Using Bulk_extractor

Start Bulk Extractor by first typing bulk_extractor -h to display some commonly-used parameters and options:

Like Foremost and Scalpel, the syntax for using bulk_extractor is quite simple and requires that an output folder (-o) and the forensic image be specified.  For this exercise, as previously mentioned, we will be extracting data from the terry-work-usb-2009-12-11.E01 image and saving the output to a folder named bulk-output.

The syntax used is as follows:

bulk_extractor -o bulk_output terry-work-usb-2009-12-11.E01

Once completed, bulk_extractor indicates that all threads have finished and provides a summary of the ...

Get Digital Forensics with Kali Linux now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.