Data extraction with bulk_extractor
The bulk_extractor
tool extracts several additional types of information that can be very useful in investigations. Although bulk_extractor
is quite capable of recovering and carving image, video, and document files, other data that can be carved and extracted by bulk_extractor
includes the following:
- Credit card numbers
- Email addresses
- URLs
- Online searches
- Social media profiles and information
For this example, we will work with a freely available evidence file named nps-2010-emails.E01
:
- The
nps-2010-emails.E01
file can be downloaded directly from the digital corpora website, which allows the use of forensic evidence images for forensic research purposes.
If not already downloaded, the file can be downloaded at https://digitalcorpora.s3.amazonaws.com/corpora/drives/nps-2010-emails/nps-2010-emails.E01.
- Once downloaded, open a new Terminal and change to the
Downloads
folder, just as we previously...