c-aff4

c-aff4

#Incident Management#Digital Forensics

Tool for parsing NTFS journal files, $Logfile, and $MFT.

Visit Website

The Advanced Forensics File Format: An Overview

The Advanced Forensics File Format 4 (AFF4) is an open-source format specifically designed for the storage of digital evidence and data. This format allows for effective management and preservation of forensic information.

This project implements a C/C++ library for AFF4 image processing

This project implements a C/C++ library designed for creating, reading, and manipulating AFF4 images. It also includes the canonical aff4imager binary, which serves as a versatile standalone imaging tool.

The library and binary are compatible with multiple operating systems

The library and binary are confirmed to function on Linux, Windows, and OSX.

It supports reading and writing various volume types

It supports reading and writing ZipFile-style volumes, Directory-style volumes, and AFF4 Image streams. This functionality utilizes either the deflate or snappy compression methods.

Support for Multi-Threaded Imaging for Enhanced Performance

It also supports multi-threaded imaging, allowing for efficient utilization on multi-core systems.

However, it does not currently

However, it does not currently implement Section 6 of the standard, which includes the processes for verifying or generating linear or block hashes.