RE: [sleuthkit-users] Future of indexing in Autopsy and Sleuthkit

From: Brian Carrier (carrierat_private)
Date: Fri May 23 2003 - 07:19:49 PDT

  • Next message: Ed Carp: "FWD: Freely available UNIX email viewer, version 1.1, available"

    Paul Bakker <bakker@fox-it.com> said:
    
    > > >Issue 2:
    > > >Human readability of the files. A speedup in the indexed 
    > > >searching process and a redeuction of the size of the used 
    > >
    > > Not an issue in my opinion, in fact I agree with another post that 
    > > mentioned making the file layout open, someone here will 
    > > write a tool to 
    > > read it.
    > 
    > I will do both. I will document the file format and provide a tool to
    > convert it to human readable format.
    
    Perfect.  One of the goals of Autopsy is that all of its data and configuration files are 
    open so that any tool can utilize them and one is not restricted to Autopsy if (s)he 
    starts with it.  Maybe we can eventully do some Sleuth Kit Informer articles on the 
    format and design ...
    
    I would actually say to keep it in text for the initial versions so that people can verify 
    it, feel comfortable with it, and debug any issues.  It can be optimized later.
    
    thanks,
    brian
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Fri May 23 2003 - 08:44:42 PDT