Skip to main content

ntrprtr configurations for forensic analysis of file systems

Project description

Description

ntrprtr configurations for forensic analysis of file systems

Installation

pip install ntrprtr_fs_forensics

Usage

Shell:


General

Option Short Type Default Description
--mode -m String - copy = Create a local copy of file system forensics configuration files

mode = copy

Option Short Type Default Description
--path -p String "" Path for local copy of ntrprtr configuration files

Example

To use this configuration files install ntrprtr and ntrprtr_fs_forensics:

pip install ntrprtr
pip install ntrprtr_fs_forensics

To use the files, create a local copy:

python -m ntrprtr_fs_forensics -m copy -p .

It creates the following structure:

./ntrprtr-fsf-config
├───ext
│       ext-group-descriptor-table.json
│       ext-inode.json
│       ext-super-block.json
│
├───fat
│       fat-directory-entry.json
│       fat-fs-info.json
│       fat-long-filename.json
│       fat-vbr-fat1216.json
│       fat-vbr-fat32.json
│       fat-vbr-type.json
│       fat-vbr.json
│
└───ntfs
        ntfs-attribute-file-name.json
        ntfs-attribute-header-general.json
        ntfs-attribute-header-non-resident.json
        ntfs-attribute-header-resident.json
        ntfs-attribute-standard-information.json
        ntfs-mft-entry-header.json
        ntfs-vbr.json

Now just use the config as input for ntrprtr:

python -m ntrprtr -m interpret -p dir-entry.bin -c ./ntrprtr-fsf-config/fat/fat-directory-entry.json -r result.txt

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ntrprtr_fs_forensics-0.5.0.tar.gz (13.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ntrprtr_fs_forensics-0.5.0-py3-none-any.whl (21.2 kB view details)

Uploaded Python 3

File details

Details for the file ntrprtr_fs_forensics-0.5.0.tar.gz.

File metadata

  • Download URL: ntrprtr_fs_forensics-0.5.0.tar.gz
  • Upload date:
  • Size: 13.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.1 CPython/3.10.8

File hashes

Hashes for ntrprtr_fs_forensics-0.5.0.tar.gz
Algorithm Hash digest
SHA256 07b6f60d770ee0d06b5699d9117e9a29d8e9cd4748d141d646a55e70269d145b
MD5 eaca75810b6927e7bf66361de53b2a6c
BLAKE2b-256 69f9aae74e667257cadbdf2b35a8ff0cc1365a53ebcae299546639ed81eb3ef2

See more details on using hashes here.

File details

Details for the file ntrprtr_fs_forensics-0.5.0-py3-none-any.whl.

File metadata

File hashes

Hashes for ntrprtr_fs_forensics-0.5.0-py3-none-any.whl
Algorithm Hash digest
SHA256 071b8c41cb47cba69aeb9c6ee19d7e29b848995142da08fe306020672dc0979a
MD5 12ed2eadbb3a26e380661f92f31f886f
BLAKE2b-256 8cee3502eb010b6e45951a98a80452dd56b3d1cbf756ad4c739b69224a91a235

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page