The goal of this tool is to "extract images and pdf files from a forensic image".

This tool will also extract additional information about the files. Including, file type specific features, such as EXIF data in images and metadata tags in PDF files.

Other information included about the extracted files:

  • An MD5 hash of the file
  • The file size
  • The offset into the image file where the file is found

The extracted files are catagorized into deleted and overt folder structure, representing if the file was recovered from allocated or unallocated locations in the file system.

midterm.py(9.71 KB) marcbudofsky, May 9 2013, 12:17 PM

You must Sign-In to post a comment.