<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.forensicswiki.org/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;feed=atom&amp;action=history</id>
		<title>Snorkel - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;action=history"/>
		<updated>2013-05-24T06:31:49Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.20.3</generator>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;diff=9754&amp;oldid=prev</id>
		<title>Joachim Metz: /* Image File Formats Understood */</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;diff=9754&amp;oldid=prev"/>
				<updated>2012-09-20T19:30:12Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Image File Formats Understood&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
			&lt;tr style='vertical-align: top;'&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 19:30, 20 September 2012&lt;/td&gt;
			&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 20:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 20:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;{|&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;{|&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Image file formats&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Image file formats&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|[[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Encase_image_file_format&lt;/del&gt;|EnCase]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|[[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Encase image file format&lt;/ins&gt;|EnCase]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;| &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;| &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Joachim Metz</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;diff=9753&amp;oldid=prev</id>
		<title>Joachim Metz at 19:29, 20 September 2012</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;diff=9753&amp;oldid=prev"/>
				<updated>2012-09-20T19:29:54Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
			&lt;tr style='vertical-align: top;'&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 19:29, 20 September 2012&lt;/td&gt;
			&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 23:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 23:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;| &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;| &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;RAW (&lt;/del&gt;[[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Dd&lt;/del&gt;|dd]]&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;)&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|[[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Raw Image Format&lt;/ins&gt;|&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;RAW (&lt;/ins&gt;dd&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;)&lt;/ins&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;| &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;| &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;VMWare (&lt;/del&gt;[[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;vmdk&lt;/del&gt;]]&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;)&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|[[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;VMWare Virtual Disk Format (VMDK)|VMWare (VMDK)&lt;/ins&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|}&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Joachim Metz</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;diff=9752&amp;oldid=prev</id>
		<title>Joachim Metz: /* File Systems Understood */</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;diff=9752&amp;oldid=prev"/>
				<updated>2012-09-14T15:24:47Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;File Systems Understood&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
			&lt;tr style='vertical-align: top;'&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 15:24, 14 September 2012&lt;/td&gt;
			&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 33:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 33:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;{|&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;{|&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Volume managers&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Volume managers&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Windows (LDM)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;|[[Logical Disk Manager (LDM)&lt;/ins&gt;|Windows (LDM)&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Partitioning schemes&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;|Partitioning schemes&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Joachim Metz</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;diff=9751&amp;oldid=prev</id>
		<title>Bally: Created page with '{{Infobox_Software |   name = Snorkel |   maintainer = NFI |   os = Java |   genre = {{Analysis}}  |   license = proprietary |   website = [http://www.holmes.nl/NFIlabs/Snorkel h…'</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Snorkel&amp;diff=9751&amp;oldid=prev"/>
				<updated>2009-08-18T13:00:49Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;#039;{{Infobox_Software |   name = Snorkel |   maintainer = NFI |   os = Java |   genre = {{Analysis}}  |   license = proprietary |   website = [http://www.holmes.nl/NFIlabs/Snorkel h…&amp;#039;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Infobox_Software |&lt;br /&gt;
  name = Snorkel |&lt;br /&gt;
  maintainer = NFI |&lt;br /&gt;
  os = Java |&lt;br /&gt;
  genre = {{Analysis}}  |&lt;br /&gt;
  license = proprietary |&lt;br /&gt;
  website = [http://www.holmes.nl/NFIlabs/Snorkel http://www.holmes.nl/NFIlabs/Snorkel] |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
'''Snorkel''' is a Java software library that is used by developers of forensic software. Snorkel is not a standalone forensic application, but it is an important piece of infrastructure that can be used by many forensic applications: Snorkel gives access to digital evidence files, file systems, files, slack space, unallocated clusters, etc. This type of access is a key enabler in the development of forensic software systems, ranging from single-purpose stand-alone tools to integrated forensic processing systems.&lt;br /&gt;
&lt;br /&gt;
Snorkel is developed by the Netherlands Forensic Institute&lt;br /&gt;
&lt;br /&gt;
=Features=&lt;br /&gt;
&lt;br /&gt;
Snorkel recognizes and gives access to numerous storage formats for digital evidence, disk partitioning schemes, volume managers, file systems, and structured files. The formats supported are summarized below.&lt;br /&gt;
&lt;br /&gt;
==Image File Formats Understood==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|Image file formats&lt;br /&gt;
|[[Encase_image_file_format|EnCase]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|RAW ([[Dd|dd]])&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|VMWare ([[vmdk]])&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==File Systems Understood==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|Volume managers&lt;br /&gt;
|Windows (LDM)&lt;br /&gt;
|-&lt;br /&gt;
|Partitioning schemes&lt;br /&gt;
|PC/MBR&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|Apple&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|GPT&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|BSD&lt;br /&gt;
|-&lt;br /&gt;
|File systems&lt;br /&gt;
|Windows ([[FAT]], [[NTFS]])&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|Apple ([[MFS]], [[HFS]], [[HFS+]])&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|Linux ([[Ext3|EXT]], [[Reiserfs|Reiser]])&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|Solaris, BSD ([[UFS]])&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|CD ([[ISO9660]], Joliet)&lt;br /&gt;
|-&lt;br /&gt;
|File Formats&lt;br /&gt;
|Windows registry (Win 9x, NT)&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|Microsoft Office (OLE2)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ==File Search Facilities== --&amp;gt;&lt;br /&gt;
&amp;lt;!-- ==Historical Reconstruction== --&amp;gt;&lt;br /&gt;
&amp;lt;!-- Can it build timelines and search by creation date? --&amp;gt;&lt;br /&gt;
&amp;lt;!-- ==Searching Abilities== --&amp;gt;&lt;br /&gt;
&amp;lt;!-- Can it search? Does it build an index? Can it focus on file types or particular kinds of metadata? --&amp;gt;&lt;br /&gt;
&amp;lt;!-- ==Hash Databases== --&amp;gt;&lt;br /&gt;
&amp;lt;!-- Can it create hashes of files and/or blocks? Can it compare these hash values to any databases? --&amp;gt;&lt;br /&gt;
&amp;lt;!-- What sort of hash functions does it use? --&amp;gt;&lt;br /&gt;
&amp;lt;!-- ==Evidence Collection Features== --&amp;gt;&lt;br /&gt;
&amp;lt;!-- Can it sign files? Does it keep an audit log? --&amp;gt;&lt;br /&gt;
&amp;lt;!-- =History= --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==License Notes==&lt;br /&gt;
&lt;br /&gt;
Snorkel is has a proprietary license.&lt;br /&gt;
An evaluation version is available from the website.&lt;br /&gt;
&lt;br /&gt;
= External Links =&lt;br /&gt;
&lt;br /&gt;
* [http://www.forensischinstituut.nl/ the Netherlands Forensic Institute]&lt;br /&gt;
* [http://www.holmes.nl/NFIlabs/Snorkel Snorkel website]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- ==External Reviews== --&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bally</name></author>	</entry>

	</feed>