bulk_extractor (64-bit) and BEViewer, developed by NPS, is an open‑source digital forensics toolkit designed for fast, scalable artifact extraction. bulk_extractor scans disk images, directories, and individual files at the raw byte level—without relying on file system metadata—to uncover features such as email addresses, URLs, phone numbers, credit card candidates, GPS coordinates, EXIF data, and more. It processes allocated, unallocated, and slack space, handles compressed data where possible, and produces plain‑text feature files and histograms suitable for triage, incident response, and e‑discovery. The 64‑bit build supports large datasets and multi‑core performance.
BEViewer complements bulk_extractor with a graphical interface for reviewing and managing results. It lets you open existing output directories or launch new scans, browse artifacts by type, search and filter findings, view surrounding context at specific byte offsets, apply stoplists to reduce noise, bookmark items of interest, and export reports.
Key features:
Note: Accessing physical disks may require administrative privileges. For best results, analyze forensic images or copies rather than live systems.
bulk_extractor (64-bit) and BEViewer is developed by NPS. The most popular version of this product among our users is 1.0.
You can check Super Email Extractor, Bulk Extractor, PC Icon Extractor and other related programs like Offline Email Extractor at the "download" section.
Comments