Rebuild Elastic Block Storage (EBS) direct API blocks into a DD forensic image generated by Snap4n6 Serverless Imager.
Project description
Snap4n6 CLI
Rebuild Elastic Block Storage (EBS) direct API blocks into a DD forensic image generated by Snap4n6 Serverless Imager.
Permissions
- s3:GetBucketLocation
- s3:GetObject
- s3:ListBucket
- ssm:GetParameter
Installation
pip install snap4n6
Help
Snap4n6 v0.4.0
optional arguments:
-h, --help show this help message and exit
Required:
--region REGION us-east-2
--snapid SNAPID snap-0f3e60199f11889da
Optional:
--ext4 Rebuild EXT4 File System
Command
Microsoft Windows Snapshots contain the NTFS File System necessary to rebuild a forensic image.
Linux Snapshots require the creation of Superblocks for the EXT4 File System using: mkfs.ext4
snap4n6 --region us-east-2 --snapid snap-0f3e60199f11889da --ext4
Output
Snap4n6 v0.4.0
Region: us-east-2
Snapshot: snap-0f3e60199f11889da
Ext4 Fs: True
0+0 records in
0+0 records out
0 bytes (0 B) copied, 0.000209499 s, 0.0 kB/s
mke2fs 1.42.9 (28-Dec-2013)
snap-0f3e60199f11889da.dd is not a block special device.
Proceed anyway? (y,n) Discarding device blocks: done
Filesystem label=
OS type: Linux
Block size=4096 (log=2)
Fragment size=4096 (log=2)
Stride=0 blocks, Stripe width=0 blocks
65536 inodes, 262144 blocks
13107 blocks (5.00%) reserved for the super user
First data block=0
Maximum filesystem blocks=268435456
8 block groups
32768 blocks per group, 32768 fragments per group
8192 inodes per group
Superblock backups stored on blocks:
32768, 98304, 163840, 229376
Allocating group tables: done
Writing inode tables: done
Creating journal (8192 blocks): done
Writing superblocks and filesystem accounting information: done
4%|██▌ | 4/104 [00:05<02:07, 1.28s/it]
Local Development
$ python setup.py install --user
Alternatives
- aws-snap-io - https://github.com/forensicmatt/aws-snap-io
- coldsnap - https://github.com/awslabs/coldsnap
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
snap4n6-0.4.2.tar.gz
(7.7 kB
view details)
Built Distribution
File details
Details for the file snap4n6-0.4.2.tar.gz
.
File metadata
- Download URL: snap4n6-0.4.2.tar.gz
- Upload date:
- Size: 7.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.2 CPython/3.9.16
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 725eb93ed2f6e8424cb793499c26adfd198f1c79357c1a918902d21e5638cf16 |
|
MD5 | 54449bc467642b67dc44d649246d48ef |
|
BLAKE2b-256 | 6f715f93c4fc6a18d9628d05069453d2284c8b5015fb8d71408fe5d1c656fa11 |
File details
Details for the file snap4n6-0.4.2-py3-none-any.whl
.
File metadata
- Download URL: snap4n6-0.4.2-py3-none-any.whl
- Upload date:
- Size: 8.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.2 CPython/3.9.16
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 0aef4eaa6d7c99b34579eeac010e3a43dd4958236fa3fcfb6ac5936de06ea1bf |
|
MD5 | d70217191ae3e8c7d0a122638c6508ba |
|
BLAKE2b-256 | 66d2b65caf2bdfa07f9989cbd06e931861d5efd68d0319cea4ddcd20c16bfd3c |