Skip to content

Latest commit

 

History

History
46 lines (38 loc) · 2.78 KB

File metadata and controls

46 lines (38 loc) · 2.78 KB

Tools for working with DFXML-files

Overview about the provided tools

The following DFXML tools are provided:

Script nameShort description
allocation_counterProduces a cross-tabulation of the allocation state of each file’s inode and name
cat_fileobjects.pyPrints a new DFXML of all fileobjects in an input DFXML file to stdout
cat_partitions.pyConcatenates dfxml-files containing one partition each and prints result to stdout
deidentify_xml.pyRemoves PII from filenames in a DFXML file
dfxinfo.pyPrint information about a DFXML file
dfxml_html.pyA collection of functions for generating HTML
Extractor.pyExtracts files specified in a XML-file (or all) from an image to a target directory
hash_sectors.pyOutputs sector hashes for sectors with files matching a predicate
iblkfind.pyOutputs files, which are located in a given set of sectors
icarvingtruth.pyFinds the ground truth in a predefined series of disk images
idifference.pyGenerates a report about what’s different between two disk images.
igrep.pyFind files in image, which contain the given string
ihistogram.pyDraws a quick histogram of the timestamps in an XML file
imap.pyMap image files and try to find “missing” data by comparing with the other imgs
iredact.pyImage redaction tool using a set of rules
ireport.pyGenerates stats from a DFXML file(s)
iverifyChecks, an image if all files specified in an XML file are present
rdifference.pyFinds and reports differences in two Windows registry hive-files
report_silent_changes.pyTakes a differentially-annotated DFXML file and outputs subtle and ‘silent’ changes

Work needed

  • dfxml_tool.py
  • walk_to_dfxml.py
  • idifference.py/idifference2.py
  • ireport.py
  • iexport.py
  • exp_slack.py
  • validate_dfxml.py
  • nsrl_rds.py
  • corpus_sync.py

Uncategorized

  • make_differential_dfxml.py
  • break_out_diffs_by_anno.py
  • mem_info.py (no dependencies)