Bulk-extractor, a tool for batch extraction of information
Bulk-extractor, a tool for batch extraction of information
In digital forensics, we usually have to face huge amounts of data, such as hundreds of GB or even TB-level data. It is a long, boring and tedious process to extract valuable data from these massive data. Kali Linux provides a batch data extraction tool bulk-extractor. The tool is written in C++ language and can automatically extract all kinds of data from the backup image file, such as phone number, credit card number, e-mail address, EXIF, GPS, Prefetch and so on. In order to facilitate analysis, the tool will also analyze the extracted information and the frequency of statistical information. Each information collection and extraction function of the tool is implemented in the form of plug-ins. In this way, penetration testers can select the corresponding plug-ins according to the project, thus completing the analysis work more quickly.