Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Example: e01-forensic

Inputs

  • examples/inputs/e01-forensic-samples/README.md
  • examples/inputs/e01-forensic-samples/sample.E01

Profile

# E01 Forensic Image Example Profile
# Demonstrates analysis of E01 (Expert Witness Format / EnCase) forensic disk images

decode = ["base64"]

max-file-size = 104857600  # 100 MiB

tag = "e01-forensic"

# Patterns to match in E01 images and extracted partitions
[[patterns]]
  name = "E01 Signature"
  pattern = "45:56:46:09:0D:0A:FF:00"  # "EVF" signature
  type = "bytes"

[[patterns]]
  name = "AWS Access Key"
  pattern = "AKIA[0-9A-Z]{16}"
  type = "regex"

[[patterns]]
  name = "SSH Private Key"
  pattern = "-----BEGIN.*PRIVATE KEY-----"
  type = "regex"

[[patterns]]
  name = "Password in Config"
  pattern = "password\\s*=\\s*['\"]?[^'\"\\s]+"
  type = "regex"

[[patterns]]
  name = "MBR Boot Signature"
  pattern = "55:AA"
  type = "bytes"

[[patterns]]
  name = "GPT Signature"
  pattern = "45:46:49:20:50:41:52:54"  # "EFI PART"
  type = "bytes"

[[patterns]]
  name = "NTFS Signature"
  pattern = "4E:54:46:53"  # "NTFS"
  type = "bytes"

[[patterns]]
  name = "Email Address"
  pattern = "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\\.[a-zA-Z]{2,}"
  type = "regex"

Report outputs

Triage report (converted from triage_report.json)

total_files4
critical_count0
high_count0
medium_count0
low_count0
minimal_count4
must_investigate_count0
all_scoresNone
generated_at2026-01-31T11:16:10.476841061+00:00

top_scores

characteristics_scorefile_typefile_type_scoremust_investigatepathpattern_count_scorepattern_matchespattern_severity_scorereasonsrisk_levelscoresha256
0Other0False/sample.E01535["3 suspicious patterns detected"]Minimal1016b7e321137f3719320a3d844da38923eae1bc9f2134a10c8c56bc3682985c43
0Other0False/README.md000[]Minimal070a741fdc8fd57be0dbe105b6d92199126b9440343d201de42a5d65111e3025a
0Other0False/sample.E01/sample.E01:e01:metadata000[]Minimal09a46a57c78f9996e1549d33f1f1a02ea01639b871abab3b6e203b2c73c5dba99
0Other0False/sample.E01/sample.E01:e01:sections000[]Minimal0859291139098c14d13d8bce18c2661100e6515bda7d384ca4b03f2ef67b0e2f2

CSV outputs

errors.csv

Empty CSV

files.csv

pathfile_namesha256file_createdfile_modifiedfile_accessedmime_types_from_file_extensionis_symbolic_linkis_extracted_fileis_decoded_fileis_deobfuscated_filetag
/README.mdREADME.md70a741fdc8fd57be0dbe105b6d92199126b9440343d201de42a5d65111e3025a2026-01-31T10:59:09.276752167Z2026-01-31T10:59:09.276752167Z2026-01-31T11:13:54.14750985Z["application/x-genesis-rom"]0000
/sample.E01/sample.E01:e01:metadatasample.E01:e01:metadata9a46a57c78f9996e1549d33f1f1a02ea01639b871abab3b6e203b2c73c5dba99[]0100
/sample.E01/sample.E01:e01:sectionssample.E01:e01:sections859291139098c14d13d8bce18c2661100e6515bda7d384ca4b03f2ef67b0e2f2[]0100
/sample.E01sample.E0116b7e321137f3719320a3d844da38923eae1bc9f2134a10c8c56bc3682985c432026-01-31T10:59:09.276752167Z2026-01-31T10:59:09.276752167Z2026-01-31T11:13:54.14750985Z[]0000

pattern_matches.csv

idsha256pattern_namematch_typematchlocationlength
116b7e321137f3719320a3d844da38923eae1bc9f2134a10c8c56bc3682985c43E01 SignaturebytesEVF �08
216b7e321137f3719320a3d844da38923eae1bc9f2134a10c8c56bc3682985c43Password in Configregexpassword=secret1232:869274
316b7e321137f3719320a3d844da38923eae1bc9f2134a10c8c56bc3682985c43Email Addressregextest@example.com2:59716

signature_matches.csv

Empty CSV

unique_files.csv

sha256sha1md5file_sizemime_type_for_contentshannon_entropy
70a741fdc8fd57be0dbe105b6d92199126b9440343d201de42a5d65111e3025aed81dba87cf0c7d8422c123406673185cddbe5055a9f9a9818d43cec1c6eed7af64328db2220text/plain4.94692176785771
9a46a57c78f9996e1549d33f1f1a02ea01639b871abab3b6e203b2c73c5dba998406cb1cd0ef3aa12868db8513ebaea6aa9a884f9aa1d45dc0ae3ed7edcf024010bd6334830text/plain4.95453188643216
859291139098c14d13d8bce18c2661100e6515bda7d384ca4b03f2ef67b0e2f2ce7b2ec567e74c335f98d6d8d490e39e343821447d74182dbff1c2ef700f49190df3f85f294text/plain4.88598232057513
16b7e321137f3719320a3d844da38923eae1bc9f2134a10c8c56bc3682985c43996863509a9c64701c8d2a28fe5193c45ab60560484246f9115e0b0f3039c07aacba8c071147application/octet-stream0.449226489277724