Skip to main content

ntrprtr configurations for forensic analysis of file systems

Project description

Description

ntrprtr configurations for forensic analysis of file systems

Installation

pip install ntrprtr_fs_forensics

Usage

Shell:


General

Option Short Type Default Description
--mode -m String - copy = Create a local copy of file system forensics configuration files

mode = copy

Option Short Type Default Description
--path -p String "" Path for local copy of ntrprtr configuration files

Example

To use this configuration files install ntrprtr and ntrprtr_fs_forensics:

pip install ntrprtr
pip install ntrprtr_fs_forensics

To use the files, create a local copy:

python -m ntrprtr_fs_forensics -m copy -p .

It creates the following structure:

./ntrprtr-fsf-config
├───ext
│       ext-group-descriptor-table.json
│       ext-inode.json
│       ext-super-block.json
│       
├───fat
│       fat-directory-entry.json
│       fat-fs-info.json
│       fat-long-filename.json
│       fat-vbr-fat1216.json
│       fat-vbr-fat32.json
│       fat-vbr-type.json
│       fat-vbr.json
│
└───ntfs

Now just use the config as input for ntrprtr:

python -m ntrprtr -m interpret -p dir-entry.bin -c ./ntrprtr-fsf-config/fat/fat-directory-entry.json -r result.txt

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ntrprtr_fs_forensics-0.1.0.tar.gz (9.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ntrprtr_fs_forensics-0.1.0-py3-none-any.whl (14.1 kB view details)

Uploaded Python 3

File details

Details for the file ntrprtr_fs_forensics-0.1.0.tar.gz.

File metadata

  • Download URL: ntrprtr_fs_forensics-0.1.0.tar.gz
  • Upload date:
  • Size: 9.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.1 CPython/3.10.8

File hashes

Hashes for ntrprtr_fs_forensics-0.1.0.tar.gz
Algorithm Hash digest
SHA256 585ff63bbd6da1d493acfc6eeb8977a1d40c5585c5e70cbb5281cd53cb33e905
MD5 0405a24382fd712f42613e64053f4571
BLAKE2b-256 447aeeecc702ee0c5c58f7069914cac25a2589fbed770d112cc0dec8ab453fbf

See more details on using hashes here.

File details

Details for the file ntrprtr_fs_forensics-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for ntrprtr_fs_forensics-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9c6832c7515c055e440c801f596ad620f71c62792fd04ed8c714e507d9182068
MD5 04d351e04306ff608ca570f773c48f64
BLAKE2b-256 59b35024c470c08fc313f66415bfcbbf36827db16fd4abaded58b56d7e35e16f

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page