官术网_书友最值得收藏!

Getting started

All libraries used in this script are present in Python’s standard library. The os library, once again, can be used here to gather file metadata. One of the most helpful methods for gathering file metadata is the os.stat() function. It's important to note that the stat() call only provides information available with the current operating system and the filesystem of the mounted volume. Most forensic suites allow an examiner to mount a forensic image as a volume on a system and generally preserve the file attributes available to the stat call. In Chapter 8, Working with Forensic Evidence Containers Recipes, we will demonstrate how to open forensic acquisitions to directly extract file information.


To learn more about the os library, visit https://docs.python.org/3/library/os.html.
主站蜘蛛池模板: 云南省| 怀来县| 内丘县| 庐江县| 化德县| 雅安市| 山东省| 衡阳县| 德庆县| 张北县| 六枝特区| 鄂温| 阿拉善盟| 海兴县| 河间市| 康乐县| 迁西县| 台东市| 龙海市| 葵青区| 汉中市| 甘洛县| 肥东县| 岳普湖县| 内江市| 盘山县| 镇远县| 衢州市| 塘沽区| 银川市| 铁岭市| 宁城县| 安福县| 新建县| 鄂温| 云阳县| 新乐市| 云梦县| 溧阳市| 永州市| 朝阳市|