Main Page

From BitCurator
Jump to: navigation, search

The BitCurator Environment is a Ubuntu-derived Linux distribution geared towards the needs of archivists and librarians. It includes a suite of open source digital forensics and data analysis tools to help collecting institutions process born-digital materials. BitCurator supports positive digital preservation outcomes using software (see our Software page) and practices adopted from the digital forensics community.

  • Create forensic disk images: Disk images packaged with metadata about devices, file systems, and the creation process.
  • Analyze files and file systems: View details on file system contents from a wide variety of file systems.
  • Extract file system metadata: File system metadata is a critical link in the chain of custody and in records of provenance.
  • Identify and redact sensitive information: Locate private and sensitive information on digital media and prepare materials for public access.
  • Locate and remove duplicate files: Know what files to keep and what can be discarded.

Get BitCurator

File-2.png
BitCurator Virtual Machine (v1.6.10)

[Download Mirror] [MD5 checksum]

Disk-9.png
BitCurator Installation ISO (v1.6.10)

[Download Mirror] [MD5 checksum]

Documentation and Help

Book-2.png
Quickstart Guide Installing and using BitCurator.
User-8.png
BitCurator User Group Get support and discuss issues with the community.
Monitor.png
Screencasts and Video Tutorials Useful screencasts on our YouTube channel.

Future (Testing) Releases

Upcoming releases of the BitCurator environment will be based on Ubuntu 16.04LTS. Download the beta here to try out our latest test environment. Note! These environments may be missing some functionality! Use at your own risk!

File-2.png
BitCurator Virtual Machine (v1.7.2-Beta)

[Download Mirror] [MD5 checksum]

Disk-9.png
BitCurator Installation ISO (v1.7.2-Beta)

[Download Mirror] [MD5 checksum]

Virtual Machine Login

BitCurator ships with a default user. We suggest you change the password when working in production environments!

username: bcadmin

password: bcadmin

Support BitCurator

Ongoing development of the BitCurator environment depends on the support of BitCurator Consortium members. Find out more about becoming a member.

Acknowledgements

BitCurator is hosted at the School of Information and Library Science at the University of North Carolina, Chapel Hill. Grants from the Andrew W. Mellon Foundation supported BitCurator through September 2014. Project development was conducted in partnership with the Maryland Institute for Technology in the Humanities (MITH) from September 2010 to September 2014. BitCurator is currently managed by the BitCurator Consortium in association with the Educopia Institute.

Sils.png

Bcc-logo.png

Mellon.png

Visit our main site to see more information on current and former BitCurator team members and contributors.

License

Software in our Github repository is GNU GPLv3 licensed. This wiki and associated documentation are licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). All other software included in the BitCurator environment is distributed in accordance with original licenses.

Using BitCurator (By Task or Workflow)

  1. BitCurator in Preservation and Archiving Workflows
  2. Preparing Media
  3. Data Triage
  4. Using Digital Forensics Tools
  5. Building and Using Regular Expressions
  1. BitCurator in Preservation and Archiving Workflows
  2. Preparing Media. Connect physical media and analyze file system(s) and other contents.
  3. Data Triage. Clean, organize, and explore your data.
  4. Using Digital Forensics Tools. Generate reports and prepare data for preservation or access.
  5. Or, explore using these features on their own:

    1. Understanding types of information you might wish to scan for
    1. Descriptions and examples of Digital Forensics XML tags
  6. Building and Using Regular Expressions. Many forensics tools include support for search using regular expressions, a powerful mechanism that can help you match a range of patterns with a single search string.

Using BitCurator (By Tool or Script)

  1. Software produced by the BitCurator team
  2. Disk imaging
  3. Forensic analysis, hashing, and metadata generation
  4. Other utilities
  1. Software produced by the BitCurator team
    • BitCurator Reporting Tool: A GUI-driven (and optionally command-line) tool for running forensics tools in sequence to produce human- and machine-readable reports.
    • BitCurator Disk Image Access Tool: A GUI interface to browse raw and forensically-packaged disk images, export files and deleted items, and view disk image metadata.
    • BitCurator Mounter: A Qt GUI application to list currently attached devices along with technical details. Allows users to mount fixed and removable media according to the current mount policy.
    • BitCurator Read-Only AppIndicator: A Ubuntu AppIndicator allowing users to switch the system mount policy between "Read Only" and "Read/Write" for any attached media prior to mounting.
  2. Disk imaging
    • Guymager: Multi-threaded open-source forensic disk imaging tool.
    • dcfldd: A forensics-focused rewrite of dd.
    • dd: Create raw disk images and transfer data between devices.
    • ddrescue: A version of dd with additional options for data recovery.
    • ewfacquire: Acquire Expert Witness packaged disk images from devices on the command line.
    • cdrdao: A CD imaging tool.
  3. Forensic analysis, hashing, and metadata generation
    • bulk_extractor: A stream-based tool for disk image analysis.
    • bulk_extractor Viewer (BEViewer): The GUI front-end for bulk-extractor
    • DFXML tools: A set of C and Python programs to process Digital Forensics XML.
    • fiwalk: File system analysis and DFXML export.
    • The Sleuth Kit: A suite of forensics tools, utilities, and APIs.
    • libewf: Open-source support for the Expert Witness format.
    • AFFLIB: Open-source library for the Advanced Forensic Format.
    • pyExifToolGUI: A GUI front-end for Exiftool. Allows editing of image metadata.
    • sdhash: File similarity tool using similarity digests.
    • ssdeep: Fast hash generation.
  4. Other utilities
    • ClamAV / ClamTK: Virus scanning.
    • FSlint: Duplicate file identification and deletion.
    • HFS Utilities: Utilities providing access to legacy HFS file systems, such as HFS Explorer.
    • FITS: The File Information Tool Set.
    • readpst: A utility for reading and exporting the contents of PST files.
    • recoll: An indexing tool.
    • GTK Hash: A cryptographic hashing tool.
    • GHex: A hex viewer/editor
    • Nautilus scripts: Support for various interactions with files and file systems.
    • Safe Mount: Software write-blocking for digital media.

Additional Useful Information

  1. Guidance on building a lab
  2. Internationalization / Language Support
  1. Putting together labs for research, education, or production
  2. Working with materials in a range of languages


Retrieved from "http://wiki.bitcurator.net/index.php?title=Main_Page&oldid=1754"
Personal tools
Namespaces

Variants
Actions
About
Support
Tools