Skip to main content

ntrprtr configurations for forensic analysis of file systems

Project description

Description

ntrprtr configurations for forensic analysis of file systems

Installation

pip install ntrprtr_fs_forensics

Usage

Shell:


General

Option Short Type Default Description
--mode -m String - copy = Create a local copy of file system forensics configuration files

mode = copy

Option Short Type Default Description
--path -p String "" Path for local copy of ntrprtr configuration files

Example

To use this configuration files install ntrprtr and ntrprtr_fs_forensics:

pip install ntrprtr
pip install ntrprtr_fs_forensics

To use the files, create a local copy:

python -m ntrprtr_fs_forensics -m copy -p .

It creates the following structure:

./ntrprtr-fsf-config
├───ext
│       ext-file-descriptor-table.json
│       ext-group-descriptor-table.json
│       ext-inode.json
│       ext-super-block.json
│
├───fat
│       fat-directory-entry.json
│       fat-fs-info.json
│       fat-long-filename.json
│       fat-vbr-fat1216.json
│       fat-vbr-fat32.json
│       fat-vbr-type.json
│       fat-vbr.json
│
└───ntfs
        ntfs-attribute-header-general.json
        ntfs-attribute-header-non-resident.json
        ntfs-attribute-header-resident.json
        ntfs-mft-header.json
        ntfs-vbr.json

Now just use the config as input for ntrprtr:

python -m ntrprtr -m interpret -p dir-entry.bin -c ./ntrprtr-fsf-config/fat/fat-directory-entry.json -r result.txt

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ntrprtr_fs_forensics-0.3.0.tar.gz (12.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ntrprtr_fs_forensics-0.3.0-py3-none-any.whl (18.8 kB view details)

Uploaded Python 3

File details

Details for the file ntrprtr_fs_forensics-0.3.0.tar.gz.

File metadata

  • Download URL: ntrprtr_fs_forensics-0.3.0.tar.gz
  • Upload date:
  • Size: 12.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.1 CPython/3.10.8

File hashes

Hashes for ntrprtr_fs_forensics-0.3.0.tar.gz
Algorithm Hash digest
SHA256 9862f4fcfe838a2e08479c5034d6c3be0e180d74b77b5cd544c192f59c2ba469
MD5 a46bacad46bbb00ae4c471dff49ee06d
BLAKE2b-256 7fbf41fc1e08f940b76a7b5cec8748b740c0b567aeb7ef741dbf02e09981227c

See more details on using hashes here.

File details

Details for the file ntrprtr_fs_forensics-0.3.0-py3-none-any.whl.

File metadata

File hashes

Hashes for ntrprtr_fs_forensics-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 ce951618812df8539698b3cb0b3ed07c025d99fcec363b40ee5eb04150cb6ca1
MD5 2e4cf6500193bfa8cb0311548d7e4d8c
BLAKE2b-256 56d07a5711878b7c3b6a879e8910c4b97c6a16813845409921fed19b1931924a

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page