simsong / bulk_extractor

This is the development tree. Production downloads are at:
https://github.com/simsong/bulk_extractor/releases
Other
1.08k stars 185 forks source link

update hiberfile (XPRESS) and add test vectors #253

Open simsong opened 2 years ago

simsong commented 2 years ago

After spending 20-30 hours investigating, I'm disabling the scan_hiberfile scanner by default because I'm not convinced that it's actually doing anything. I've looked at feature files that find features with HIBERFILE in the forensic path and the same features appear in the uncompressed text.

XPRESS has evolved in the decade since we incorporated the old pyexpress code from pyflag and I do not have a current version of it. However, I do have references to new code implementations. I will incorporate them if I can get some test vectors.

References:

simsong commented 2 years ago

@jonstewart - you mentioned that you might have a source for a test vector here?