Start Bulk Extractor by first typing bulk_extractor -h to display some commonly-used parameters and options:
Like Foremost and Scalpel, the syntax for using bulk_extractor is quite simple and requires that an output folder (-o) and the forensic image be specified. For this exercise, as previously mentioned, we will be extracting data from the terry-work-usb-2009-12-11.E01 image and saving the output to a folder named bulk-output.
The syntax used is as follows:
bulk_extractor -o bulk_output terry-work-usb-2009-12-11.E01
Once completed, bulk_extractor indicates that all threads have finished and provides a summary of the ...