Forensic Analysis Tool for Btrfs File System.
Linux
Install the Sleuth Kit library --> Link
mkdir build
cd build
cmake ..
make
Raw image which contains a btrfs partition, or a partition device file with btrfs.
btrfrsc [-o offset1,offset2,offset3...] image
-o offset: Offset to the beginning of the partition (in sectors). May have multiple values if the pool is made up by multiple partitions(devices).
- Browse nodes derived from root tree and print information.
- Browse nodes in filesystem tree and print information.
- List all files in default filesystem tree.
- Explor files and subdirectories in default root directory.
- Switch to a subvolume or snapshot and exploere files within.
- Read a file from image and save to current directory.
There will be some stand alone programs built in Tools/ folder.
Most of them simulates functions of tools in The Sleuth's Kit.
Current list:
Tools/fsstat: Print information about the file system.
Tools/fls: List files and/or directories in a Btrfs partition image.
Tools/istat: Print information about an inode.
Tools/icat: Output the contents of file with provided inode number in Btrfs.
Tools/subls: List subvolumes and snapshots in a Btrfs image.
Reference of Btrfs structure can be found in btrfs Wiki.
Btrfs on-disk format: Link
This software uses MIT License.
The Sleuth Kit library is employed.
You can find the Sleuth Kit from sleuthkit/sleuthkit