ForensicsWiki will continue to operate as it has before and will not be shutting down. Thank you for your continued support of ForensicsWiki.

Difference between revisions of "PyFlag"

From ForensicsWiki
Jump to: navigation, search
m
(External Links)
Line 47: Line 47:
  
 
= External Links =
 
= External Links =
 +
http://sourceforge.net/projects/pyflag/
  
 
==External Reviews==
 
==External Reviews==

Revision as of 01:28, 17 June 2007

PyFlag
Maintainer: Michael Cohen, David Collett
OS: Linux,Web-based
Genre: Analysis
License: GPL
Website: pyflag.net


PyFlag is a web-based, database-backed forensic and log analysis GUI written in Python. PyFlag stores disk images in the sgzip format.

Features

File Systems Understood

File Search Facilities

  • Lists allocated and unallocated files.
  • Sorts files by type.
  • Searches for keywords.
  • Works with compressed zip files.

Historical Reconstruction

Can it build timelines and search by creation date?

  • Creates a "case file".

Searching Abilities

  • Searches for keywords.
  • Builds an index.

Hash Databases

Evidence Collection Features

History

License Notes

External Links

http://sourceforge.net/projects/pyflag/

External Reviews