PyFlag Forensic and Log Analysis GUI

For:DFRWS 2008
Date: 2008-08-13
Authors: Dr. Michael Cohen
Data specialist
Australian Federal Police.

Network Forensics

PyFlag Design Goals

IO Sources

File Systems

VFS Internals

VFS Internals

The FileSystem Driver

Scanning the VFS

Architecture Overview

images/architecture.png

Network Forensics

Network Forensics

Packet handlers - DNS

Stream Handlers - HTTP

HTML Rendering

Web applications

Data presentation

Conclusions

References

The wiki can be found at
Volatility