Skip to main content

Crate forensicnomicon_core

Crate forensicnomicon_core 

Source
Expand description

§forensicnomicon-core

Stable engine layer of the ForensicNomicon. Houses the slow-moving pieces that downstream analyzers and readers depend on, kept apart from the fast-moving detection knowledge (the ~6.5k artifact descriptors) in the umbrella forensicnomicon crate:

  • report — the normalized cross-scheme DFIR finding vocabulary (Finding/Severity/Observation) that every *-forensic analyzer emits.
  • catalog — the descriptor types, the catalog::ForensicCatalog lookup engine and its query methods, container/record parsing profiles, and the in-core decoders. It carries no artifact data; the umbrella crate wires the assembled dataset into a global CATALOG via ForensicCatalog::new.
  • evidence::EvidenceStrength and volatility::VolatilityClass — the rating types stored on each descriptor (the catalog-querying helpers live in the umbrella crate, where the global catalog is wired).
  • Structural format constants readers depend on: decmpfs, filesystems, partition_schemes, partition_types.

These carry no dependency on the assembled detection catalog, so a knowledge change never forces a republish of crates that only need this engine. The umbrella forensicnomicon crate re-exports everything here, so existing imports such as forensicnomicon::report::Finding or forensicnomicon::catalog::CATALOG continue to resolve unchanged.

Re-exports§

pub use file_id::FileId;

Modules§

catalog
Forensic artifact catalog — engine and types.
decmpfs
HFS+/APFS transparent-compression (decmpfs) on-disk format constants.
evidence
Evidence strength / confidence model for forensic artifacts.
file_id
Filesystem-object identity — the stable name each filesystem gives one node.
filesystems
Filesystem superblock / boot-sector magic signatures.
partition_schemes
Disk partitioning-scheme detection from on-disk magic numbers.
partition_types
MBR partition type codes (the 1-byte type field in an MBR partition entry).
report
Normalized cross-scheme forensic report vocabulary — the superset model.
volatility
Artifact volatility model — RFC 3227 Order of Volatility encoded as data.
volume_encryption
Volume full-disk-encryption detection from a volume boot record.
volume_serial
Volume serial-number extraction from a volume boot record.