Forensicswiki.org has moved to this site, forensicswiki.xyz. For information, please join the Google Group forensicswiki-reborn

Bodyfile

From Forensics Wiki
Jump to navigation Jump to search

Bodyfile is an output format (as far as known) introduced by the SleuthKit.

The bodyfile is typically an intermediate file generated by fls or ils which are then provided as input to the mactime tool.

The bodyfile uses a delimiter-separated value format, with the pipe-character (|) as the delimiter.

Different version of the SleuthKit use different version of the bodyfile format.

The following fields are defined for SleuthKit 3.0 and later:

MD5|name|inode|mode_as_string|UID|GID|size|atime|mtime|ctime|crtime

Known issues:

External Links