Skip to main content

ntrprtr configurations for forensic analysis of file systems

Project description

Description

ntrprtr configurations for forensic analysis of file systems

Installation

pip install ntrprtr_fs_forensics

Usage

Shell:


General

Option Short Type Default Description
--mode -m String - copy = Create a local copy of file system forensics configuration files

mode = copy

Option Short Type Default Description
--path -p String "" Path for local copy of ntrprtr configuration files

Example

To use this configuration files install ntrprtr and ntrprtr_fs_forensics:

pip install ntrprtr
pip install ntrprtr_fs_forensics

To use the files, create a local copy:

python -m ntrprtr_fs_forensics -m copy -p .

It creates the following structure:

./ntrprtr-fsf-config
|
├───ext
│       ext-group-descriptor-table.json
│       ext-inode.json
│       ext-super-block.json
│
├───fat
│       fat-directory-entry.json
│       fat-fs-info.json
│       fat-long-filename.json
│       fat-vbr-fat1216.json
│       fat-vbr-fat32.json
│       fat-vbr-type.json
│       fat-vbr.json
|
├───gpt
│       gpt-entry.json
|       gpt-header.json
|
├───mbr
│       mbr.json
│
└───ntfs
        ntfs-attribute-file-name.json
        ntfs-attribute-header-general.json
        ntfs-attribute-header-non-resident.json
        ntfs-attribute-header-resident.json
        ntfs-attribute-standard-information.json
        ntfs-mft-entry-header.json
        ntfs-vbr.json

Now just use the config as input for ntrprtr:

python -m ntrprtr -m interpret -p dir-entry.bin -c ./ntrprtr-fsf-config/fat/fat-directory-entry.json -r result.txt

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ntrprtr_fs_forensics-0.7.0.tar.gz (14.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ntrprtr_fs_forensics-0.7.0-py3-none-any.whl (24.1 kB view details)

Uploaded Python 3

File details

Details for the file ntrprtr_fs_forensics-0.7.0.tar.gz.

File metadata

  • Download URL: ntrprtr_fs_forensics-0.7.0.tar.gz
  • Upload date:
  • Size: 14.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.1 CPython/3.10.8

File hashes

Hashes for ntrprtr_fs_forensics-0.7.0.tar.gz
Algorithm Hash digest
SHA256 4488a05db25c892a40b582e1fea1f6d3a2f367c958edda12d0f333afd89cf81e
MD5 dd3bf5d4bc2524a7caa75bfaa245b4b2
BLAKE2b-256 51c6f21d14aee02fa29d4be7f17ecacf1c3f0024a37178a6485586b78d85120c

See more details on using hashes here.

File details

Details for the file ntrprtr_fs_forensics-0.7.0-py3-none-any.whl.

File metadata

File hashes

Hashes for ntrprtr_fs_forensics-0.7.0-py3-none-any.whl
Algorithm Hash digest
SHA256 1e089cae73e45fb7f6c76c439f46c87e3477c74e1840423874963bb245b6660f
MD5 6deab7b7b326529691877601745ca605
BLAKE2b-256 4ea43fe5e4b2f2b56ddd788aa85e5841b31f69d7d1254fbf8464af3a380e311b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page