Skip to content

Read Ex01, SMART, AFF and AFD acquisitions with -t raw, and refuse L01 - #324

Merged
abrignoni merged 1 commit into
mainfrom
feat/acquisition-formats
Sep 27, 2026
Merged

abrignoni merged 1 commit into
mainfrom
feat/acquisition-formats

Conversation

@abrignoni

Copy link
Copy Markdown
Owner

Reads more acquisition formats with -t raw, and refuses logical evidence.

  • Re-vendors qnxprobe 1.38 and ewfprobe 0.2.0. E01, SMART .s01, Ex01, AFF, and an AFD folder (from the folder or any .aff in it) are read in place. Before, an Ex01, AFF, AFD or L01 came back as one unrecognised volume and nothing was searched.
  • EnCase L01 is refused with a message saying it holds files, not a disk.
  • scripts/raw_image.py names the container in the run log. It stays byte-identical in the five cores, and the same change goes to the other four.
  • The GUI lists .s01, .Ex01 and .aff with the raw image types.
  • Tests: an AFF and an AFD of the NTFS fixture stage the same files as the raw image, and an L01 is refused.

🤖 Generated with Claude Code

Re-vendors qnxprobe 1.38 and ewfprobe 0.2.0. qnxprobe now hands every disk
image ewfprobe reads to it (E01, SMART .s01, Ex01, AFF, and an AFD folder from
the folder or any .aff in it) and refuses EnCase L01 logical evidence, which
holds files rather than a disk. Before, an Ex01, AFF, AFD or L01 was read as raw
bytes and came back as one volume the reader did not recognise, so no artifact
found anything.

scripts/raw_image.py, byte-identical across the five cores, names the container
in the run log through qnxprobe.describe_acquisition. The GUI lists .s01, .Ex01
and .aff with the raw image types. The seeker tests build an AFF and an AFD of
the NTFS fixture and require the same files as the raw image, and require an L01
to be refused.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@abrignoni
abrignoni merged commit b93ebfe into main Sep 27, 2026
9 checks passed
@abrignoni
abrignoni deleted the feat/acquisition-formats branch September 27, 2026 06:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant