Open Computer Forensics Architecture 2.0.6pl2 (Default branch) |
|
|
The Open Computer Forensics Architecture (OCFA) is
a modular computer forensics framework to automate
the digital forensic process, to speed up the
investigation and give tactical investigators
direct access to the seized data through an easy
to use search and browse interface. The
architecture forms an environment where existing
forensic tools and libraries can be easily plugged
into the architecture and can thus be made part of
the recursive extraction of data and metadata from
digital evidence. It aims to be highly modular,
robust, fault tolerant, recursive, and scalable in
order to be usable in large investigations that
spawn numerous terabytes of evidence data and
cover hundreds of evidence items.
License: GNU General Public License (GPL)
Changes:
This release adds a workaround to make sure the
indexer does not get
and/or process large files (Clucene expands its
memory usage to about
four times the size of the largest file it is
given to index), makes
the configure script more strict and more complete
(especially with
respect to 32/64 bit Linux), adds some
SLES9-specific patches, and adds
workarounds for bugs in 7zip and objdump.
|