Stars
acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container.
A Dissect module implementing a parser for the NTFS file system, used by the Windows operating system.
The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy access to various data sources inside disk images or file collecti…