What it is
A Python forensic tool for raw disk images, written for CSE 469 Computer and Network Forensics. Before an analyst works on an image, they need to know how the disk is partitioned and be able to prove the image hasn’t changed. This tool does both.
What I built
- Parsing of raw disk images, with automatic detection of the partition scheme: MBR or GPT.
- Extraction of the partition table entries.
- MD5, SHA-256 and SHA-512 digests of the image for evidence integrity checks.
- Output as structured JSON or as a human-readable report.
How it works
The tool reads the first sectors of the image to find out which scheme the disk uses, then decodes the matching partition table. The hash digests are computed over the image so the same values can be checked again later, which is how an examiner shows the evidence was not altered during analysis.