The following DFXML tools are provided:
| Script name | Short description |
|---|---|
| allocation_counter | Produces a cross-tabulation of the allocation state of each file’s inode and name |
| cat_fileobjects.py | Prints a new DFXML of all fileobjects in an input DFXML file to stdout |
| cat_partitions.py | Concatenates dfxml-files containing one partition each and prints result to stdout |
| deidentify_xml.py | Removes PII from filenames in a DFXML file |
| dfxinfo.py | Print information about a DFXML file |
| dfxml_html.py | A collection of functions for generating HTML |
| Extractor.py | Extracts files specified in a XML-file (or all) from an image to a target directory |
| hash_sectors.py | Outputs sector hashes for sectors with files matching a predicate |
| iblkfind.py | Outputs files, which are located in a given set of sectors |
| icarvingtruth.py | Finds the ground truth in a predefined series of disk images |
| idifference.py | Generates a report about what’s different between two disk images. |
| igrep.py | Find files in image, which contain the given string |
| ihistogram.py | Draws a quick histogram of the timestamps in an XML file |
| imap.py | Map image files and try to find “missing” data by comparing with the other imgs |
| iredact.py | Image redaction tool using a set of rules |
| ireport.py | Generates stats from a DFXML file(s) |
| iverify | Checks, an image if all files specified in an XML file are present |
| rdifference.py | Finds and reports differences in two Windows registry hive-files |
| report_silent_changes.py | Takes a differentially-annotated DFXML file and outputs subtle and ‘silent’ changes |
- dfxml_tool.py
- walk_to_dfxml.py
- idifference.py/idifference2.py
- ireport.py
- iexport.py
- exp_slack.py
- validate_dfxml.py
- nsrl_rds.py
- corpus_sync.py
- make_differential_dfxml.py
- break_out_diffs_by_anno.py
- mem_info.py (no dependencies)