PyFlag
From Forensics Wiki
Contents |
Pyflag
"FLAG (Forensic and Log Analysis GUI) was designed to simplify the process of log file analysis and forensic investigations. Often, when investigating a large case, a great deal of data needs to be analysed and correlated. PyFlag uses a database as a backend to assist in managing the large volumes of data. This allows PyFlag to remain responsive and expedite data manipulation operations."
Features
File Systems Understood
(unknown)
File Search Facilities
- Lists allocated and unallocated files.
- Sorts files by type.
- Searches for keywords.
- Registry Viewer
Historical Reconstruction
Can it build timelines and search by creation date?
Searching Abilities
- Searches for keywords.
- Builds an index.
Hash Databases
- Hashes and compares with Hashkeeper using MD5.
Evidence Collection Features
History
- Creates a "case file".
License Notes
GNU GPL.
External Links
[http://pyflag.sourceforge.net/ Website}