官术网_书友最值得收藏!

Getting started

All libraries used in this script are present in Python’s standard library. The os library, once again, can be used here to gather file metadata. One of the most helpful methods for gathering file metadata is the os.stat() function. It's important to note that the stat() call only provides information available with the current operating system and the filesystem of the mounted volume. Most forensic suites allow an examiner to mount a forensic image as a volume on a system and generally preserve the file attributes available to the stat call. In Chapter 8, Working with Forensic Evidence Containers Recipes, we will demonstrate how to open forensic acquisitions to directly extract file information.


To learn more about the os library, visit https://docs.python.org/3/library/os.html.
主站蜘蛛池模板: 鹤岗市| 浮梁县| 宝兴县| 宜黄县| 抚远县| 伽师县| 龙山县| 普兰店市| 本溪市| 巴马| 朝阳县| 石楼县| 宣城市| 富顺县| 神木县| 乐东| 库车县| 合作市| 斗六市| 黄山市| 舟山市| 沛县| 松江区| 阜新市| 健康| 北川| 新郑市| 嘉兴市| 丰顺县| 缙云县| 布尔津县| 尉氏县| 禹城市| 江达县| 洛宁县| 潜山县| 郑州市| 剑阁县| 武山县| 吕梁市| 尉犁县|