mirror of
https://github.com/Ponce/slackbuilds
synced 2024-11-14 21:56:41 +01:00
7d6aa2d75b
Signed-off-by: David Spencer <idlemoor@slackbuilds.org>
23 lines
972 B
Text
23 lines
972 B
Text
bulk_extractor is a C++ program that scans a disk image, a file, or a directory
|
|
of files and extracts useful information without parsing the file system or
|
|
file system structures. The results are stored in feature files that can be
|
|
easily inspected, parsed, or processed with automated tools. bulk_extractor
|
|
also creates histograms of features that it finds, as features that are more
|
|
common tend to be more important.
|
|
|
|
bulk_extractor is distinguished from other forensic tools by its speed and
|
|
thoroughness.
|
|
|
|
Optional dependancies include libewf (recognized if installed), afflib
|
|
(recognized if installed), and liblightgrep.
|
|
|
|
To add optional liblightgrep support:
|
|
|
|
LIGHTGREP_ENABLE=yes ./bulk_extractor.SlackBuild
|
|
|
|
NOTE:
|
|
When running bulk_extractor with lightgrep, use
|
|
"-x find -e lightgrep -F findlist.txt" in addition to regular options.
|
|
|
|
If you want to use the java based GUI (BEViewer), you will also need to have
|
|
java installed. This has been tested with JDK.
|