dc3dd - Enhanced version of dd that includes features useful for forensics
|License:||GPLv2+ and GPLv3+|
dc3dd is a patched version of GNU dd to include a number of features useful for computer forensics. Many of these features were inspired by dcfldd, but were rewritten for dc3dd. * Pattern writes. The program can write a single hexadecimal value or a text string to the output device for wiping purposes. * Piecewise and overall hashing with multiple algorithms and variable size windows. Supports MD5, SHA-1, SHA-256, and SHA-512. Hashes can be computed before or after conversions are made. * Progress meter with automatic input/output file size probing * Combined log for hashes and errors * Error grouping. Produces one error message for identical sequential errors * Verify mode. Able to repeat any transformations done to the input file and compare it to an output. * Ability to split the output into chunks with numerical or alphabetic extensions
|dc3dd-7.2.641-1.el5.x86_64 [130 KiB]||
by Richard Cordovano (2014-06-16):
* Release 7.2.164-1 * Log output may be sent to multiple job logs and hash logs. Simply specify log=LOG and/or hlog=LOG more than once. * Verification of an image restored to a device larger than the image is now supported. Specify hof=DEVICE to hash only the bytes dc3dd writes to the device. Specify fhod=DEVICE to hash both the bytes dc3dd writes to the device and all the bytes that follow, up to the end of the device. * Specifying hof=DEVICE will now default to phod=DEVICE behavior (hash only the bytes output by dc3dd, not the full device).