Foregone
Author(s)
Joe Stewart
Latest Version
0.1
Description
Foregone is a forensic file recovery tool written in Perl. It was inspired by the Air Force Office of Special Investigations' forensic tool known as "Foremost", which uses defined headers and footers of certain file types to search a raw disk image and extract files with those characteristics. Foregone is a Perl implementation of the same technique with some added features:
- Only searches for headers starting on a block boundary, for a speed increase
- Uses compression to reject interleaved blocks of dissimilar files
Foregone should not be considered an investigative-level forensic tool, but merely a utility that may help you recover files from a corrupted filesystem.
License Agreement
Please note that SecureWorks cannot provide support for these tools, but feedback is appreciated.
