Advanced Forensics Format

From Just Solve the File Format Problem
(Difference between revisions)
Jump to: navigation, search
(Added compression type, appears to be lossless when looking at AFFLib v3 which includes LZMA SDK.)
(Software: Add The Sleuth Kit and Autopsy)
 
Line 22: Line 22:
 
* [https://www.exterro.com/digital-forensics-software/ftk-imager Exterro FTK Imager] (trialware, mostly Windows-only) - supports the AFF4 format and execution on portable drives (as of FTK Imager 4.7)
 
* [https://www.exterro.com/digital-forensics-software/ftk-imager Exterro FTK Imager] (trialware, mostly Windows-only) - supports the AFF4 format and execution on portable drives (as of FTK Imager 4.7)
 
* [https://www.magnetforensics.com/blog/updates-in-magnet-axiom-4-2-include-support-for-aff4-skype-warrant-returns-and-whatsapp/ Magnet AXIOM 4.2 and Magnet AXIOM Cyber 4.2 download link] (trialware) - Mentioned as blog entry, the software is available only at customer portal that is linked in this URL.
 
* [https://www.magnetforensics.com/blog/updates-in-magnet-axiom-4-2-include-support-for-aff4-skype-warrant-returns-and-whatsapp/ Magnet AXIOM 4.2 and Magnet AXIOM Cyber 4.2 download link] (trialware) - Mentioned as blog entry, the software is available only at customer portal that is linked in this URL.
 +
* [[The Sleuth Kit and Autopsy]] - supports AFF image format.<ref>[http://wiki.sleuthkit.org/index.php?title=Reference_Documents Reference Documents - SleuthKitWiki]</ref>
  
 
== Links ==
 
== Links ==

Latest revision as of 04:46, 16 August 2025

File Format
Name Advanced Forensics Format
Ontology
Extension(s) .aff
LoCFDD fdd000412(v1), fdd000413(v4)
PRONOM fmt/844
Wikidata ID Q27473543
Compression lossless
Magic Bytes 41 46 46
Developed By Simson L. Garfinkel and Basis Technology
Maintained By Phillip Hellewell (v3 only)

Advanced Forensics Format is an open-source format developed originally by Basis Technology and Simson L. Garfinkel, and is maintained by Phillip Hellewell[1], that:

  • Is designed to support precision forensics using compression, encryption, and segmentation, [2] As well as an alternative to current proprietary disk image formats.[3],
  • Offers two significant benefits. First, it is more flexible due to allowing extensive metadata to be stored with metadata. Second, AFF images consume less disk space than disk images in other formats (e.g., EnCase images).[4]
  • Is a library that is available for use in both Open Source and proprietary tools implementing AFF.

The last format that offers Open Source tooling is based on the version 3, and it is still presently maintained by Phillip Hellewell. Advanced Forensics Format version 4 (AFF4) was originally written in Python,[5] however the format appears to have become closed: papers documenting format are not publicly available,[6] despite the blog entry is titled as "Open Standard". The associated tool is also offered as trialware only.[7]

[edit] Software

[edit] Links

[edit] References

  1. AFFLIB version 3 - GitHub
  2. Advanced Forensic Format (AFF) - Cyber Triage
  3. Advanced Forensic Format: An open, extensible format for disk imaging - S. Garfinkel, D. Malan, K. Dubec, C. Stevens and C. Pham - Computer Science of Harvard University
  4. Advanced Forensic Format: An open, extensible format for disk imaging - S. Garfinkel, D. Malan, K. Dubec, C. Stevens and C. Pham - Computer Science of Harvard University
  5. AFF4 - The Advanced Forensics File Format - Internet Archive copy
  6. AFF4 & AFF4-L -- An Open Standard for Forensic Imaging - Magnet Forensics blog
  7. Updates in Magnet AXIOM 4.2 Include Support for AFF4, Skype Warrant Returns, and WhatsApp - Magnet Forensics blog
  8. Makefile.am lines 1-2 - AFFLIBv3 - GitHub
  9. Reference Documents - SleuthKitWiki
Personal tools
Namespaces

Variants
Actions
Navigation
Toolbox