官术网_书友最值得收藏!

Getting started

All libraries used in this script are present in Python’s standard library. The os library, once again, can be used here to gather file metadata. One of the most helpful methods for gathering file metadata is the os.stat() function. It's important to note that the stat() call only provides information available with the current operating system and the filesystem of the mounted volume. Most forensic suites allow an examiner to mount a forensic image as a volume on a system and generally preserve the file attributes available to the stat call. In Chapter 8, Working with Forensic Evidence Containers Recipes, we will demonstrate how to open forensic acquisitions to directly extract file information.


To learn more about the os library, visit https://docs.python.org/3/library/os.html.
主站蜘蛛池模板: 健康| 怀宁县| 青海省| 水富县| 扎兰屯市| 柳江县| 和政县| 闸北区| 阿拉善右旗| 陇川县| 鄯善县| 安龙县| 通渭县| 双柏县| 礼泉县| 天水市| 修文县| 尼木县| 托克逊县| 米泉市| 九龙县| 铜山县| 翁牛特旗| 佳木斯市| 汽车| 苍梧县| 惠安县| 斗六市| 韶关市| 古交市| 连州市| 尚义县| 淅川县| 荃湾区| 双辽市| 汕尾市| 托克逊县| 兰溪市| 庄河市| 武川县| 广德县|