--
You received this message because you are subscribed to the Google Groups "bulk_extractor-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to bulk_extractor-u...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/bulk_extractor-users/8eeb74f9-4429-4a04-8290-9a882fd46897n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/bulk_extractor-users/493e5696-e17d-48ae-9873-5cd90fc1cce0n%40googlegroups.com.
Production quality. Version 1.x of bulk_extractor was a research tool that also found usefuleness in operational settings. Verison 2.x is a production tool. As such:
Research scanners have been removed from the master branch. They can still be researched by making them shared-libraries and using the bulk_extractor plug-in system.
Unit tests have been added.
Improved software development practices.
Continious integration is employed to validate each commit.
Development will take place in feature branches which will be added to the master branch only if CI tests pass.
Sensible defaults for production operation. With the undertanding that most users do not understand command-line options, bulk_extractor now runs with fewer command-line options.
Standards-compliant. Where possible, we are adopting C++14 features that are now widely available.
Experimental features have been removed. Experiments are now conducted with plugin-s.
BE2.0 will be released as a pure command-line tool. The user interface with the windows installer (and embedded CLI) will be released afterwards.
SQL will be turned on by default and the program will provide the user with instructions on how to use it. Performance will be analyzed to determine the fastest way to create the text feature files, the SQLite3 database, and the histograms.
Include other easy-to-output feature files by default, such as collect all email messages.
Integration with The Sleuth Kit for file enumeration
To view this discussion on the web visit https://groups.google.com/d/msgid/bulk_extractor-users/CAMDiSGQzk-mTVF79bEXgqgrZA30BiyqGfLZ2fXW45ovkfoR6%3Dg%40mail.gmail.com.
Scenario: Win Server 2019 using bulk_extractor V 1.6.0; Ubuntu
20.04 using bulk_extractor V Beta 2.0.0. Image is Averatech IDF
.dd 80 GB total size
No file level comparison yet due to time constraints
AveratechIDF Win server 2019 V1.6.0. Same .dd 80 GB total size
No Folders.Files listed not 0 bytes
Files (10):
domain.txt 2.9 KB
domain_histogram.txt 348 Bytes
elf.txt 630.4 KB
Report.xml 15 KB
rfc822.txt 552 Bytes
url.txt 6.3 KB
url_histogram.txt 1.1 KB
url_services.txt 345 Bytes
windirs.txt 5.8 KB
winpe.txt 55.1 KB
Averatec Ubuntu 20.04 Beta 2.0.0
No Folders or Files listed not 0 bytes
Folders (2): winpe_carved/000 with 10 files (DOS/Windows
executable (application- n/x-ms-dos-executable)
Program (application/octet-stream)
Files (11):
domain.txt 2.9 KB
domain_histogram.txt 336 Bytes
elf.txt 632.1 KB
report.xml 17.3 KB
rfc822.txt 542 Bytes
url.txt 6.3 KB
url_histogram.txt 1.1 KB
url_services.txt 354 Bytes
windirs.txt 5.8 KB
winpe.txt 55.1 KB
winpe_carved.txt 2.7 KB
===============================================
To view this discussion on the web visit https://groups.google.com/d/msgid/bulk_extractor-users/7514441e-275a-4438-8b6f-3ba64c1f8dc3n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/bulk_extractor-users/82d772b3-8e82-30cc-217f-368f1dc439b7%40gmail.com.