I've gotten some great feedback and love from the forensics community about The Evidence Locker page. With that said I never settle and I'm always tweaking pieces to add more and do more for the masses. One of the reasons I made my Arc2Lite script was to dump file listings of archives so I can hunt for specific files and see if the are inside before I work on research. This obviously doesn't scale too well with having larger and larger extractions and more extractions to examine at that.
This is how a new page was born for The Evidence Locker. I'm calling it File Search for now. My idea is to take file listing exports of each applicable evidence item found on the main compendium and make it searchable. It utilizes parquet files to feed the table that looks very similar to the main page, allowing you to filter across sources, paths, file names, and even dates if you want.
On the main page you now have a new column for "Explore File List". If a file list is available for an evidence entry, you can click the magnifying glass icon to then kick you over to File Search with an appropriate filter on the evidence name.
It will take me some time (once again) to get these listings uploaded over time. My focus is on the easy ones like .zips/.tars and then eventually work my way through the E01 and other forensic container items.
Feedback is always welcomed, drop me a message!
Other page updates include:
- new tabbed page system
- fixes to sorting including showing arrows for ascending/descending
- fixes to size sorting (now will account for bytes sorting not just alphabetical)
- minor graphical updates
Check out File Search and the latest page updates now: https://theevidencelocker.github.io/file_search.html