Advanced Forensics Format

From Just Solve the File Format Problem
Jump to: navigation, search
File Format
Name Advanced Forensics Format
Ontology
Extension(s) .aff
LoCFDD fdd000412(v1), fdd000413(v4)
PRONOM fmt/844
Wikidata ID Q27473543
Compression lossless
Magic Bytes 41 46 46
Developed By Simson L. Garfinkel and Basis Technology
Maintained By Phillip Hellewell (v3 only)

Advanced Forensics Format is an open-source format developed originally by Basis Technology and Simson L. Garfinkel, and is maintained by Phillip Hellewell[1], that:

  • Is designed to support precision forensics using compression, encryption, and segmentation, [2] As well as an alternative to current proprietary disk image formats.[3],
  • Offers two significant benefits. First, it is more flexible due to allowing extensive metadata to be stored with metadata. Second, AFF images consume less disk space than disk images in other formats (e.g., EnCase images).[4]
  • Is a library that is available for use in both Open Source and proprietary tools implementing AFF.

The last format that offers Open Source tooling is based on the version 3, and it is still presently maintained by Phillip Hellewell. Advanced Forensics Format version 4 (AFF4) was originally written in Python,[5] however the format appears to have become closed: papers documenting format are not publicly available,[6] despite the blog entry is titled as "Open Standard". The associated tool is also offered as trialware only.[7]

Software

Links

References

  1. AFFLIB version 3 - GitHub
  2. Advanced Forensic Format (AFF) - Cyber Triage
  3. Advanced Forensic Format: An open, extensible format for disk imaging - S. Garfinkel, D. Malan, K. Dubec, C. Stevens and C. Pham - Computer Science of Harvard University
  4. Advanced Forensic Format: An open, extensible format for disk imaging - S. Garfinkel, D. Malan, K. Dubec, C. Stevens and C. Pham - Computer Science of Harvard University
  5. AFF4 - The Advanced Forensics File Format - Internet Archive copy
  6. AFF4 & AFF4-L -- An Open Standard for Forensic Imaging - Magnet Forensics blog
  7. Updates in Magnet AXIOM 4.2 Include Support for AFF4, Skype Warrant Returns, and WhatsApp - Magnet Forensics blog
  8. Makefile.am lines 1-2 - AFFLIBv3 - GitHub
  9. Reference Documents - SleuthKitWiki
Personal tools
Namespaces

Variants
Actions
Navigation
Toolbox