Bulk Extractor and E0 Files

192 views
Skip to first unread message

Yaniv

unread,
Jun 29, 2011, 4:30:53 PM6/29/11
to aff-discuss
Does BE support reading segmented E0 files?

the help file says "Support for E01 files compiled in", not quite sure
what this means?

Simson Garfinkel

unread,
Jun 30, 2011, 9:25:31 AM6/30/11
to aff-d...@googlegroups.com

It means you can read them .

sent from my phone. please excuse brevity and spelling errors.

> --
> You received this message because you are subscribed to the Google Groups "aff-discuss" group.
> To post to this group, send email to aff-d...@googlegroups.com.
> To unsubscribe from this group, send email to aff-discuss...@googlegroups.com.
> For more options, visit this group at http://groups.google.com/group/aff-discuss?hl=en.
>

Yaniv

unread,
Jun 30, 2011, 10:28:50 AM6/30/11
to aff-d...@googlegroups.com
Ok... how does one go about reading them? 

Dewhirst, Rob

unread,
Jun 30, 2011, 10:29:27 AM6/30/11
to aff-d...@googlegroups.com

I am guessing this means you have the libewf installed when you built
BE. Since that supports split E01 you should have no problem?

Just a guess.

It also takes about 10 seconds to test...

Simson Garfinkel

unread,
Jun 30, 2011, 1:57:18 PM6/30/11
to aff-d...@googlegroups.com
bulk_extractor -o outdir filename.E01
 
(it automatically finds the other files.)
 
What happened when you tried this yourself?

Dewhirst, Rob

unread,
Jun 30, 2011, 2:28:35 PM6/30/11
to aff-d...@googlegroups.com
On Thu, Jun 30, 2011 at 9:28 AM, Yaniv <yani...@gmail.com> wrote:
> Ok... how does one go about reading them?

reading them with bulk_extractor or just reading them in general?

bulk_extractor image.E01 -o ./outputdir

If you just want to read them there are many writeups about mounting
E01 files and they are not hard to find. If you are on windows the
free version FTKImager is probably the easiest.

SLG

unread,
Jun 30, 2011, 3:05:37 PM6/30/11
to aff-discuss
Please review the usage:

bulk_extractor -o outputdir image.E01

The image goes last.

On Jun 30, 2:28 pm, "Dewhirst, Rob" <robdewhi...@gmail.com> wrote:
Reply all
Reply to author
Forward
0 new messages