官术网_书友最值得收藏!

Getting started

All libraries used in this script are present in Python’s standard library. The os library, once again, can be used here to gather file metadata. One of the most helpful methods for gathering file metadata is the os.stat() function. It's important to note that the stat() call only provides information available with the current operating system and the filesystem of the mounted volume. Most forensic suites allow an examiner to mount a forensic image as a volume on a system and generally preserve the file attributes available to the stat call. In Chapter 8, Working with Forensic Evidence Containers Recipes, we will demonstrate how to open forensic acquisitions to directly extract file information.


To learn more about the os library, visit https://docs.python.org/3/library/os.html.
主站蜘蛛池模板: 新和县| 甘德县| 穆棱市| 西贡区| 从化市| 元氏县| 安龙县| 昌乐县| 宣化县| 远安县| 昭苏县| 霍州市| 南阳市| 临夏县| 横峰县| 赫章县| 宁河县| 伊川县| 两当县| 永清县| 涿鹿县| 饶河县| 华坪县| 台北市| 乌什县| 海伦市| 大连市| 屯门区| 九寨沟县| 突泉县| 罗城| 金塔县| 庄浪县| 铜梁县| 怀集县| 新余市| 巨鹿县| 迭部县| 洪江市| 南平市| 忻州市|