ajnelson / sleuthkit

The Sleuth Kit (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
http://www.sleuthkit.org/sleuthkit/
1 stars 0 forks source link

fsstat volume label reporting needs new source #17

Open ajnelson opened 11 years ago

ajnelson commented 11 years ago

FAT processing pulls a volume label from the file system's superblock and root directory. XTAF's "Volume label" is the contents of the file "/name.txt" if it exists.