Skip to main content

ntrprtr configurations for forensic analysis of file systems

Project description

Description

ntrprtr configurations for forensic analysis of file systems

Installation

pip install ntrprtr_fs_forensics

Usage

Shell:


General

Option Short Type Default Description
--mode -m String - copy = Create a local copy of file system forensics configuration files

mode = copy

Option Short Type Default Description
--path -p String "" Path for local copy of ntrprtr configuration files

Example

To use this configuration files install ntrprtr and ntrprtr_fs_forensics:

pip install ntrprtr
pip install ntrprtr_fs_forensics

To use the files, create a local copy:

python -m ntrprtr_fs_forensics -m copy -p .

It creates the following structure:

./ntrprtr-fsf-config
├───ext
│       ext-file-descriptor-table.json
│       ext-group-descriptor-table.json
│       ext-inode.json
│       ext-super-block.json
│
├───fat
│       fat-directory-entry.json
│       fat-fs-info.json
│       fat-long-filename.json
│       fat-vbr-fat1216.json
│       fat-vbr-fat32.json
│       fat-vbr-type.json
│       fat-vbr.json
│
└───ntfs
        ntfs-attribute-header-general.json
        ntfs-attribute-header-non-resident.json
        ntfs-attribute-header-resident.json
        ntfs-mft-header.json
        ntfs-vbr.json

Now just use the config as input for ntrprtr:

python -m ntrprtr -m interpret -p dir-entry.bin -c ./ntrprtr-fsf-config/fat/fat-directory-entry.json -r result.txt

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ntrprtr_fs_forensics-0.4.0.tar.gz (12.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ntrprtr_fs_forensics-0.4.0-py3-none-any.whl (18.9 kB view details)

Uploaded Python 3

File details

Details for the file ntrprtr_fs_forensics-0.4.0.tar.gz.

File metadata

  • Download URL: ntrprtr_fs_forensics-0.4.0.tar.gz
  • Upload date:
  • Size: 12.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.1 CPython/3.10.8

File hashes

Hashes for ntrprtr_fs_forensics-0.4.0.tar.gz
Algorithm Hash digest
SHA256 f23472bb8556951aef1aa866ad4243fc621f7721fb73b3bdc35086db25f6fc38
MD5 04da676560fe2c4189efd79c6063710b
BLAKE2b-256 6e0c82d18fc3f3fb514e11b24b862c9ed9dbcc972363e17262775b592fa0fab7

See more details on using hashes here.

File details

Details for the file ntrprtr_fs_forensics-0.4.0-py3-none-any.whl.

File metadata

File hashes

Hashes for ntrprtr_fs_forensics-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 e531dbbf1b81f7bfac1ef9f2051b9434e5f93150b20fa6b8024ae2f209a53872
MD5 a85f1d1e4b0566f4065763440f90695b
BLAKE2b-256 0ee0ffa5612cda2a2f45b6c6647d786fadc87b56ee918686dbdde11c25a49261

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page