没有合适的资源?快使用搜索试试~ 我知道了~
Expert Witness Compression Format (EWF).pdf
需积分: 10 10 下载量 132 浏览量
2012-03-04
21:11:56
上传
评论 1
收藏 309KB PDF 举报
温馨提示
试读
56页
Expert Witness Compression Format (EWF).pdf
资源推荐
资源详情
资源评论
EWF specification
Expert Witness Compression Format specification
By Joachim Metz <jbmetz@users.sourceforge.net>
Summary
EWF is short for Expert Witness Compression Format, according to [ASR02]. It is a file type used
to store media images for forensic purposes. It is currently widely used in the field of computer
forensics in proprietary tooling like EnCase en FTK. The original specification of the format is
provided by ASRDATA, for the SMART application.
This document is intended as a working document for the EWF specification. Which should allow
existing Open Source forensic tooling to be able to process this file type.
page i
Document information
Author(s): Joachim Metz <jbmetz@users.sourceforge.net>
Abstract: This document contains the EWF file format specification.
Classification: Public
Keywords: Expert Witness Compression Format, EWF, EnCase file format, SMART
License
Copyright (c) 2006 - 2012 Joachim Metz <jbmetz@users.sourceforge.net>
Permission is granted to copy, distribute and/or modify this document under
the terms of the GNU Free Documentation License, Version 1.3 or any later
version published by the Free Software Foundation; with no Invariant Sections,
no Front-Cover Texts, and no Back-Cover Texts. A copy of the license is
included in the section entitled "GNU Free Documentation License".
Version
Version Author Date Comments
0.0.1 J.B. Metz March 7, 2006 Initial version
0.0.2 J.B. Metz March 12, 2006 Additional information.
0.0.3 J.B. Metz March 13, 2006 Additional information.
0.0.4 J.B. Metz March 15, 2006 Additional information.
0.0.5 J.B. Metz March 16, 2006 Additional information, regarding data and header2 section.
0.0.6 J.B. Metz March 17, 2006 Additional information, regarding data and header2 section.
0.0.7 J.B. Metz March 18, 2006 Additional information, regarding data, hash and header2
section.
0.0.8 J.B. Metz March 19, 2006 Additional information, regarding data section.
0.0.9 J.B. Metz March 20, 2006 Additional information, regarding chunk and compression,
offset array CRC and error2 section.
0.0.10 J.B. Metz March 22, 2006 Correction regarding EnCase 3 and compression MSB.
0.0.11 J.B. Metz March 25, 2006 Additions regarding EnCase 2.
0.0.12 J.B. Metz March 27, 2006 Small changes regarding unknown in volume and data.
Removed some spelling errors. Added the information
regarding when a chunk is compressed or not.
0.0.13 J.B. Metz April 1, 2006 Additions regarding EnCase 1.
0.0.14 J.B. Metz April 5, 2006 Additions regarding endian.
0.0.15 J.B. Metz April 10, 2006 Additions regarding disk section.
0.0.16 J.B. Metz April 15, 2006 Small adjustments regarding header section.
0.0.17 J.B. Metz April 21, 2006 Adjustments in error2 section information.
0.0.18 J.B. Metz May 1, 2006 Adjustments in hash section information.
0.0.19 J.B. Metz August 16, 2006 Fixed error in Encase 4 header2 layout information.
page ii
Version Author Date Comments
0.0.20 J.B. Metz August 17, 2006 Added information regarding SMART format generated by
FTK Imager. Corrected error about gzip compression in header
section.
0.0.21 J.B. Metz August 18, 2006 Added information regarding SMART format generated by
FTK Imager.
0.0.22 J.B. Metz August 22, 2006 Added information about segment file extension naming.
0.0.23 J.B. Metz September 8, 2006 Added information about EWF-L01 (LVF) format.
0.0.24 J.B. Metz September 22, 2006 Added information from EWF-L01 analysis.
0.0.25 J.B. Metz September 25, 2006 Changes after comments by Guy Voncken.
0.0.26 J.B. Metz October 12, 2006 Corrected error regarding EnCase 1 and SMART header
specification.
0.0.27 J.B. Metz October 19, 2006 Added theoretical maximum media size.
0.0.28 J.B. Metz October 22, 2006 Additional information about section start size in EnCase
(EWF-E01) next and done sections.
0.0.29 J.B. Metz November 27, 2006 Additional information about CRC algorithm.
0.0.30 J.B. Metz November 28, 2006 Fixed error regarding the location of the actual chunks in the
EnCase 1 format, which actually is the table sections and not
the sectors section.
0.0.31 J.B. Metz November 29, 2006 Additional information about the EnCase linen 5 (EWF-E01)
format.
0.0.32 J.B. Metz December 6, 2006 Additional information about GUID.
0.0.33 J.B. Metz December 16, 2006 Corrected error regarding header sections in EnCase 1 format.
0.0.34 J.B. Metz December 23, 2006 Added new information regarding the table section after
encountering a bug in FTK for EWF files with more than 16 *
1024 offset table entries.
0.0.35 J.B. Metz December 25, 2006 Corrected misinterpretation of original specifications,
regarding additional table sections.
0.0.36 J.B. Metz January 3, 2006 Added information about EnCase 6.
0.0.37 J.B. Metz January 7, 2006 Added information about linen 6.
0.0.38 J.B. Metz January 9, 2006 Added information about EnCase6/linen6 header.
Adjustments regarding media type and media flags.
0.0.39 J.B. Metz January 10, 2006 Added information about header values.
0.0.40 J.B. Metz January 20, 2006 Added information about EWF-X
0.0.41 J.B. Metz August 28, 2007 Added information about EnCase 6.7 >2Gb segment file
support.
0.0.42 J.B. Metz August 29, 2007 Added information about EnCase 6.7 >2Gb segment file
support and CD/DVD image session sector.
0.0.43 J.B. Metz September 5, 2007 Added information about EnCase 6.7 >2Gb segment file
support.
0.0.44 J.B. Metz September 15, 2007 Added page numbers.
0.0.45 J.B. Metz November 23, 2007 Added information about session section.
0.0.46 J.B. Metz March 10, 2008 Added information about session section.
0.0.47 J.B. Metz March 18, 2008 Added information about EnCase 6 >2GiB segment file format.
0.0.48 J.B. Metz June 1, 2008 Textual corrections.
0.0.49 J.B. Metz June 9, 2008 Added information about EnCase 6.11 winen file format.
0.0.50 J.B. Metz February9, 2009 Added information about EnCase 6.12 SHA1 hash support and
page iii
Version Author Date Comments
header values.
0.0.51 J.B. Metz April 17, 2009 Added information about EnCase software version header
value limitation.
0.0.52 J.B. Metz April 27, 2009
April 29, 2009
Added information about EnCase 6.13 Tableau write blocker
support.
0.0.53 J.B. Metz November 22,2009 Small changes.
0.0.54 J.B. Metz December 24, 2009
January 3, 2010
Added information about ltree section.
0.0.55 J.B. Metz January 10, 2010 Update for linen 6.12 and later.
0.0.56 J.B. Metz May 2, 2010 Corrected amount of into number of.
Email change
0.0.57 J.B. Metz September 2010 Minor changes.
0.0.58 J.B. Metz September 2010 Changed CRC to checksum.
0.0.59 J.B. Metz October 2010 Additional session section information with thanks to M. Nohr
Updated some tables to the newer format.
Minor changes.
0.0.60 J.B. Metz November 2010 Minor changes and improvements with thanks to G. Voncken.
Updated some tables to the newer format.
0.0.61 J.B. Metz December 2010 License version update
Additional information about optical discs.
Additional information about AD encryption.
0.0.62 J.B. Metz January 2011 Minor changes
0.0.63 J.B. Metz February 2011 Additional audio tracks information with thanks to M. Nohr
0.0.64 J.B. Metz May 2011 Changes to FTK imager format
0.0.65 J.B. Metz June 2011 Updated Logical File Evidence (LVF) format flag information
with thanks to B. Baron.
0.0.66 J.B. Metz September 2011 Updated Logical File Evidence (LVF) format flag information
with thanks to N. Harris
0.0.67 J.B. Metz December 2011 Small refinement in compressed vs uncompressed chunk data.
0.0.68 J.B. Metz February 2012 Added information about EnCase header values limitations
thanks to G. Voncken.
page iv
剩余55页未读,继续阅读
资源评论
你们都是好人
- 粉丝: 2
- 资源: 20
上传资源 快速赚钱
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
安全验证
文档复制为VIP权益,开通VIP直接复制
信息提交成功