Skip to main content

Advanced Forensic Format Version 4 (AFF4) Python module.

Project description

AFF4 -The Advanced Forensics File Format

The Advanced Forensics File Format 4 (AFF4) is an open source format used for the storage of digital evidence and data.

It was originally designed and published in [1] and has since been standardised as the AFF4 Standard v1.0, which is available at https://github.com/aff4/Standard. This project is a work in progress implementation, providing two library implementations, C/C++ and Python.

What is currently supported.

The focus of this implementation is reading physical images conforming with the AFF4 Standard v1.0, and for the ongoing development of an AFF4 based logical image standard.

Canonical images for the v1.0 physical image specification are provided in the AFF4 Reference Images github project at https://github.com/aff4/ReferenceImages

  1. Reading, writing & appending to ZipFile style volumes.
  2. Reading striped ZipFile volumes.
  3. Reading & writing AFF4 ImageStreams using the deflate or snappy compressor.
  4. Reading RDF metadata using Turtle (and to some degree YAML).
  5. Verification of linear and block hashed images.
  6. Reading & writing logical images (new) .
  7. Reading & writing deduplicated logical images (new).
  8. Encrypted AFF4 logical volumes (new).

What is not yet supported:

The write support in the libraries is currently broken and being worked on. Other aspects of the AFF4 that have not yet been implemented in this codebase include:

  1. Persistent data store (resolver).
  2. HTTP backed streams.
  3. Support for signed statements or Bill of Materials.
  4. Directory based volumes.

Notice

This is not an official Google product (experimental or otherwise), it is just code that happens to be owned by Google and Schatz Forensic.

References

[1] "Extending the advanced forensic format to accommodate multiple data sources, logical evidence, arbitrary information and forensic workflow" M.I. Cohen, Simson Garfinkel and Bradley Schatz, digital investigation 6 (2009) S57-S68.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pyaff4-0.33.tar.gz (96.0 kB view details)

Uploaded Source

Built Distribution

pyaff4-0.33-py3-none-any.whl (136.5 kB view details)

Uploaded Python 3

File details

Details for the file pyaff4-0.33.tar.gz.

File metadata

  • Download URL: pyaff4-0.33.tar.gz
  • Upload date:
  • Size: 96.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/2.0.0 pkginfo/1.5.0.1 requests/2.22.0 setuptools/41.6.0 requests-toolbelt/0.9.1 tqdm/4.38.0 CPython/3.7.0

File hashes

Hashes for pyaff4-0.33.tar.gz
Algorithm Hash digest
SHA256 e91987c0d39af1ed1a4297176e2ac30c59fc96daf0cf65757205df54926b8a95
MD5 dd56bfa2bd0ebf4620a7211ec5e23078
BLAKE2b-256 8e4fd5f0d6c7c76b3e2428373d76a390c238d30d16755d5109a546e19cafa98f

See more details on using hashes here.

File details

Details for the file pyaff4-0.33-py3-none-any.whl.

File metadata

  • Download URL: pyaff4-0.33-py3-none-any.whl
  • Upload date:
  • Size: 136.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/2.0.0 pkginfo/1.5.0.1 requests/2.22.0 setuptools/41.6.0 requests-toolbelt/0.9.1 tqdm/4.38.0 CPython/3.7.0

File hashes

Hashes for pyaff4-0.33-py3-none-any.whl
Algorithm Hash digest
SHA256 9764d8aec6cb42cdd98f234bedda052b6e19e5a3b19ae1e8c832160ee09664e6
MD5 f8ce2931a89c2f570bca9cd9d1c15792
BLAKE2b-256 68f6fa8ea85f36aa842ad3ab88c7e66116913f2476ff74ef216948bf64a5fa60

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page