Bulk Extractor
Bulk Extractor (bulk_extractor) is a free, open-source digital forensics tool created by Simson Garfinkel. It scans disk images, files and directories and pulls out useful evidence such as email addresses, URLs, phone numbers, credit card numbers, GPS data and EXIF metadata, without needing to parse the file system.
Because it ignores file system structure, Bulk Extractor can find data in deleted files, unallocated space, damaged drives and compressed archives. It is multi-threaded for speed, writes its results to feature files and histograms, and can build custom wordlists from a drive for password cracking. It comes preinstalled on Kali Linux and SIFT, and BEViewer offers a graphical interface.
On Cracking Station you’ll find Bulk Extractor tutorials, command examples and comparisons with other forensic and data carving tools such as Autopsy, PhotoRec, Scalpel and X-Ways, written for CHFI candidates and digital forensics learners.
-
All Posts
The 7 best data carving tools to recover lost and deleted data files
The 7 best data carving tools to recover lost and…
Read More »