Skip to main content

AFF4 -The Advanced Forensics File Format

The Advanced Forensics File Format 4 (AFF4) is an open source format used for the storage of digital evidence and data.

It was originally designed and published in [1] and has since been standardised as the AFF4 Standard v1.0, which is available at https://github.com/aff4/Standard. This project is a work in progress implementation, providing two library implementations, C/C++ and Python.

What is currently supported.

The focus of this implementation is reading physical images conforming with the AFF4 Standard v1.0, and for the ongoing development of an AFF4 based logical image standard.

Canonical images for the v1.0 physical image specification are provided in the AFF4 Reference Images github project at https://github.com/aff4/ReferenceImages

  1. Reading, writing & appending to ZipFile style volumes.
  2. Reading striped ZipFile volumes.
  3. Reading & writing AFF4 ImageStreams using the deflate or snappy compressor.
  4. Reading RDF metadata using Turtle (and to some degree YAML).
  5. Verification of linear and block hashed images.
  6. Reading & writing logical images (new) .
  7. Reading & writing deduplicated logical images (new).
  8. Encrypted AFF4 logical volumes (new).

What is not yet supported:

The write support in the libraries is currently broken and being worked on. Other aspects of the AFF4 that have not yet been implemented in this codebase include:

  1. Persistent data store (resolver).
  2. HTTP backed streams.
  3. Support for signed statements or Bill of Materials.
  4. Directory based volumes.

Notice

This is not an official Google product (experimental or otherwise), it is just code that happens to be owned by Google and Schatz Forensic.

References

[1] "Extending the advanced forensic format to accommodate multiple data sources, logical evidence, arbitrary information and forensic workflow" M.I. Cohen, Simson Garfinkel and Bradley Schatz, digital investigation 6 (2009) S57-S68.

Release files for pyaff4 0.34

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pyaff4 0.34
File Size Uploaded
pyaff4-0.34.tar.gz 101.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pyaff4 0.34
File Interpreter ABI Platform
pyaff4-0.34-py3-none-any.whl Python 3 none any Details

Total release size: 238.8 kB

Release files / pyaff4-0.34.tar.gz

Download URL pyaff4-0.34.tar.gz
Size 101.9 kB
Tags Source
SHA-256 checksum
How to use checksums
36a3236d8914e66c88b42d42ecb361c1f8dd1474ffe92a1743a7c0be8b82c6fe
BLAKE2b-256 checksum
How to use checksums
0a52cfe15539d649b9096c2ad64d4cd7f6aa21bcd41bbc55712c8f83c846cc3c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.4.2 importlib_metadata/4.6.3 pkginfo/1.7.1 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.62.0 CPython/3.9.6

Release files / pyaff4-0.34-py3-none-any.whl

Download URL pyaff4-0.34-py3-none-any.whl
Size 136.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e89ecda38a354689425c910bea63ef3106513c7f4829cdfbbd65d892a57f4a52
BLAKE2b-256 checksum
How to use checksums
afe4ef695ff2a0a973c52023a503d14d09cba8449a03ef8b8e5eddf890ab9f9c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.4.2 importlib_metadata/4.6.3 pkginfo/1.7.1 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.62.0 CPython/3.9.6

Release history Release notifications | RSS feed

This release

0.34 This release

2 release files

0.33

2 release files

0.32

2 release files

0.31

2 release files

0.27

1 release file

0.26

1 release file

0.24

1 release file

0.23

2 release files

0.22

2 release files

0.21

2 release files

0.20

1 release file

0.19

1 release file

0.18

1 release file

0.17

1 release file

0.16

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page