c-aff4 Logo

c-aff4

0
Free
Visit Website

The Advanced Forensics File Format 4 (AFF4) is an open source format used for the storage of digital evidence and data. This project implements a C/C++ library for creating, reading and manipulating AFF4 images, and includes the canonical aff4imager binary which provides a general purpose standalone imaging tool. The library and binary are known to work on Linux, Windows, and OSX. It supports reading and writing ZipFile style volumes, Directory style volumes, and AFF4 Image streams using deflate or snappy compressor. It also supports multi-threaded imaging for efficient utilization on multi-core systems. However, it does not currently implement Section 6. Hashing of the standard, including verifying or generating linear or block hashes.

FEATURES

ALTERNATIVES

A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.

A digital forensic tool for creating forensic images of computer hard drives and analyzing digital evidence.

A script for extracting common Windows artifacts from source images and VSCs with detailed dependencies and usage instructions.

A collection of Mac OS X and iOS forensics resources with a focus on artifact collection and collaboration.

A forensics tool for tracking USB device artifacts on Linux machines.

A command-line utility and Python package for mounting and unmounting various disk image formats with support for different volume systems and filesystems.

A shell script for basic forensic collection of various artefacts from UNIX systems.

Universal hexadecimal editor for computer forensics, data recovery, and IT security.

PINNED