diff options
Diffstat (limited to 'system/bulk_extractor/README')
-rw-r--r-- | system/bulk_extractor/README | 36 |
1 files changed, 13 insertions, 23 deletions
diff --git a/system/bulk_extractor/README b/system/bulk_extractor/README index 3679062b4b..37375ce4d8 100644 --- a/system/bulk_extractor/README +++ b/system/bulk_extractor/README @@ -1,23 +1,13 @@ -bulk_extractor is a C++ program that scans a disk image, a file, or a directory -of files and extracts useful information without parsing the file system or -file system structures. The results are stored in feature files that can be -easily inspected, parsed, or processed with automated tools. bulk_extractor -also creates histograms of features that it finds, as features that are more -common tend to be more important. - -bulk_extractor is distinguished from other forensic tools by its speed and -thoroughness. - -Optional dependancies include libewf (recognized if installed), afflib -(recognized if installed), and liblightgrep. - -To add optional liblightgrep support: - - LIGHTGREP_ENABLE=yes ./bulk_extractor.SlackBuild - -NOTE: - When running bulk_extractor with lightgrep, use - "-x find -e lightgrep -F findlist.txt" in addition to regular options. - -If you want to use the java based GUI (BEViewer), you will also need to have -java installed. This has been tested with JDK. +bulk_extractor is a C++ program that scans a disk image, a file, or +a directory of files and extracts useful information without parsing +the file system or file system structures. The results are stored in +feature files that can be easily inspected, parsed, or processed with +automated tools. bulk_extractor also creates histograms of features +that it finds, as features that are more common tend to be more +important. + +bulk_extractor is distinguished from other forensic tools by its speed +and thoroughness. + +Optional dependencies include libewf (recognized if installed) and +afflib (recognized if installed). |