The Advanced Forensics File Format 4 (AFF4) is an open source format used for the storage of digital evidence and data. This project implements a C/C++ library for creating, reading and manipulating AFF4 images, and includes the canonical aff4imager binary which provides a general purpose standalone imaging tool. The library and binary are known to work on Linux, Windows, and OSX. It supports reading and writing ZipFile style volumes, Directory style volumes, and AFF4 Image streams using deflate or snappy compressor. It also supports multi-threaded imaging for efficient utilization on multi-core systems. However, it does not currently implement Section 6. Hashing of the standard, including verifying or generating linear or block hashes.
This tool is not verified yet and doesn't have listed features.
Did you submit the verified tool? Sign in to add features.
Are you the author? Claim the tool by clicking the icon above. After claiming, you can add features.
A community-sourced repository of digital forensic artifacts in YAML format.
A command-line tool for searching and extracting strings from files with various options like ASCII and Unicode string search.
Customizable live OS constructor tool for remote forensics and incident response.
A tool for triaging crash files with various output formats and debugging engine options.
A forensics tool for tracking USB device artifacts on Linux machines.
A library to access FileVault Drive Encryption (FVDE) encrypted volumes on Mac OS X systems.