FileSystem Investigator

Forensic Browser

Introduction

  1. What is FileSystem Investigator?

    FileSystem Investigator is a platform independent file system viewer and data extraction tool. It allows the user to:

    • View the contents of the target file system in a forensicly safe manner, bypassing the normal operating system mechanisms.
    • Extract files and whole directory trees of files from the source filesystem.

    Since it is written in platform-neutral Java, it can be used to examine filesystems outside their native environment. For example, it can be used to view a Linux filesystem while running under Windows.

  2. Supported Filesystems

    FileSystem Investigator is designed to be able to handle many different file systems.

    Currently ReiserFS version 3 and the Second Extended Filesystem (EXT2/EXT3) are supported.

  3. How it works

    FileSystem Investigator directly accesses the source disk and processes the data using it own built in filesystem drivers. This ensures that it is safe to use FileSystem Investigator for forensic investigations. FileSystem Investigator will never write to the source media thus important timestamps are preserved. FileSystem Investigator can also read disk-image files such as those created by dd. Files and whole directory structures can be extracted easily from the source drive and stored for further use or analysis. Due to limitations imposed by Java, special files such as device nodes, pipes, sockets and links, cannot be extracted.

  4. To do

    • Add support for EXT2/3, FAT12/16/32, NTFS
    • Add utilities for generating MD5 hashes.

    Contributions and suggestions are welcome.

  5. Sponsorship and customizations

    If your company has specialized needs for enhancements and/or is willing to sponsor development please contact us at