Directories
¶
| Path | Synopsis |
|---|---|
|
cmd
|
|
|
ffind
command
Find forensic artifacts in mount points or on the live system.
|
Find forensic artifacts in mount points or on the live system. |
|
flog
command
Log forensic artifacts as JSON in ECS.
|
Log forensic artifacts as JSON in ECS. |
|
fmount
command
Mount disk images for read-only processing.
|
Mount disk images for read-only processing. |
|
internal
|
|
|
fact
Fact definitions.
|
Fact definitions. |
|
fact/ez
Fact ez functions.
|
Fact ez functions. |
|
fact/hash
Hash functions.
|
Hash functions. |
|
fact/zip
Zip archive functions.
|
Zip archive functions. |
|
ffind
FFind functions.
|
FFind functions. |
|
flog
Eric Zimmermann tools.
|
Eric Zimmermann tools. |
|
fmount
Dislocker functions.
|
Dislocker functions. |
|
sys
System functions.
|
System functions. |
|
test
Test functions.
|
Test functions. |
|
pkg
|
|
|
ecs
ECS event mapping functions.
|
ECS event mapping functions. |
|
ffind
FFind implementation details.
|
FFind implementation details. |
|
flog
FLog implementation details.
|
FLog implementation details. |
|
fmount
FMount implementation details.
|
FMount implementation details. |
|
windows
Windows system artifact enumeration functions.
|
Windows system artifact enumeration functions. |
Click to show internal directories.
Click to hide internal directories.