE of CONFIDENTIALITY and DISCLAIMER This transmission, including attachments, is confidential. It may also be privileged or otherwise protected by work product immunity or other legal rules. If you have received it by mistake, please let us know by e-mail to the sender, only, and delete it from your system; you may not copy this message or disclose its contents to anyone. Unless expressly noted, above, this communication does not reflect an intention by the sender to conduct a transaction or make any agreement by electronic means. Nothing contained in this transmission shall constitute a contract or electronic signature under the ESIGN, any version of the UETA, or any other statute governing electronic transactions. If this transmission contains advice, the advice is based on instructions in relation to, and is provided to the addressee in connection with, the matter mentioned above. Responsibility is not accepted for reliance upon it by any other person or for any other purpose. |
From: Alan B. <ala...@gm...> - 2015-03-25 22:29:04
|
New photorec carver is a great addition but only processing unallocated. Definitely better support for carving of files in allocated such as pagefil, shadow volumes, thumbcache, etc. Option in photorec to choose what files are extracted. I too would like native support on Linux, have managed to run autopsy on Ubuntu but photorec module only works on windows only. Also generating reports that include bookmarked images should include a thumbnail of the image with mac times. Great work done on autopsy to date |
From: Brian C. <ca...@sl...> - 2015-03-25 22:18:41
|
Hi Nanni, What do you mean by this? Do you mean an HTML report with a table and rows for events or an ASCII timeline similar to the old mactime reports? thanks, brian On Mar 25, 2015, at 10:06 AM, Nanni Bassetti <dig...@gm...> wrote: > Timeline exportable report > > Dott. Nanni Bassetti www.nannibassetti.com > > Il 25/mar/2015 14:59 "Simson Garfinkel" <si...@ac...> ha scritto: > I think that it would be very useful for Autopsy to run on another platform—either Linux or Mac, but probably Linux. That would allow it to be used on bootable CDs without requiring a full Windows environment. > > The second thing I'd like to see is some kind of support for parallel computation on multiple systems—an Autopsy cluster. > > Finally, I'd like to see better support for encrypted containers and password cracking. > > On Wed, Mar 25, 2015 at 9:47 AM, Brian Carrier <ca...@sl...> wrote: > I'm taking a survey to help plan for some future development. What is the one feature that you want most in Autopsy that is not there? Send replies to either me directly or the list. > > thanks, > brian > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Brian C. <ca...@sl...> - 2015-03-25 22:17:45
|
Thanks everyone. On the Linux front, I sent a message out to some package maintainers to get them involved to figure out what we should be doing so that it is easy for them to package. thanks, brian On Mar 25, 2015, at 9:47 AM, Brian Carrier <ca...@sl...> wrote: > I'm taking a survey to help plan for some future development. What is the one feature that you want most in Autopsy that is not there? Send replies to either me directly or the list. > > thanks, > brian > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Atila <ati...@dp...> - 2015-03-25 20:54:39
|
Yes, it is possible, but I'm sure there would be more users with prepacked packages. Not a terrible problem for me, I use a Windows VM in a Fedora host (ridiculous, I know). On 25-03-2015 16:29, Ketil Froyn wrote: > > I agree that a prepackaged Linux version would be nice, but I think > this is a packaging issue that doesn't require lots of development > resources and planning for the future. Autopsy builds nicely on Ubuntu > Linux today, so I already run it on Linux. Fairly comprehensive build > instructions are available here if anybody wants to try: > > http://forum.sleuthkit.org/viewtopic.php?f=5&t=106 > > Ketil > > On 25 Mar 2015 20:16, "Atila" <ati...@dp... > <mailto:ati...@dp...>> wrote: > > +1 > On 25-03-2015 14:10, Luis Gómez 'Pope' wrote: >> +1, give us Linux support back!! (PLEASE) :) >> >> Keep up the good work Brian, and thanks! >> >> -- >> Sent from a mobile device. Please excuse any typos. >> >> >> El 25/3/2015, a las 14:57, Simson Garfinkel <si...@ac... >> <mailto:si...@ac...>> escribió: >> >>> I think that it would be very useful for Autopsy to run on >>> another platform—either Linux or Mac, but probably Linux. That >>> would allow it to be used on bootable CDs without requiring a >>> full Windows environment. >>> >>> The second thing I'd like to see is some kind of support for >>> parallel computation on multiple systems—an Autopsy cluster. >>> >>> Finally, I'd like to see better support for encrypted containers >>> and password cracking. >>> >>> On Wed, Mar 25, 2015 at 9:47 AM, Brian Carrier >>> <ca...@sl... <mailto:ca...@sl...>> wrote: >>> >>> I'm taking a survey to help plan for some future >>> development. What is the one feature that you want most in >>> Autopsy that is not there? Send replies to either me >>> directly or the list. >>> >>> thanks, >>> brian >>> > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel > Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your > hub for all > things parallel software development, from weekly thought > leadership blogs to > news, videos, case studies, tutorials and more. Take a look and > join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |