google / turbinia

Automation and Scaling of Digital Forensics Tools
Apache License 2.0
750 stars 162 forks source link

Add EWF evidence type(s) #377

Closed aarontp closed 2 years ago

aarontp commented 5 years ago

We should add a new evidence type for EWF along with pre/post-processors that know how to create a loop device and mount them so that other Tasks besides Plaso can also process them.

joachimmetz commented 5 years ago

FYI EWF can be multiple evidence types: disk, memory, optical, logical

aarontp commented 5 years ago

Yeah, the intention here would be to support just the E01 disk format to start.

aarontp commented 2 years ago

Fixed by https://github.com/google/turbinia/pull/1112