Difference between revisions of "Forensic file formats"

From ForensicsWiki
Redirect page
Jump to: navigation, search
m (Proprietary Formats)
 
(20 intermediate revisions by 11 users not shown)
Line 1: Line 1:
==Proprietary Formats==
+
#REDIRECT [[:Category:Forensics_File_Formats]]
The proprietary formats are usually created by the vendor of a particular tool. In most cases they are named after that tool. Where documentation exists, we link to it.
+
 
+
; [[EnCase]]
+
: Has it's own format. Images in this format can be created by the [[Encase Imager]], which is freely available. Reading those images, however, requires the full version of [[EnCase]].
+
 
+
; [[iLook]]
+
: We're told it has it's own format.
+
 
+
; [[SMART]] from ASR Data.
+
: This format uses a raw image and a second file with proprietary metadata (at least it did a couple of years ago).
+
 
+
; [[FTK]] Logical Image Format
+
: According to FTK's documentation, "The image created will include only logical files; it will not include any file system metadata, deleted files, unallocated space, etc. It cannot be converted to a sector image (such as .E01) because it does not store sector information. Although logical images can be examined in FTK Imager 2.x or newer, they are not supported by the current version of FTK. Logical image support will be added to FTK in a future release."
+
 
+
; [[Safeback]] images
+
: Some people have used Safeback for forensic purposes, although these images always need to be restored before they can be used.
+
 
+
 
+
 
+
===Older formats, not really in use anymore===
+
 
+
; [[DIBS]] Disk Image Backup System, by Computer Forensics
+
 
+
; [[Vogon Imager]]
+
: Vogon imager claims that it can handle EnCase. There is some evidence that it may have (or had) its own file format as well. http://www.vogon-forensic-hardware.com/
+
 
+
===Ones we aren't so sure about===
+
 
+
; [[FTK]] by Access Data.
+
: We think that they use their own format, but we have never used FTK to acquire. ?
+
 
+
==Open Formats==
+
; [[AFF]]
+
: Full details of the format and a working implementation can be downloaded from http://www.afflib.org/
+
 
+
; Seekable GZIP
+
: This format is used by the [[PyFlag]] disk forensics system. Although it's compressed and supports seeking, it does not support the inclusion of metadata in the image file.
+
 
+
; [[ProDiscover]] format from Technology Pathways.
+
: This format is documented at http://www.techpathways.com/uploads/ProDiscoverImageFileFormatv4.pdf
+

Latest revision as of 20:13, 20 April 2009