Notifications
Clear all

Hfs+ Journal Parser

8 Posts
5 Users
0 Reactions
1,529 Views
pr3cur50r
(@pr3cur50r)
Eminent Member
Joined: 15 years ago
Posts: 28
Topic starter  

Hello, I have been having some issues with AHJP and Kazamia's EnScript for parsing hfs+ which the developers are kindly looking into at the moment but in the mean time I thought it may be worth while asking if anyone in the forum is aware of any other open source/paid for alternatives to these tools? Thanks in advance!


   
Quote
 lars
(@lars)
Eminent Member
Joined: 17 years ago
Posts: 31
 

BlackLight - https://www.blackbagtech.com/software-products/blacklight.html


   
ReplyQuote
pr3cur50r
(@pr3cur50r)
Eminent Member
Joined: 15 years ago
Posts: 28
Topic starter  

Thanks for your suggestion lars, are you aware of any other open source alternatives?
Kind Regards


   
ReplyQuote
 lars
(@lars)
Eminent Member
Joined: 17 years ago
Posts: 31
 

No - I'm not aware of any open source tools that can currently do this.


   
ReplyQuote
pr3cur50r
(@pr3cur50r)
Eminent Member
Joined: 15 years ago
Posts: 28
Topic starter  

Thanks anyway lars, much appreciated.


   
ReplyQuote
citizen
(@citizen)
Eminent Member
Joined: 10 years ago
Posts: 38
 

https://digital-forensics.sans.org/media/FOR518-Reference-Sheet.pdf
https://support.apple.com/en-ph/HT201711
http//ntfs.com/hfs.htm

Maybe start with a tiny image with a text file and a folder. (do things (Structured/documented things) -> capture -> analyze)

Hope this helps you along.


   
ReplyQuote
mokosiy
(@mokosiy)
Trusted Member
Joined: 13 years ago
Posts: 55
 

It looks like Dave Cowen offers HFS journal parser for free https://www.gettriforce.com/product/hfs-journal-parser/


   
ReplyQuote
(@thefuf)
Reputable Member
Joined: 17 years ago
Posts: 262
 

https://github.com/bored-engineer/iOS-DataProtection/tree/master/python_scripts/hfs


   
ReplyQuote
Share: