sleuthkit / sleuthkit

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
http://www.sleuthkit.org/sleuthkit/
2.52k stars 593 forks source link

Where is the pool layer documentation? #2748

Open joachimmetz opened 1 year ago

joachimmetz commented 1 year ago

Where is the TSK pool layer documented?

http://wiki.sleuthkit.org/index.php?title=TSK_Tool_Overview does not mention the concept of pools

A third party paper seems to mention some details https://www.researchgate.net/publication/318925723_Extending_The_Sleuth_Kit_and_its_underlying_model_for_pooled_storage_file_system_forensic_analysis

joachimmetz commented 1 year ago

Questions to be answered: