Difference between revisions of "PyFlag"
From Forensics Wiki
Uwe Hermann (Talk | contribs) (Rewritten description (the previous was cut'n'pasted from the website). Added history.) |
Uwe Hermann (Talk | contribs) m (Pyflag moved to PyFlag) |
Revision as of 15:49, 21 March 2006
PyFlag is a web-based, database-backed forensic and log analysis GUI written in Python.
Contents |
Features
File Systems Understood
File Search Facilities
- Lists allocated and unallocated files.
- Sorts files by type.
- Searches for keywords.
- Works with compressed zip files.
Historical Reconstruction
Can it build timelines and search by creation date?
- Creates a "case file".
Searching Abilities
- Searches for keywords.
- Builds an index.
Hash Databases
- Hashes and compares with Hashkeeper using MD5.
Evidence Collection Features
History
- Originally started by the Australian Department of Defence, PyFlag is now hosted on SourceForge.
License Notes
- GNU GPL.