Index _ | A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z _ __add__() (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __and__() (dissect.cstruct.FlagInstance method) (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.flag.FlagInstance method) (dissect.cstruct.types.FlagInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __bool__() (dissect.cstruct.FlagInstance method) (dissect.cstruct.types.flag.FlagInstance method) (dissect.cstruct.types.FlagInstance method) __bytes__() (dissect.cstruct.Instance method) (dissect.cstruct.types.Instance method) (dissect.cstruct.types.instance.Instance method) __call__() (dissect.cstruct.BaseType method) (dissect.cstruct.Enum method) (dissect.cstruct.Flag method) (dissect.cstruct.types.base.BaseType method) (dissect.cstruct.types.BaseType method) (dissect.cstruct.types.Enum method) (dissect.cstruct.types.enum.Enum method) (dissect.cstruct.types.Flag method) (dissect.cstruct.types.flag.Flag method) (dissect.ntfs.Mft method) (dissect.ntfs.mft.Mft method) (dissect.target.helpers.lazy.FailedImport method) (dissect.target.helpers.lazy.LazyAttr method) (dissect.target.helpers.record.ExtendableRecordDescriptor method) (dissect.target.helpers.targetd.CommandProxy method) (dissect.target.plugin.Plugin method) (dissect.target.plugins.general.config.ConfigurationTreePlugin method) (flow.record.base.DynamicFieldtypeModule method) (flow.record.base.RecordDescriptor method) (flow.record.RecordDescriptor method) (flow.record.utils.EventHandler method) __contains__() (dissect.cstruct.Enum method) (dissect.cstruct.Instance method) (dissect.cstruct.parser.TokenConsumer method) (dissect.cstruct.types.Enum method) (dissect.cstruct.types.enum.Enum method) (dissect.cstruct.types.Instance method) (dissect.cstruct.types.instance.Instance method) (dissect.ntfs.util.AttributeMap method) (dissect.sql.sqlite3.WALCheckpoint method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.helpers.configutil.ConfigurationParser method) (dissect.target.helpers.regutil.VirtualKey method) (flow.record.fieldtypes.net.ip.ipnetwork method) (flow.record.fieldtypes.net.ipnetwork method) (flow.record.fieldtypes.net.ipv4.subnet method) (flow.record.fieldtypes.net.ipv4.SubnetList method) (flow.record.selector.CompiledSelector method) (flow.record.selector.NoneObject method) (flow.record.selector.Selector method) (flow.record.selector.TypeMatcherInstance method) __del__() (dissect.target.loaders.smb.SmbRegistry method) (dissect.target.loaders.targetd.TargetdLoader method) (flow.record.adapter.AbstractWriter method) (flow.record.stream.RecordStreamWriter method) __dir__() (dissect.target.Target method) (dissect.target.target.Target method) __doc__ (dissect.target.helpers.lazy.LazyAttr property) __enter__() (acquire.acquire.collector.Collector method) (dissect.target.helpers.configutil.ScopeManager method) (flow.record.adapter.AbstractReader method) (flow.record.adapter.AbstractWriter method) __eq__() (dissect.cstruct.EnumInstance method) (dissect.cstruct.parser.Token method) (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.enum.EnumInstance method) (dissect.cstruct.types.EnumInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) (dissect.eventlog.bxml.Token method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.sql.sqlite3.Column method) (dissect.target.helpers.fsutil.stat_result method) (dissect.volume.vss.BlockDescriptor method) (flow.record.base.Record method) (flow.record.base.RecordDescriptor method) (flow.record.fieldtypes.net.ip.ipaddress method) (flow.record.fieldtypes.net.ip.ipnetwork method) (flow.record.fieldtypes.net.ipaddress method) (flow.record.fieldtypes.net.ipnetwork method) (flow.record.fieldtypes.net.ipv4.address method) (flow.record.fieldtypes.path method) (flow.record.Record method) (flow.record.RecordDescriptor method) (flow.record.selector.NoneObject method) (flow.record.selector.TypeMatcherInstance method) __exit__() (acquire.acquire.collector.Collector method) (dissect.target.helpers.configutil.ScopeManager method) (flow.record.adapter.AbstractReader method) (flow.record.adapter.AbstractWriter method) __findable__ (dissect.target.plugin.Plugin attribute) (dissect.target.plugins.apps.webserver.webserver.WebserverPlugin attribute) (dissect.target.plugins.general.example.ExamplePlugin attribute) (dissect.target.plugins.os.unix.packagemanager.PackageManagerPlugin attribute) __floordiv__() (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __format__() (flow.record.fieldtypes.bytes method) (flow.record.fieldtypes.net.ip.ipaddress method) (flow.record.fieldtypes.net.ipaddress method) (flow.record.fieldtypes.string method) __fstype__ (dissect.target.filesystem.Filesystem property) __getattr__() (dissect.cim.cim.Class method) (dissect.cim.cim.Instance method) (dissect.cim.classes.InstanceKey method) (dissect.cim.index.Key method) (dissect.cstruct.cstruct method) (dissect.cstruct.cstruct.cstruct method) (dissect.cstruct.Enum method) (dissect.cstruct.Instance method) (dissect.cstruct.parser.TokenCollection method) (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.Enum method) (dissect.cstruct.types.enum.Enum method) (dissect.cstruct.types.Instance method) (dissect.cstruct.types.instance.Instance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) (dissect.esedb.record.Record method) (dissect.esedb.tools.sru.Entry method) (dissect.etl.etl.Event method) (dissect.etl.headers.event.EventHeaderExtendedDataItem method) (dissect.evidence.ad1.AD1 method) (dissect.evidence.ad1.FileEntry method) (dissect.evidence.ad1.FileMeta method) (dissect.evidence.ad1.LogicalImage method) (dissect.hypervisor.disk.vmdk.SparseExtentHeader method) (dissect.ntfs.attr.Attribute method) (dissect.ntfs.Attribute method) (dissect.ntfs.usnjrnl.UsnRecord method) (dissect.ntfs.UsnRecord method) (dissect.ntfs.util.AttributeCollection method) (dissect.ntfs.util.AttributeMap method) (dissect.shellitem.lnk.lnk.LnkExtraData method) (dissect.shellitem.lnk.lnk.LnkInfo method) (dissect.shellitem.lnk.lnk.LnkStringData method) (dissect.sql.sqlite3.Row method) (dissect.target.filesystem.EntryList method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.helpers.lazy.FailedImport method) (dissect.target.helpers.lazy.LazyAttr method) (dissect.target.helpers.lazy.LazyImport method) (dissect.target.helpers.targetd.CommandProxy method) (dissect.target.plugins.os.unix.linux.fortios._os.ConfigNode method) (dissect.target.Target method) (dissect.target.target.Target method) (dissect.target.tools.shell.TargetCmd method) (dissect.util.plist.NSObject method) (flow.record.base.DynamicFieldtypeModule method) (flow.record.base.GroupedRecord method) (flow.record.GroupedRecord method) (flow.record.selector.TypeMatcher method) (flow.record.selector.TypeMatcherInstance method) (flow.record.selector.WrappedRecord method) __getattribute__() (dissect.eventlog.wevt_object.WevtObject method) (dissect.thumbcache.thumbcache_file.ThumbcacheFile method) (dissect.thumbcache.ThumbcacheFile method) __getitem__() (dissect.cim.classes.PropertyStates method) (dissect.cim.index.Key method) (dissect.cim.mappings.Mapping method) (dissect.cim.objects.TOC method) (dissect.cstruct.BaseType method) (dissect.cstruct.Enum method) (dissect.cstruct.Instance method) (dissect.cstruct.types.base.BaseType method) (dissect.cstruct.types.BaseType method) (dissect.cstruct.types.Enum method) (dissect.cstruct.types.enum.Enum method) (dissect.cstruct.types.Instance method) (dissect.cstruct.types.instance.Instance method) (dissect.esedb.record.Record method) (dissect.esedb.tools.impacket.RecordWrapper method) (dissect.esedb.tools.sru.Entry method) (dissect.executable.elf.elf.StringTable method) (dissect.executable.elf.elf.Table method) (dissect.executable.elf.StringTable method) (dissect.hypervisor.descriptor.hyperv.HyperVFile method) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry method) (dissect.hypervisor.disk.vhd.BlockAllocationTable method) (dissect.ntfs.util.AttributeMap method) (dissect.ole.ole.Chain method) (dissect.sql.sqlite3.Row method) (dissect.sql.sqlite3.WALCheckpoint method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.helpers.configutil.ConfigurationParser method) (dissect.target.helpers.fsutil.stat_result method) (dissect.target.helpers.regutil.HiveCollection method) (dissect.target.helpers.regutil.KeyCollection method) (dissect.target.target.Collection method) (dissect.thumbcache.thumbcache_file.ThumbcacheFile method) (dissect.thumbcache.ThumbcacheFile method) (dissect.util.plist.NSDictionary method) (dissect.util.plist.NSKeyedArchiver method) (dissect.util.plist.NSObject method) (dissect.volume.vss.BlockMap method) (dissect.volume.vss.StoreBitmap method) __gt__() (flow.record.selector.NoneObject method) (flow.record.selector.TypeMatcherInstance method) __gte__() (flow.record.selector.NoneObject method) (flow.record.selector.TypeMatcherInstance method) __hash__ (dissect.ntfs.mft.MftRecord attribute) (dissect.ntfs.MftRecord attribute) __hash__() (dissect.cstruct.EnumInstance method) (dissect.cstruct.types.enum.EnumInstance method) (dissect.cstruct.types.EnumInstance method) (flow.record.base.RecordDescriptor method) (flow.record.fieldtypes.datetime method) (flow.record.RecordDescriptor method) __init_subclass__() (dissect.target.plugin.InternalPlugin class method) (dissect.target.plugin.NamespacePlugin class method) (dissect.target.plugin.OSPlugin class method) (dissect.target.plugin.Plugin class method) (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm class method) (dissect.target.plugins.os.windows.dpapi.crypto.HashAlgorithm class method) __init_subclass_namespace__() (dissect.target.plugin.NamespacePlugin method) __init_subclass_subplugin__() (dissect.target.plugin.NamespacePlugin method) __int__() (dissect.cstruct.EnumInstance method) (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.enum.EnumInstance method) (dissect.cstruct.types.EnumInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __invert__() (dissect.cstruct.FlagInstance method) (dissect.cstruct.types.flag.FlagInstance method) (dissect.cstruct.types.FlagInstance method) __iter__ (dissect.esedb.tools.sru.SRU attribute) __iter__() (dissect.etl.Buffer method) (dissect.etl.ETL method) (dissect.etl.etl.Buffer method) (dissect.etl.etl.ETL method) (dissect.eventlog.Evt method) (dissect.eventlog.evt.Evt method) (dissect.eventlog.Evtx method) (dissect.eventlog.evtx.Evtx method) (dissect.eventlog.wevt.MAPS_WEVT_TYPE method) (dissect.eventlog.wevt.TTBL_WEVT_TYPE method) (dissect.eventlog.wevt.WEVT method) (dissect.eventlog.wevt.WEVT_TYPE method) (dissect.eventlog.wevtutil.WevtutilWrapper method) (dissect.executable.elf.elf.Table method) (dissect.ntfs.Index method) (dissect.ntfs.index.Index method) (dissect.ole.ole.Chain method) (dissect.regf.regf.FastLeaf method) (dissect.regf.regf.HashLeaf method) (dissect.regf.regf.IndexLeaf method) (dissect.regf.regf.IndexRoot method) (dissect.regf.regf.ValueList method) (dissect.sql.sqlite3.Row method) (dissect.sql.sqlite3.Table method) (dissect.target.helpers.cache.CacheWriter method) (dissect.target.helpers.cache.LineReader method) (dissect.target.helpers.configutil.PeekableIterator method) (dissect.target.helpers.fsutil.stat_result method) (dissect.target.helpers.regutil.HiveCollection method) (dissect.target.helpers.regutil.KeyCollection method) (dissect.target.helpers.regutil.ValueCollection method) (dissect.target.plugins.os.unix.locate.gnulocate.GNULocateFile method) (dissect.target.plugins.os.unix.locate.mlocate.MLocateFile method) (dissect.target.plugins.os.unix.locate.plocate.PLocateFile method) (dissect.target.plugins.os.unix.log.atop.AtopFile method) (dissect.target.plugins.os.unix.log.journal.JournalFile method) (dissect.target.plugins.os.unix.log.lastlog.LastLogFile method) (dissect.target.plugins.os.unix.log.utmp.UtmpFile method) (dissect.target.plugins.os.windows.regf.shimcache.ShimCache method) (dissect.target.target.Collection method) (flow.record.adapter.AbstractReader method) (flow.record.adapter.avro.AvroReader method) (flow.record.adapter.broker.BrokerReader method) (flow.record.adapter.csvfile.CsvfileReader method) (flow.record.adapter.elastic.ElasticReader method) (flow.record.adapter.jsonfile.JsonfileReader method) (flow.record.adapter.mongo.MongoReader method) (flow.record.adapter.sqlite.SqliteReader method) (flow.record.adapter.stream.StreamReader method) (flow.record.adapter.xlsx.XlsxReader method) (flow.record.selector.TypeMatcherInstance method) (flow.record.stream.RecordStreamReader method) __len__() (dissect.cstruct.Array method) (dissect.cstruct.Instance method) (dissect.cstruct.parser.TokenConsumer method) (dissect.cstruct.RawType method) (dissect.cstruct.Structure method) (dissect.cstruct.types.Array method) (dissect.cstruct.types.base.Array method) (dissect.cstruct.types.base.RawType method) (dissect.cstruct.types.Instance method) (dissect.cstruct.types.instance.Instance method) (dissect.cstruct.types.RawType method) (dissect.cstruct.types.Structure method) (dissect.cstruct.types.structure.Structure method) (dissect.ole.ole.Chain method) (dissect.target.helpers.regutil.HiveCollection method) (dissect.target.helpers.regutil.KeyCollection method) (dissect.target.helpers.regutil.ValueCollection method) (dissect.target.target.Collection method) (flow.record.selector.NoneObject method) __lshift__() (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __lt__() (flow.record.selector.NoneObject method) (flow.record.selector.TypeMatcherInstance method) __lte__() (flow.record.selector.NoneObject method) (flow.record.selector.TypeMatcherInstance method) __MAPPING__ (dissect.target.plugins.os.unix.packagemanager.OperationTypes attribute) __missing__() (flow.record.adapter.text.DefaultMissing method) __mod__() (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __mul__() (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __multi_volume__ (dissect.target.filesystem.Filesystem attribute) (dissect.target.filesystems.btrfs.BtrfsFilesystem attribute) __namespace__ (dissect.target.plugin.Plugin attribute) (dissect.target.plugins.apps.av.mcafee.McAfeePlugin attribute) (dissect.target.plugins.apps.av.sophos.SophosPlugin attribute) (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) (dissect.target.plugins.apps.av.trendmicro.TrendMicroPlugin attribute) (dissect.target.plugins.apps.browser.brave.BravePlugin attribute) (dissect.target.plugins.apps.browser.browser.BrowserPlugin attribute) (dissect.target.plugins.apps.browser.chrome.ChromePlugin attribute) (dissect.target.plugins.apps.browser.chromium.ChromiumPlugin attribute) (dissect.target.plugins.apps.browser.edge.EdgePlugin attribute) (dissect.target.plugins.apps.browser.firefox.FirefoxPlugin attribute) (dissect.target.plugins.apps.browser.iexplore.InternetExplorerPlugin attribute) (dissect.target.plugins.apps.container.docker.DockerPlugin attribute) (dissect.target.plugins.apps.remoteaccess.anydesk.AnydeskPlugin attribute) (dissect.target.plugins.apps.remoteaccess.remoteaccess.RemoteAccessPlugin attribute) (dissect.target.plugins.apps.remoteaccess.teamviewer.TeamviewerPlugin attribute) (dissect.target.plugins.apps.ssh.openssh.OpenSSHPlugin attribute) (dissect.target.plugins.apps.ssh.opensshd.SSHServerPlugin attribute) (dissect.target.plugins.apps.ssh.putty.PuTTYPlugin attribute) (dissect.target.plugins.apps.ssh.ssh.SSHPlugin attribute) (dissect.target.plugins.apps.vpn.openvpn.OpenVPNPlugin attribute) (dissect.target.plugins.apps.vpn.wireguard.WireGuardPlugin attribute) (dissect.target.plugins.apps.webhosting.cpanel.CPanelPlugin attribute) (dissect.target.plugins.apps.webserver.apache.ApachePlugin attribute) (dissect.target.plugins.apps.webserver.caddy.CaddyPlugin attribute) (dissect.target.plugins.apps.webserver.citrix.CitrixWebserverPlugin attribute) (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin attribute) (dissect.target.plugins.apps.webserver.nginx.NginxPlugin attribute) (dissect.target.plugins.apps.webserver.webserver.WebserverPlugin attribute) (dissect.target.plugins.general.config.ConfigurationTreePlugin attribute) (dissect.target.plugins.general.scrape.ScrapePlugin attribute) (dissect.target.plugins.general.users.UsersPlugin attribute) (dissect.target.plugins.os.unix.datetime.DateTimePlugin attribute) (dissect.target.plugins.os.unix.etc.EtcTree attribute) (dissect.target.plugins.os.unix.linux.debian.apt.AptPlugin attribute) (dissect.target.plugins.os.unix.linux.debian.dpkg.DpkgPlugin attribute) (dissect.target.plugins.os.unix.linux.proc.ProcPlugin attribute) (dissect.target.plugins.os.unix.linux.redhat.yum.YumPlugin attribute) (dissect.target.plugins.os.unix.linux.sockets.NetSocketPlugin attribute) (dissect.target.plugins.os.unix.linux.suse.zypper.ZypperPlugin attribute) (dissect.target.plugins.os.unix.locate.gnulocate.GNULocatePlugin attribute) (dissect.target.plugins.os.unix.locate.locate.BaseLocatePlugin attribute) (dissect.target.plugins.os.unix.locate.mlocate.MLocatePlugin attribute) (dissect.target.plugins.os.unix.locate.plocate.PLocatePlugin attribute) (dissect.target.plugins.os.unix.packagemanager.PackageManagerPlugin attribute) (dissect.target.plugins.os.windows.amcache.AmcachePlugin attribute) (dissect.target.plugins.os.windows.amcache.AmcachePluginOldMixin attribute) (dissect.target.plugins.os.windows.cim.CimPlugin attribute) (dissect.target.plugins.os.windows.datetime.DateTimePlugin attribute) (dissect.target.plugins.os.windows.defender.MicrosoftDefenderPlugin attribute) (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin attribute) (dissect.target.plugins.os.windows.exchange.exchange.ExchangePlugin attribute) (dissect.target.plugins.os.windows.log.etl.EtlPlugin attribute) (dissect.target.plugins.os.windows.notifications.NotificationsPlugin attribute) (dissect.target.plugins.os.windows.regf.cit.CITPlugin attribute) (dissect.target.plugins.os.windows.regf.clsid.CLSIDPlugin attribute) (dissect.target.plugins.os.windows.regf.mru.MRUPlugin attribute) (dissect.target.plugins.os.windows.registry.RegistryPlugin attribute) (dissect.target.plugins.os.windows.sru.SRUPlugin attribute) (dissect.target.plugins.os.windows.thumbcache.ThumbcachePlugin attribute) (dissect.target.plugins.os.windows.ual.UalPlugin attribute) __ne__() (dissect.cstruct.EnumInstance method) (dissect.cstruct.parser.Token method) (dissect.cstruct.types.enum.EnumInstance method) (dissect.cstruct.types.EnumInstance method) (dissect.target.helpers.fsutil.stat_result method) (flow.record.selector.NoneObject method) (flow.record.selector.TypeMatcherInstance method) __next__() (dissect.target.helpers.configutil.PeekableIterator method) __nonzero__ (dissect.cstruct.FlagInstance attribute) (dissect.cstruct.types.flag.FlagInstance attribute) (dissect.cstruct.types.FlagInstance attribute) __nonzero__() (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __noteq__() (flow.record.selector.NoneObject method) (flow.record.selector.TypeMatcherInstance method) __or__() (dissect.cstruct.FlagInstance method) (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.flag.FlagInstance method) (dissect.cstruct.types.FlagInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __path__ (in module flow.record.adapter) __pow__() (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __rand__ (dissect.cstruct.FlagInstance attribute) (dissect.cstruct.types.flag.FlagInstance attribute) (dissect.cstruct.types.FlagInstance attribute) __record_descriptors__ (dissect.target.plugin.Plugin attribute) __reduce__() (dissect.target.helpers.compat.path_310.PureDissectPath method) (dissect.target.helpers.compat.path_311.PureDissectPath method) (dissect.target.helpers.compat.path_312.PureDissectPath method) (dissect.target.helpers.compat.path_39.PureDissectPath method) __register__ (dissect.target.loaders.cb.CbRegistry attribute) (dissect.target.loaders.smb.SmbRegistry attribute) (dissect.target.plugin.Plugin attribute) __repr__() (acquire.acquire.dynamic.windows.named_objects.NamedObject method) (dissect.archive.wim.DirectoryEntry method) (dissect.archive.wim.Image method) (dissect.btrfs.btrfs.INode method) (dissect.btrfs.btrfs.Subvolume method) (dissect.btrfs.INode method) (dissect.btrfs.Subvolume method) (dissect.cim.cim.Namespace method) (dissect.cim.classes.PropertyReference method) (dissect.cim.classes.QualifierReference method) (dissect.cim.index.Key method) (dissect.cstruct.Array method) (dissect.cstruct.EnumInstance method) (dissect.cstruct.Expression method) (dissect.cstruct.expression.Expression method) (dissect.cstruct.Field method) (dissect.cstruct.FlagInstance method) (dissect.cstruct.Instance method) (dissect.cstruct.parser.Token method) (dissect.cstruct.parser.TokenConsumer method) (dissect.cstruct.Pointer method) (dissect.cstruct.PointerInstance method) (dissect.cstruct.RawType method) (dissect.cstruct.Structure method) (dissect.cstruct.types.Array method) (dissect.cstruct.types.base.Array method) (dissect.cstruct.types.base.RawType method) (dissect.cstruct.types.enum.EnumInstance method) (dissect.cstruct.types.EnumInstance method) (dissect.cstruct.types.Field method) (dissect.cstruct.types.flag.FlagInstance method) (dissect.cstruct.types.FlagInstance method) (dissect.cstruct.types.Instance method) (dissect.cstruct.types.instance.Instance method) (dissect.cstruct.types.Pointer method) (dissect.cstruct.types.pointer.Pointer method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) (dissect.cstruct.types.RawType method) (dissect.cstruct.types.Structure method) (dissect.cstruct.types.structure.Field method) (dissect.cstruct.types.structure.Structure method) (dissect.cstruct.types.structure.Union method) (dissect.cstruct.types.Union method) (dissect.cstruct.Union method) (dissect.esedb.index.Index method) (dissect.esedb.page.BranchNode method) (dissect.esedb.page.LeafNode method) (dissect.esedb.page.Page method) (dissect.esedb.page.Tag method) (dissect.esedb.record.Record method) (dissect.esedb.record.TagField method) (dissect.esedb.table.Column method) (dissect.esedb.table.Table method) (dissect.esedb.tools.sru.Entry method) (dissect.etl.etl.Event method) (dissect.etl.etl.EventRecord method) (dissect.etl.headers.event.EventHeaderExtendedDataItem method) (dissect.etl.headers.headers.Header method) (dissect.eventlog.bxml.BxmlSub method) (dissect.eventlog.wevt.WEVT method) (dissect.eventlog.wevt_object.WevtObject method) (dissect.evidence.ad1.FileEntry method) (dissect.evidence.ad1.FileMeta method) (dissect.evidence.ad1.LogicalImage method) (dissect.evidence.ewf.HeaderSection method) (dissect.evidence.ewf.SectionDescriptor method) (dissect.executable.ELF method) (dissect.executable.elf.ELF method) (dissect.executable.elf.elf.ELF method) (dissect.executable.elf.elf.Section method) (dissect.executable.elf.elf.SectionTable method) (dissect.executable.elf.elf.Segment method) (dissect.executable.elf.elf.SegmentTable method) (dissect.executable.elf.elf.Symbol method) (dissect.executable.elf.Section method) (dissect.executable.elf.SectionTable method) (dissect.executable.elf.Segment method) (dissect.executable.elf.SegmentTable method) (dissect.executable.elf.Symbol method) (dissect.extfs.extfs.INode method) (dissect.extfs.extfs.XAttr method) (dissect.extfs.INode method) (dissect.extfs.journal.CommitBlock method) (dissect.extfs.journal.DescriptorBlock method) (dissect.extfs.journal.DescriptorBlockTag method) (dissect.fat.fat.DirectoryEntry method) (dissect.ffs.ffs.INode method) (dissect.hypervisor.backup.vma.Device method) (dissect.hypervisor.backup.vma.Extent method) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry method) (dissect.hypervisor.descriptor.vmx.Pair method) (dissect.hypervisor.descriptor.vmx.Phrase method) (dissect.jffs.jffs2.INode method) (dissect.ntfs.ACE method) (dissect.ntfs.attr.Attribute method) (dissect.ntfs.attr.AttributeHeader method) (dissect.ntfs.attr.AttributeList method) (dissect.ntfs.attr.FileName method) (dissect.ntfs.attr.ReparsePoint method) (dissect.ntfs.attr.StandardInformation method) (dissect.ntfs.Attribute method) (dissect.ntfs.AttributeHeader method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.ntfs.secure.ACE method) (dissect.ntfs.usnjrnl.UsnRecord method) (dissect.ntfs.UsnRecord method) (dissect.ole.ole.DirectoryEntry method) (dissect.regf.regf.KeyValue method) (dissect.regf.regf.NamedKey method) (dissect.shellitem.lnk.Lnk method) (dissect.shellitem.lnk.lnk.Lnk method) (dissect.shellitem.lnk.lnk.LnkExtraData method) (dissect.shellitem.lnk.lnk.LnkInfo method) (dissect.shellitem.lnk.lnk.LnkStringData method) (dissect.shellitem.lnk.lnk.LnkTargetIdList method) (dissect.sql.sqlite3.Cell method) (dissect.sql.sqlite3.Column method) (dissect.sql.sqlite3.Index method) (dissect.sql.sqlite3.Page method) (dissect.sql.sqlite3.Row method) (dissect.sql.sqlite3.Table method) (dissect.sql.sqlite3.WALCheckpoint method) (dissect.sql.sqlite3.WALFrame method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.container.Container method) (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.dir.DirectoryFilesystem method) (dissect.target.helpers.fsutil.stat_result method) (dissect.target.helpers.lazy.LazyAttr method) (dissect.target.helpers.lazy.LazyImport method) (dissect.target.helpers.network_managers.NetworkManager method) (dissect.target.helpers.regutil.RegistryKey method) (dissect.target.helpers.regutil.RegistryValue method) (dissect.target.helpers.regutil.VirtualHive method) (dissect.target.helpers.targetd.CommandProxy method) (dissect.target.loader.Loader method) (dissect.target.loaders.itunes.FileInfo method) (dissect.target.loaders.res.File method) (dissect.target.loaders.res.Folder method) (dissect.target.plugins.os.windows.datetime.WindowsTimezone method) (dissect.target.plugins.os.windows.dpapi.blob.Blob method) (dissect.target.plugins.os.windows.regf.cit.Entry method) (dissect.target.plugins.os.windows.regf.shellbags.EXTENSION_BLOCK method) (dissect.target.plugins.os.windows.regf.shellbags.SHITEM method) (dissect.target.Target method) (dissect.target.target.Collection method) (dissect.target.target.Target method) (dissect.target.volume.Volume method) (dissect.target.volume.VolumeSystem method) (dissect.thumbcache.index.IndexEntry method) (dissect.thumbcache.IndexEntry method) (dissect.thumbcache.thumbcache_file.ThumbcacheEntry method) (dissect.thumbcache.ThumbcacheEntry method) (dissect.util.plist.NSDictionary method) (dissect.util.plist.NSKeyedArchiver method) (dissect.util.plist.NSObject method) (dissect.vmfs.vmfs.FileDescriptor method) (dissect.volume.ddf.ddf.ControllerData method) (dissect.volume.ddf.ddf.DDFPhysicalDisk method) (dissect.volume.ddf.ddf.PhysicalDiskData method) (dissect.volume.ddf.ddf.PhysicalDiskRecord method) (dissect.volume.ddf.ddf.VirtualDiskConfigurationRecord method) (dissect.volume.ddf.ddf.VirtualDiskRecord method) (dissect.volume.disk.Partition method) (dissect.volume.disk.partition.Partition method) (dissect.volume.lvm.LVM2 method) (dissect.volume.lvm.lvm2.LVM2 method) (dissect.volume.lvm.LVM2Device method) (dissect.volume.lvm.metadata.HistoricalLogicalVolume method) (dissect.volume.lvm.metadata.LogicalVolume method) (dissect.volume.lvm.metadata.PhysicalVolume method) (dissect.volume.lvm.metadata.Segment method) (dissect.volume.lvm.metadata.VolumeGroup method) (dissect.volume.lvm.physical.LVM2Device method) (dissect.volume.vss.BlockDescriptor method) (dissect.volume.vss.Catalog method) (dissect.volume.vss.VSS method) (dissect.xfs.xfs.INode method) (flow.record.base.GroupedRecord method) (flow.record.base.Record method) (flow.record.base.RecordDescriptor method) (flow.record.base.RecordField method) (flow.record.fieldtypes.boolean method) (flow.record.fieldtypes.bytes method) (flow.record.fieldtypes.datetime method) (flow.record.fieldtypes.digest method) (flow.record.fieldtypes.filesize method) (flow.record.fieldtypes.net.ip.ipaddress method) (flow.record.fieldtypes.net.ip.ipnetwork method) (flow.record.fieldtypes.net.ipaddress method) (flow.record.fieldtypes.net.ipnetwork method) (flow.record.fieldtypes.net.ipv4.address method) (flow.record.fieldtypes.net.ipv4.subnet method) (flow.record.fieldtypes.path method) (flow.record.fieldtypes.uint16 method) (flow.record.fieldtypes.unix_file_mode method) (flow.record.fieldtypes.windows_path method) (flow.record.GroupedRecord method) (flow.record.Record method) (flow.record.RecordDescriptor method) (flow.record.RecordField method) (flow.record.selector.CompiledSelector method) (flow.record.selector.Selector method) (flow.record.selector.WrappedRecord method) __ror__ (dissect.cstruct.FlagInstance attribute) (dissect.cstruct.types.flag.FlagInstance attribute) (dissect.cstruct.types.FlagInstance attribute) __rshift__() (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __rtruediv__() (dissect.target.helpers.compat.path_310.PureDissectPath method) (dissect.target.helpers.compat.path_311.PureDissectPath method) (dissect.target.helpers.compat.path_39.PureDissectPath method) __rxor__ (dissect.cstruct.FlagInstance attribute) (dissect.cstruct.types.flag.FlagInstance attribute) (dissect.cstruct.types.FlagInstance attribute) __setattr__() (dissect.cim.classes.InstanceKey method) (dissect.cstruct.Instance method) (dissect.cstruct.types.Instance method) (dissect.cstruct.types.instance.Instance method) (flow.record.base.GroupedRecord method) (flow.record.base.Record method) (flow.record.GroupedRecord method) (flow.record.Record method) __setitem__() (dissect.eventlog.utils.KeyValueCollection method) (dissect.target.plugins.apps.vpn.wireguard.MultiDict method) __slots__ (acquire.acquire.dynamic.windows.named_objects.NamedObject attribute) (dissect.archive.wim.Resource attribute) (dissect.cstruct.Instance attribute) (dissect.cstruct.parser.Token attribute) (dissect.cstruct.types.Instance attribute) (dissect.cstruct.types.instance.Instance attribute) (dissect.esedb.page.BranchNode attribute) (dissect.esedb.page.Node attribute) (dissect.esedb.page.Tag attribute) (dissect.esedb.record.TagField attribute) (dissect.etl.etl.Event attribute) (dissect.etl.etl.EventRecord attribute) (dissect.etl.headers.event.EventDescriptor attribute) (dissect.etl.headers.event.EventHeaderExtendedDataItem attribute) (dissect.eventlog.wevt_object.BMAP attribute) (dissect.eventlog.wevt_object.CHAN attribute) (dissect.eventlog.wevt_object.EVNT attribute) (dissect.eventlog.wevt_object.KEYW attribute) (dissect.eventlog.wevt_object.LEVL attribute) (dissect.eventlog.wevt_object.OPCO attribute) (dissect.eventlog.wevt_object.PRVA attribute) (dissect.eventlog.wevt_object.TASK attribute) (dissect.eventlog.wevt_object.TEMP attribute) (dissect.eventlog.wevt_object.TEMP_DESCRIPTOR attribute) (dissect.eventlog.wevt_object.VMAP attribute) (dissect.ntfs.attr.Attribute attribute) (dissect.ntfs.attr.AttributeHeader attribute) (dissect.ntfs.attr.AttributeList attribute) (dissect.ntfs.attr.AttributeRecord attribute) (dissect.ntfs.attr.FileName attribute) (dissect.ntfs.attr.ReparsePoint attribute) (dissect.ntfs.attr.StandardInformation attribute) (dissect.ntfs.Attribute attribute) (dissect.ntfs.AttributeHeader attribute) (dissect.ntfs.AttributeRecord attribute) (dissect.target.helpers.compat.path_310.TargetPath attribute) (dissect.target.helpers.compat.path_311.TargetPath attribute) (dissect.target.helpers.compat.path_312.TargetPath attribute) (dissect.target.helpers.compat.path_39.TargetPath attribute) (dissect.target.helpers.fsutil.stat_result attribute) (dissect.thumbcache.thumbcache_file.ThumbcacheFile attribute) (dissect.thumbcache.ThumbcacheFile attribute) (dissect.util.compression.lzxpress_huffman.Node attribute) (dissect.volume.vss.BlockDescriptor attribute) (flow.record.base.Record attribute) (flow.record.Record attribute) (flow.record.selector.WrappedRecord attribute) __str__() (acquire.acquire.dynamic.windows.types.UNICODE_STRING method) (dissect.cim.classes.InstanceKey method) (dissect.cim.index.Key method) (dissect.cstruct.EnumInstance method) (dissect.cstruct.FlagInstance method) (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.enum.EnumInstance method) (dissect.cstruct.types.EnumInstance method) (dissect.cstruct.types.flag.FlagInstance method) (dissect.cstruct.types.FlagInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) (dissect.esedb.record.Record method) (dissect.eventlog.bxml.BxmlSub method) (dissect.eventlog.bxml.BxmlTag method) (dissect.eventlog.bxml.BxmlType method) (dissect.eventlog.bxml.Template method) (dissect.hypervisor.disk.vmdk.DiskDescriptor method) (dissect.target.filesystem.FilesystemEntry method) (flow.record.fieldtypes.boolean method) (flow.record.fieldtypes.datetime method) (flow.record.fieldtypes.net.ip.ipaddress method) (flow.record.fieldtypes.net.ip.ipnetwork method) (flow.record.fieldtypes.net.ipaddress method) (flow.record.fieldtypes.net.ipnetwork method) (flow.record.fieldtypes.net.ipv4.address method) (flow.record.fieldtypes.net.ipv4.subnet method) (flow.record.selector.CompiledSelector method) (flow.record.selector.Selector method) (flow.record.selector.WrappedRecord method) __sub__() (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) __type__ (dissect.target.container.Container attribute) (dissect.target.containers.asdf.AsdfContainer attribute) (dissect.target.containers.ewf.EwfContainer attribute) (dissect.target.containers.hdd.HddContainer attribute) (dissect.target.containers.hds.HdsContainer attribute) (dissect.target.containers.qcow2.QCow2Container attribute) (dissect.target.containers.raw.RawContainer attribute) (dissect.target.containers.split.SplitContainer attribute) (dissect.target.containers.vdi.VdiContainer attribute) (dissect.target.containers.vhd.VhdContainer attribute) (dissect.target.containers.vhdx.VhdxContainer attribute) (dissect.target.containers.vmdk.VmdkContainer attribute) (dissect.target.filesystem.Filesystem attribute) (dissect.target.filesystem.RootFilesystem attribute) (dissect.target.filesystem.VirtualFilesystem attribute) (dissect.target.filesystems.ad1.AD1Filesystem attribute) (dissect.target.filesystems.btrfs.BtrfsFilesystem attribute) (dissect.target.filesystems.btrfs.BtrfsSubvolumeFilesystem attribute) (dissect.target.filesystems.cb.CbFilesystem attribute) (dissect.target.filesystems.config.ConfigurationFilesystem attribute) (dissect.target.filesystems.cpio.CpioFilesystem attribute) (dissect.target.filesystems.dir.DirectoryFilesystem attribute) (dissect.target.filesystems.exfat.ExfatFilesystem attribute) (dissect.target.filesystems.extfs.ExtFilesystem attribute) (dissect.target.filesystems.fat.FatFilesystem attribute) (dissect.target.filesystems.ffs.FfsFilesystem attribute) (dissect.target.filesystems.itunes.ITunesFilesystem attribute) (dissect.target.filesystems.jffs.JFFSFilesystem attribute) (dissect.target.filesystems.ntfs.NtfsFilesystem attribute) (dissect.target.filesystems.smb.SmbFilesystem attribute) (dissect.target.filesystems.squashfs.SquashFSFilesystem attribute) (dissect.target.filesystems.tar.TarFilesystem attribute) (dissect.target.filesystems.vmfs.VmfsFilesystem attribute) (dissect.target.filesystems.vmtar.VmtarFilesystem attribute) (dissect.target.filesystems.xfs.XfsFilesystem attribute) (dissect.target.filesystems.zip.ZipFilesystem attribute) (dissect.target.plugin.ChildTargetPlugin attribute) (dissect.target.plugins.child.esxi.ESXiChildTargetPlugin attribute) (dissect.target.plugins.child.hyperv.HyperVChildTargetPlugin attribute) (dissect.target.plugins.child.virtuozzo.VirtuozzoChildTargetPlugin attribute) (dissect.target.plugins.child.vmware_workstation.WorkstationChildTargetPlugin attribute) (dissect.target.plugins.child.wsl.WSLChildTargetPlugin attribute) (dissect.target.volume.VolumeSystem attribute) (dissect.target.volumes.bde.BitlockerVolumeSystem attribute) (dissect.target.volumes.ddf.DdfVolumeSystem attribute) (dissect.target.volumes.disk.DissectVolumeSystem attribute) (dissect.target.volumes.luks.LUKSVolumeSystem attribute) (dissect.target.volumes.lvm.LvmVolumeSystem attribute) (dissect.target.volumes.md.MdVolumeSystem attribute) (dissect.target.volumes.vmfs.VmfsVolumeSystem attribute) (flow.record.fieldtypes.typedlist attribute) __usage__ (in module flow.record.adapter.archive) (in module flow.record.adapter.avro) (in module flow.record.adapter.broker) (in module flow.record.adapter.csvfile) (in module flow.record.adapter.elastic) (in module flow.record.adapter.jsonfile) (in module flow.record.adapter.line) (in module flow.record.adapter.mongo) (in module flow.record.adapter.split) (in module flow.record.adapter.splunk) (in module flow.record.adapter.sqlite) (in module flow.record.adapter.stream) (in module flow.record.adapter.text) (in module flow.record.adapter.xlsx) __xor__() (dissect.cstruct.FlagInstance method) (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.flag.FlagInstance method) (dissect.cstruct.types.FlagInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) _current (dissect.target.helpers.configutil.ScopeManager attribute) _parents (dissect.target.helpers.configutil.ScopeManager attribute) _previous (dissect.target.helpers.configutil.ScopeManager attribute) _public_member (in module codestyle) _root (dissect.target.helpers.configutil.ScopeManager attribute) A absolute (dissect.archive.wim.ReparsePoint property) (dissect.ntfs.attr.ReparsePoint property) absolute() (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) abspath() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) AbstractReader (class in flow.record.adapter) AbstractWriter (class in flow.record.adapter) access() (dissect.target.plugins.apps.webserver.apache.ApachePlugin method) (dissect.target.plugins.apps.webserver.caddy.CaddyPlugin method) (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin method) (dissect.target.plugins.apps.webserver.nginx.NginxPlugin method) ACCESS_LOG_NAMES (dissect.target.plugins.apps.webserver.apache.ApachePlugin attribute) (dissect.target.plugins.apps.webserver.citrix.CitrixWebserverPlugin attribute) ACCESS_MASK (class in acquire.acquire.dynamic.windows.ntdll) (in module dissect.ntfs.c_ntfs) access_time (dissect.target.plugins.os.windows.regf.shellbags.SHITEM property) AccessDeniedError account_policy() (dissect.target.plugins.os.unix.bsd.osx.user.UserPlugin method) AccountPolicyRecord (in module dissect.target.plugins.os.unix.bsd.osx.user) ACE (class in dissect.ntfs) (class in dissect.ntfs.secure) ACE_OBJECT_FLAGS (in module dissect.ntfs.c_ntfs) ACE_TYPE (in module dissect.ntfs.c_ntfs) ack_pingpong (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) ack_threads (dissect.volume.lvm.metadata.VdoPoolSegment attribute) ACL (class in dissect.ntfs) (class in dissect.ntfs.secure) acmru() (dissect.target.plugins.os.windows.regf.mru.MRUPlugin method) ACMruRecord (in module dissect.target.plugins.os.windows.regf.mru) acquire.acquire module acquire.acquire.acquire module acquire.acquire.collector module acquire.acquire.crypt module acquire.acquire.dynamic module acquire.acquire.dynamic.windows module acquire.acquire.dynamic.windows.collect module acquire.acquire.dynamic.windows.exceptions module acquire.acquire.dynamic.windows.handles module acquire.acquire.dynamic.windows.named_objects module acquire.acquire.dynamic.windows.ntdll module acquire.acquire.dynamic.windows.types module acquire.acquire.esxi module acquire.acquire.gui module acquire.acquire.gui.base module acquire.acquire.gui.win32 module acquire.acquire.hashes module acquire.acquire.log module acquire.acquire.outputs module acquire.acquire.outputs.base module acquire.acquire.outputs.dir module acquire.acquire.outputs.tar module acquire.acquire.outputs.zip module acquire.acquire.tools module acquire.acquire.tools.decrypter module acquire.acquire.uploaders module acquire.acquire.uploaders.minio module acquire.acquire.uploaders.plugin module acquire.acquire.uploaders.plugin_registry module acquire.acquire.utils module acquire.acquire.volatilestream module ACQUIRE_BANNER (in module acquire.acquire.acquire) acquire_children_and_targets() (in module acquire.acquire.acquire) acquire_handles() (dissect.target.plugins.filesystem.acquire_handles.OpenHandlesPlugin method) acquire_hashes() (dissect.target.plugins.filesystem.acquire_hash.AcquireHashPlugin method) acquire_target() (in module acquire.acquire.acquire) acquire_target_regular() (in module acquire.acquire.acquire) acquire_target_targetd() (in module acquire.acquire.acquire) AcquireHashPlugin (class in dissect.target.plugins.filesystem.acquire_hash) AcquireHashRecord (in module dissect.target.plugins.filesystem.acquire_hash) AcquireOpenHandlesRecord (in module dissect.target.plugins.filesystem.acquire_handles) ACTION (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) ActiveDirectory (class in acquire.acquire.acquire) ActivitiesCache (class in acquire.acquire.acquire) activitiescache() (dissect.target.plugins.os.windows.activitiescache.ActivitiesCachePlugin method) ActivitiesCachePlugin (class in dissect.target.plugins.os.windows.activitiescache) ActivitiesCacheRecord (in module dissect.target.plugins.os.windows.activitiescache) activity() (dissect.target.plugins.os.unix.generic.GenericPlugin method) (dissect.target.plugins.os.unix.linux.fortios.generic.GenericPlugin method) (dissect.target.plugins.os.windows.generic.GenericPlugin method) activity_id (dissect.etl.headers.event.EventHeader property) AD1 (class in dissect.evidence.ad1) ad1_def (in module dissect.evidence.ad1) AD1File (class in dissect.target.loaders.ad1) AD1Filesystem (class in dissect.target.filesystems.ad1) AD1FilesystemEntry (class in dissect.target.filesystems.ad1) AD1Loader (class in dissect.target.loaders.ad1) add() (dissect.btrfs.stream.ChunkStream method) (dissect.cstruct.parser.TokenCollection method) (dissect.ntfs.util.AttributeMap method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.helpers.regutil.HiveCollection method) (dissect.target.helpers.regutil.KeyCollection method) (dissect.target.helpers.regutil.ValueCollection method) (dissect.target.target.Collection method) (dissect.util.stream.MappingStream method) (dissect.util.stream.OverlayStream method) (dissect.volume.vss.BlockMap method) (flow.record.fieldtypes.net.ipv4.SubnetList method) add_attributes() (dissect.eventlog.bxml.BxmlTag method) add_bytes() (dissect.evidence.asdf.asdf.AsdfWriter method) (dissect.evidence.asdf.AsdfWriter method) add_child_template() (dissect.eventlog.bxml.Template method) add_children() (dissect.eventlog.bxml.BxmlTag method) add_command_collected() (acquire.acquire.collector.CollectionReport method) add_command_failed() (acquire.acquire.collector.CollectionReport method) add_dir_collected() (acquire.acquire.collector.CollectionReport method) add_dir_failed() (acquire.acquire.collector.CollectionReport method) add_dir_missing() (acquire.acquire.collector.CollectionReport method) add_field() (dissect.cstruct.Structure method) (dissect.cstruct.types.Structure method) (dissect.cstruct.types.structure.Structure method) add_file_collected() (acquire.acquire.collector.CollectionReport method) add_file_failed() (acquire.acquire.collector.CollectionReport method) add_file_missing() (acquire.acquire.collector.CollectionReport method) add_func_error() (dissect.target.report.TargetExecutionReport method) add_glob_empty() (acquire.acquire.collector.CollectionReport method) add_glob_failed() (acquire.acquire.collector.CollectionReport method) add_handler() (flow.record.utils.EventHandler method) add_hive() (dissect.target.plugins.os.windows.registry.RegistryPlugin method) add_incompatible_plugin() (dissect.target.report.TargetExecutionReport method) add_layer() (dissect.target.filesystem.RootFilesystem method) add_metadata_file() (dissect.evidence.asdf.asdf.AsdfWriter method) (dissect.evidence.asdf.AsdfWriter method) add_mounts() (dissect.target.plugins.os.windows._os.WindowsPlugin method) add_path_failed() (acquire.acquire.collector.CollectionReport method) add_path_missing() (acquire.acquire.collector.CollectionReport method) add_plugin() (dissect.target.Target method) (dissect.target.target.Target method) add_registered_plugin() (dissect.target.report.TargetExecutionReport method) add_sub() (dissect.eventlog.bxml.Template method) add_subkey() (dissect.target.helpers.regutil.VirtualKey method) add_symlink_collected() (acquire.acquire.collector.CollectionReport method) add_symlink_failed() (acquire.acquire.collector.CollectionReport method) add_target_report() (dissect.target.report.ExecutionReport method) add_value() (dissect.target.helpers.regutil.VirtualKey method) add_virtual_ntfs_filesystem() (in module dissect.target.helpers.loaderutil) additional_header_fields() (dissect.etl.headers.event.EventHeader method) (dissect.etl.headers.headers.ErrorHeader method) (dissect.etl.headers.headers.EventInstanceGUIDHeader method) (dissect.etl.headers.headers.EventInstanceHeader method) (dissect.etl.headers.headers.EventTraceHeader method) (dissect.etl.headers.headers.Header method) (dissect.etl.headers.headers.MessageTraceHeader method) (dissect.etl.headers.system.CompactSystemHeader method) (dissect.etl.headers.system.PerfinfoTraceHeader method) (dissect.etl.headers.system.SystemHeader method) address (class in flow.record.fieldtypes.net.ipv4) Address (in module flow.record.fieldtypes.net.ipv4) address_fmt() (in module dissect.vmfs.resource) address_tbz() (in module dissect.vmfs.resource) address_type() (in module dissect.vmfs.resource) ADDRESS_TYPE_MASK (in module dissect.vmfs.c_vmfs) addtype() (dissect.cstruct.cstruct method) (dissect.cstruct.cstruct.cstruct method) adpolicy() (dissect.target.plugins.os.windows.adpolicy.ADPolicyPlugin method) ADPolicyPlugin (class in dissect.target.plugins.os.windows.adpolicy) ADPolicyRecord (in module dissect.target.plugins.os.windows.adpolicy) ADVANCED (dissect.util.feature.Feature attribute) aes_decrypt() (in module dissect.target.loaders.itunes) aes_unwrap_key() (in module dissect.target.loaders.itunes) aligned_size (dissect.etl.etl.EventRecord property) AlignedStream (class in dissect.util.stream) ALIGNMENT (in module dissect.hypervisor.disk.c_vhdx) all() (dissect.target.plugins.general.users.UsersPlugin method) all_with_home() (dissect.target.plugins.general.users.UsersPlugin method) allocated_size (dissect.ntfs.attr.AttributeHeader property) (dissect.ntfs.AttributeHeader property) allocation_policy (dissect.volume.lvm.metadata.LogicalVolume attribute) (dissect.volume.lvm.metadata.VolumeGroup attribute) AllocationGroup (class in dissect.xfs.xfs) ALLOW_NO_BACKING_FILE (in module dissect.hypervisor.disk.qcow2) alnum() (dissect.cstruct.expression.ExpressionTokenizer method) ALPC_PORT (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) ALPCGuid (in module dissect.etl.utils) alpha() (dissect.cstruct.expression.ExpressionTokenizer method) alt_separator (dissect.target.filesystem.RootFilesystem property) ALTERNATE_DATA_STREAM (dissect.target.plugins.filesystem.ntfs.utils.InformationType attribute) alternateshell() (dissect.target.plugins.os.windows.generic.GenericPlugin method) AlternateShellRecord (in module dissect.target.plugins.os.windows.generic) AMCACHE_FILE_KEYS (in module dissect.target.plugins.os.windows.amcache) amcache_install() (dissect.target.plugins.os.windows.log.amcache.AmcacheInstallPlugin method) AMCACHE_PROGRAM_KEYS (in module dissect.target.plugins.os.windows.amcache) AmcacheArpCreateRecord (in module dissect.target.plugins.os.windows.log.amcache) AmcacheFileCreateRecord (in module dissect.target.plugins.os.windows.log.amcache) AmcacheInstallPlugin (class in dissect.target.plugins.os.windows.log.amcache) AmcachePlugin (class in dissect.target.plugins.os.windows.amcache) AmcachePluginOldMixin (class in dissect.target.plugins.os.windows.amcache) ANDROID (dissect.target.plugin.OperatingSystem attribute) AndroidPlugin (class in dissect.target.plugins.os.unix.linux.android._os) ANON_FS_RE (in module dissect.target.loaders.tar) ANSITRING (dissect.eventlog.bxml.BxmlType attribute) AnydeskPlugin (class in dissect.target.plugins.apps.remoteaccess.anydesk) apache_response_time_to_ms() (in module dissect.target.plugins.apps.webserver.apache) ApachePlugin (class in dissect.target.plugins.apps.webserver.apache) APM (class in dissect.volume.disk.schemes) (class in dissect.volume.disk.schemes.apm) apm_def (in module dissect.volume.disk.schemes.apm) Appcompat (class in acquire.acquire.acquire) appdb() (dissect.target.plugins.os.windows.notifications.NotificationsPlugin method) appdb_def (in module dissect.target.plugins.os.windows.notifications) APPDB_MAGIC (in module dissect.target.plugins.os.windows.notifications) AppDBBadgeRecord (in module dissect.target.plugins.os.windows.notifications) AppDBPushRecord (in module dissect.target.plugins.os.windows.notifications) AppDBRecord (in module dissect.target.plugins.os.windows.notifications) AppDBTileRecord (in module dissect.target.plugins.os.windows.notifications) AppDBToastRecord (in module dissect.target.plugins.os.windows.notifications) appinit() (dissect.target.plugins.os.windows.generic.GenericPlugin method) AppInitRecord (in module dissect.target.plugins.os.windows.generic) AppLaunchAppcompatRecord (in module dissect.target.plugins.os.windows.amcache) applaunches() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) application() (dissect.target.plugins.os.windows.sru.SRUPlugin method) application_files() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) APPLICATION_HOST_CONFIG (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin attribute) application_timeline() (dissect.target.plugins.os.windows.sru.SRUPlugin method) ApplicationAppcompatRecord (in module dissect.target.plugins.os.windows.amcache) ApplicationFileAppcompatRecord (in module dissect.target.plugins.os.windows.amcache) ApplicationRecord (in module dissect.target.plugins.os.windows.sru) applications() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) ApplicationTimelineRecord (in module dissect.target.plugins.os.windows.sru) apply() (dissect.target.Target method) (dissect.target.target.DiskCollection method) (dissect.target.target.FilesystemCollection method) (dissect.target.target.Target method) (dissect.target.target.VolumeCollection method) apply_fixup() (in module dissect.ntfs.util) AppxDebugKeyRecord (in module dissect.target.plugins.os.windows.regf.appxdebugkeys) appxdebugkeys() (dissect.target.plugins.os.windows.regf.appxdebugkeys.AppxDebugKeysPlugin method) AppxDebugKeysPlugin (class in dissect.target.plugins.os.windows.regf.appxdebugkeys) APT_LOG_OPERATIONS (in module dissect.target.plugins.os.unix.linux.debian.apt) AptPlugin (class in dissect.target.plugins.os.unix.linux.debian.apt) ARABIC (dissect.esedb.lcmapstring.SCRIPT attribute) ArcHistoryRecord (in module dissect.target.plugins.os.windows.regf.7zip) architecture() (dissect.target.plugin.OSPlugin method) (dissect.target.plugins.general.default.DefaultPlugin method) (dissect.target.plugins.os.unix._os.UnixPlugin method) (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin method) (dissect.target.plugins.os.unix.linux.fortios._os.FortiOSPlugin method) (dissect.target.plugins.os.windows._os.WindowsPlugin method) ArchiveReader (class in flow.record.adapter.archive) ArchiveWriter (class in flow.record.adapter.archive) aRepr (in module flow.record.stream) arg() (in module dissect.target.plugin) args (flow.record.fieldtypes.uri property) args_to_uri() (in module dissect.target.tools.utils) Array (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.base) ARRAY_MASK (dissect.eventlog.bxml.BxmlTemplateDescriptor attribute) ARRAY_STATES (in module dissect.cim.c_cim) ArraySizeError artifact_type (acquire.acquire.collector.Record attribute) artifact_value (acquire.acquire.collector.Record attribute) ArtifactType (class in acquire.acquire.collector) as_dict() (dissect.esedb.record.Record method) (dissect.esedb.record.RecordData method) (dissect.hypervisor.descriptor.hyperv.HyperVFile method) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.report.ExecutionReport method) (dissect.target.report.TargetExecutionReport method) as_full_map() (dissect.eventlog.bxml.Template method) as_hashlib_method() (acquire.acquire.hashes.HashFunc method) as_map() (dissect.eventlog.bxml.Template method) ASCII_MAP (in module dissect.target.plugins.apps.container.docker) asdf_def (in module dissect.evidence.asdf.asdf) AsdfContainer (class in dissect.target.containers.asdf) AsdfLoader (class in dissect.target.loaders.asdf) AsdfSnapshot (class in dissect.evidence) (class in dissect.evidence.asdf) (class in dissect.evidence.asdf.asdf) AsdfStream (class in dissect.evidence) (class in dissect.evidence.asdf) (class in dissect.evidence.asdf.asdf) AsdfWriter (class in dissect.evidence.asdf) (class in dissect.evidence.asdf.asdf) AsnRecord (in module flow.record.tools.geoip) asnrecord_for_ip() (in module flow.record.tools.geoip) AST_COMPARATORS (in module flow.record.selector) AST_NODE_S_TYPES (in module flow.record.selector) AST_NODE_VALUE_TYPES (in module flow.record.selector) AST_OPERATORS (in module flow.record.selector) atime (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.fat.fat.DirectoryEntry property) (dissect.fat.fat.RootDirectory property) (dissect.xfs.xfs.INode property) atime() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.vmfs.vmfs.FileDescriptor method) atime_ns (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.xfs.xfs.INode property) atime_ns() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) atjob (in module dissect.target.plugins.os.windows.task_helpers.tasks_job) atjob_def (in module dissect.target.plugins.os.windows.task_helpers.tasks_job) atop() (dissect.target.plugins.os.unix.log.atop.AtopPlugin method) atop_def (in module dissect.target.plugins.os.unix.log.atop) ATOP_GLOB (dissect.target.plugins.os.unix.log.atop.AtopPlugin attribute) ATOP_MAGIC (dissect.target.plugins.os.unix.log.atop.AtopPlugin attribute) ATOP_PATH (dissect.target.plugins.os.unix.log.atop.AtopPlugin attribute) atop_tstat_def (in module dissect.target.plugins.os.unix.log.atop) ATOP_VERSIONS (dissect.target.plugins.os.unix.log.atop.AtopPlugin attribute) AtopFile (class in dissect.target.plugins.os.unix.log.atop) AtopPlugin (class in dissect.target.plugins.os.unix.log.atop) AtopRecord (in module dissect.target.plugins.os.unix.log.atop) attach() (dissect.volume.lvm.metadata.VolumeGroup method) AtTask (class in dissect.target.plugins.os.windows.task_helpers.tasks_job) attr() (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.MappedFile method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) attr_extents (dissect.xfs.xfs.INode property) attrfork() (dissect.xfs.xfs.INode method) Attribute (class in dissect.ntfs) (class in dissect.ntfs.attr) attribute() (dissect.ntfs.index.IndexEntry method) (dissect.ntfs.IndexEntry method) ATTRIBUTE_CLASS_MAP (in module dissect.ntfs.attr) ATTRIBUTE_FLAG_COMPRESSION_MASK (in module dissect.ntfs.c_ntfs) ATTRIBUTE_FLAG_ENCRYPTED (in module dissect.ntfs.c_ntfs) ATTRIBUTE_FLAG_SPARSE (in module dissect.ntfs.c_ntfs) attribute_type (dissect.ntfs.index.IndexRoot property) ATTRIBUTE_TYPE_CODE (in module dissect.ntfs) (in module dissect.ntfs.c_ntfs) AttributeCollection (class in dissect.ntfs.util) AttributeHeader (class in dissect.ntfs) (class in dissect.ntfs.attr) AttributeList (class in dissect.ntfs.attr) AttributeMap (class in dissect.ntfs.util) AttributeRecord (class in dissect.ntfs) (class in dissect.ntfs.attr) attributes() (dissect.ntfs.attr.AttributeList method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) audit() (dissect.target.plugins.os.unix.log.audit.AuditPlugin method) AUDIT_REGEX (in module dissect.target.plugins.os.unix.log.audit) AuditPlugin (class in dissect.target.plugins.os.unix.log.audit) auditpol() (dissect.target.plugins.os.windows.regf.auditpol.AuditpolPlugin method) AuditPolicyRecord (in module dissect.target.plugins.os.windows.regf.auditpol) AuditpolPlugin (class in dissect.target.plugins.os.windows.regf.auditpol) AuditRecord (in module dissect.target.plugins.os.unix.log.audit) authlog() (dissect.target.plugins.os.unix.log.auth.AuthPlugin method) AuthLogRecord (in module dissect.target.plugins.os.unix.log.auth) authorized_keys() (dissect.target.plugins.apps.ssh.openssh.OpenSSHPlugin method) AuthorizedKeysRecord (in module dissect.target.plugins.apps.ssh.ssh) AuthPlugin (class in dissect.target.plugins.os.unix.log.auth) auto_upload (acquire.acquire.gui.base.GUI attribute) autocommit_blocks (dissect.volume.lvm.metadata.WriteCacheSegment attribute) autocommit_time (dissect.volume.lvm.metadata.WriteCacheSegment attribute) AV (class in acquire.acquire.acquire) AV_ACTION_TAKEN (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_CLEANABLE (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_COMPRESSED (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_CONFIDENCE (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_DELETABLE (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_DEPTH (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_DOWNLOADED_FROM (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_EVENT (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_EVENT_DATA (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_FILE (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_PREVALENCE (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_QUARANTINE_ID (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_QUARANTINE_STATUS (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_RISK (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_SCAN_ID (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_STILL_INFECTED (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_TIMESTAMP (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_USER (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_VIRUS (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_VIRUS_ID (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AV_VIRUS_TYPE (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) AVRO_MAGIC (in module flow.record.base) AVRO_TYPE_MAP (in module flow.record.adapter.avro) avro_type_to_flow_type() (in module flow.record.adapter.avro) AvroReader (class in flow.record.adapter.avro) AvroWriter (class in flow.record.adapter.avro) B ba_size (dissect.volume.lvm.metadata.PhysicalVolume attribute) ba_start (dissect.volume.lvm.metadata.PhysicalVolume attribute) backtrace() (flow.record.selector.SelectorResult method) BAD_CLUSTER (in module dissect.fat.c_fat) BadClusterError, [1] bag_def (in module dissect.target.plugins.os.windows.regf.shellbags) bam() (dissect.target.plugins.os.windows.regf.bam.BamDamPlugin method) BamDamPlugin (class in dissect.target.plugins.os.windows.regf.bam) BamDamRecord (in module dissect.target.plugins.os.windows.regf.bam) base() (flow.record.base.RecordDescriptor method) (flow.record.RecordDescriptor method) base_records() (dissect.clfs.blf.BLF method) BaseLocatePlugin (class in dissect.target.plugins.os.unix.locate.locate) basename() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) BaseRecord (class in dissect.clfs.blf) BaseType (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.base) BaseUseData (class in dissect.target.plugins.os.windows.regf.cit) BaseUseDataBitmaps (class in dissect.target.plugins.os.windows.regf.cit) bashhistory() (dissect.target.plugins.os.unix.history.CommandHistoryPlugin method) BASIC_RECORD_FIELDS (in module dissect.target.plugins.apps.webserver.iis) BasicRecordDescriptor (in module dissect.target.plugins.apps.webserver.iis) bat() (dissect.hypervisor.disk.hdd.HDS method) BAT_REGION_GUID (in module dissect.hypervisor.disk.c_vhdx) bde (in module dissect.target.volume) BETA (dissect.util.feature.Feature attribute) BFFCALLBACK (in module acquire.acquire.gui.win32) BINARY (dissect.eventlog.bxml.BxmlType attribute) BinaryAppcompatRecord (in module dissect.target.plugins.os.windows.amcache) bind() (acquire.acquire.collector.Collector method) bind_module() (acquire.acquire.collector.Collector method) BINXML (dissect.eventlog.bxml.BxmlType attribute) bio_rotation (dissect.volume.lvm.metadata.VdoPoolSegment attribute) bio_threads (dissect.volume.lvm.metadata.VdoPoolSegment attribute) BIT64_HEADERS (in module dissect.etl.headers.headers) BitBuffer (class in dissect.cstruct) (class in dissect.cstruct.bitbuffer) BitlockerVolumeSystem (class in dissect.target.volumes.bde) BitlockerVolumeSystemError bitmap (dissect.volume.vss.Store property) bitmap() (dissect.hypervisor.disk.qcow2.L2Table method) BITMAP_ENTRY (in module dissect.fat.c_exfat) BITMAP_FIELDS (in module dissect.target.plugins.os.windows.regf.cit) bitmap_flush_interval (dissect.volume.lvm.metadata.IntegritySegment attribute) BITS (class in acquire.acquire.acquire) BitString (class in dissect.util.compression.lzxpress_huffman) BLACK (dissect.target.helpers.cyber.Color attribute) BLF (class in dissect.clfs.blf) BLF_PATH (dissect.target.plugins.os.windows.clfs.ClfsPlugin attribute) blkstofrags() (in module dissect.ffs.ffs) Blob (class in dissect.target.plugins.os.windows.dpapi.blob) blob_data() (dissect.hypervisor.backup.vma.VMA method) blob_def (in module dissect.target.plugins.os.windows.dpapi.blob) blob_string() (dissect.hypervisor.backup.vma.VMA method) BLOCK_FLAG (in module dissect.volume.vss) BLOCK_INDENT (in module dissect.target.report) block_length (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm attribute) (dissect.target.plugins.os.windows.dpapi.crypto.HashAlgorithm attribute) block_list (dissect.volume.vss.Store property) block_list() (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) BLOCK_MAGIC (in module dissect.evidence.asdf.asdf) block_map_cache_size_mb (dissect.volume.lvm.metadata.VdoPoolSegment attribute) block_map_era_length (dissect.volume.lvm.metadata.VdoPoolSegment attribute) block_size (dissect.vmfs.vmfs.FileDescriptor property) (dissect.volume.lvm.metadata.IntegritySegment attribute) BLOCK_SIZE (in module dissect.eventlog.evt) (in module dissect.hypervisor.backup.xva) (in module dissect.target.loaders.phobos) (in module dissect.volume.vss) BlockAllocationTable (class in dissect.hypervisor.disk.vhd) (class in dissect.hypervisor.disk.vhdx) BlockDescriptor (class in dissect.volume.vss) BLOCKED (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) BlockHeader (class in dissect.clfs.c_clfs) BlockList (class in dissect.volume.vss) BlockMap (class in dissect.volume.vss) blocks() (dissect.vmfs.vmfs.FileDescriptor method) BlockStream (class in dissect.vmfs.vmfs) BLUE (dissect.target.helpers.cyber.Color attribute) BM_SETCHECK (in module acquire.acquire.gui.win32) BMAP (class in dissect.eventlog.wevt_object) BN_CLICKED (in module acquire.acquire.gui.win32) BOOL (dissect.eventlog.bxml.BxmlType attribute) boolean (class in flow.record.fieldtypes) BOOLEAN_STATES (in module dissect.cim.c_cim) Boot (class in acquire.acquire.acquire) boot() (dissect.target.plugins.os.windows.log.etl.EtlPlugin method) Bootbanks (class in acquire.acquire.acquire) bootshell() (dissect.target.plugins.os.windows.generic.GenericPlugin method) BootShellRecord (in module dissect.target.plugins.os.windows.generic) BootTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) BOTTOM (acquire.acquire.acquire.ExecutionOrder attribute) bPrefixData (in module dissect.esedb.index) bPrefixNull (in module dissect.esedb.index) bPrefixNullHigh (in module dissect.esedb.index) bPrefixZeroLength (in module dissect.esedb.index) BranchNode (class in dissect.esedb.page) BravePlugin (class in dissect.target.plugins.apps.browser.brave) BrokenIndexError BrokenMftError BrokerReader (class in flow.record.adapter.broker) BrokerWriter (class in flow.record.adapter.broker) BROWSEINFOA (class in acquire.acquire.gui.win32) BrowserCookieRecord (dissect.target.plugins.apps.browser.brave.BravePlugin attribute) (dissect.target.plugins.apps.browser.chrome.ChromePlugin attribute) (dissect.target.plugins.apps.browser.chromium.ChromiumMixin attribute) (dissect.target.plugins.apps.browser.edge.EdgePlugin attribute) (dissect.target.plugins.apps.browser.firefox.FirefoxPlugin attribute) (in module dissect.target.plugins.apps.browser.browser) BrowserDownloadRecord (dissect.target.plugins.apps.browser.brave.BravePlugin attribute) (dissect.target.plugins.apps.browser.chrome.ChromePlugin attribute) (dissect.target.plugins.apps.browser.chromium.ChromiumMixin attribute) (dissect.target.plugins.apps.browser.edge.EdgePlugin attribute) (dissect.target.plugins.apps.browser.firefox.FirefoxPlugin attribute) (dissect.target.plugins.apps.browser.iexplore.InternetExplorerPlugin attribute) (in module dissect.target.plugins.apps.browser.browser) BrowserExtensionRecord (dissect.target.plugins.apps.browser.brave.BravePlugin attribute) (dissect.target.plugins.apps.browser.chrome.ChromePlugin attribute) (dissect.target.plugins.apps.browser.chromium.ChromiumMixin attribute) (dissect.target.plugins.apps.browser.edge.EdgePlugin attribute) (in module dissect.target.plugins.apps.browser.browser) BrowserHistoryRecord (dissect.target.plugins.apps.browser.brave.BravePlugin attribute) (dissect.target.plugins.apps.browser.chrome.ChromePlugin attribute) (dissect.target.plugins.apps.browser.chromium.ChromiumMixin attribute) (dissect.target.plugins.apps.browser.edge.EdgePlugin attribute) (dissect.target.plugins.apps.browser.firefox.FirefoxPlugin attribute) (dissect.target.plugins.apps.browser.iexplore.InternetExplorerPlugin attribute) (in module dissect.target.plugins.apps.browser.browser) BrowserPlugin (class in dissect.target.plugins.apps.browser.browser) BS_AUTOCHECKBOX (in module acquire.acquire.gui.win32) BS_CENTER (in module acquire.acquire.gui.win32) BS_CHECKBOX (in module acquire.acquire.gui.win32) BS_FLAT (in module acquire.acquire.gui.win32) BS_PUSHBUTTON (in module acquire.acquire.gui.win32) BSD (class in acquire.acquire.acquire) (class in dissect.volume.disk.schemes) (class in dissect.volume.disk.schemes.bsd) (dissect.target.plugin.OperatingSystem attribute) bsd_def (in module dissect.volume.disk.schemes.bsd) BsdPlugin (class in dissect.target.plugins.os.unix.bsd._os) BsdProfile (class in acquire.acquire.acquire) bSentinel (in module dissect.esedb.index) bsf() (in module dissect.ntfs.c_ntfs) (in module dissect.vmfs.c_vmfs) btime() (dissect.ffs.ffs.INode method) btime_ns() (dissect.ffs.ffs.INode method) btmp() (dissect.target.plugins.os.unix.log.utmp.UtmpPlugin method) BTMP_GLOB (dissect.target.plugins.os.unix.log.utmp.UtmpPlugin attribute) BtmpRecord (in module dissect.target.plugins.os.unix.log.utmp) BTree (class in dissect.btrfs.tree) (class in dissect.volume.dm.btree) Btrfs (class in dissect.btrfs) (class in dissect.btrfs.btrfs) BTRFS_BLOCK_GROUP (in module dissect.btrfs.c_btrfs) BTRFS_BLOCK_GROUP_PROFILE_MASK (in module dissect.btrfs.c_btrfs) BTRFS_BLOCK_GROUP_RAID1_MASK (in module dissect.btrfs.c_btrfs) BTRFS_BLOCK_GROUP_RAID56_MASK (in module dissect.btrfs.c_btrfs) BTRFS_BLOCK_GROUP_STRIPE_MASK (in module dissect.btrfs.c_btrfs) BTRFS_BLOCK_GROUP_TYPE_MASK (in module dissect.btrfs.c_btrfs), [1] btrfs_def (in module dissect.btrfs.c_btrfs) BTRFS_RAID_ATTRIBUTES (in module dissect.btrfs.c_btrfs) BtrfsFilesystem (class in dissect.target.filesystems.btrfs) BtrfsFilesystemEntry (class in dissect.target.filesystems.btrfs) BtrfsSubvolumeFilesystem (class in dissect.target.filesystems.btrfs) Buffer (class in dissect.etl) (class in dissect.etl.etl) buffer() (dissect.etl.ETL method) (dissect.etl.etl.ETL method) buffer_sectors (dissect.volume.lvm.metadata.IntegritySegment attribute) BUFFER_SIZE (in module acquire.acquire.dynamic.windows.ntdll) (in module dissect.target.helpers.hashutil) BufferedStream (class in dissect.util.stream) BufferFlag (in module dissect.etl.utils) buffers() (dissect.etl.ETL method) (dissect.etl.etl.ETL method) buffers_written (dissect.etl.headers.logfile.LogfileHeader property) BufferType (in module dissect.etl.utils) build_pipe() (in module dissect.target.tools.shell) build_pipe_stdout() (in module dissect.target.tools.shell) BuildProp (class in dissect.target.plugins.os.unix.linux.android._os) BUILTIN_PROPERTIES (in module dissect.cim.c_cim) builtin_property_name (dissect.cim.classes.PropertyReference property) BUILTIN_QUALIFIERS (in module dissect.cim.c_cim) Bxml (class in dissect.eventlog.bxml) BXML_ATTRIBUTE (dissect.eventlog.bxml.BxmlToken attribute) BXML_CLOSE_EMPTY_ELEMENT_TAG (dissect.eventlog.bxml.BxmlToken attribute) BXML_CLOSE_START_ELEMENT_TAG (dissect.eventlog.bxml.BxmlToken attribute) bxml_def (in module dissect.eventlog.bxml) BXML_END (dissect.eventlog.bxml.BxmlToken attribute) BXML_END_ELEMENT (dissect.eventlog.bxml.BxmlToken attribute) BXML_FRAGMENT_HEADER (dissect.eventlog.bxml.BxmlToken attribute) BXML_START_ELEMENT (dissect.eventlog.bxml.BxmlToken attribute) bxml_struct (in module dissect.eventlog.bxml) BXML_TEMPLATE_INSTANCE (dissect.eventlog.bxml.BxmlToken attribute) BXML_TOKEN_CHAR_REFERENCE (dissect.eventlog.bxml.BxmlToken attribute) BXML_TOKEN_ENTITY_REFERENCE (dissect.eventlog.bxml.BxmlToken attribute) BXML_TOKEN_NORMAL_SUBSTITUTION (dissect.eventlog.bxml.BxmlToken attribute) BXML_TOKEN_OPTIONAL_SUBSTITUTION (dissect.eventlog.bxml.BxmlToken attribute) BXML_VALUE (dissect.eventlog.bxml.BxmlToken attribute) BxmlException, [1] BxmlNameReader (class in dissect.eventlog.bxml) BxmlSub (class in dissect.eventlog.bxml) BxmlTag (class in dissect.eventlog.bxml) BxmlTemplateDescriptor (class in dissect.eventlog.bxml) BxmlToken (class in dissect.eventlog.bxml) BxmlType (class in dissect.eventlog.bxml) by_name() (dissect.executable.elf.elf.SectionTable method) (dissect.executable.elf.SectionTable method) by_type() (dissect.executable.elf.elf.SectionTable method) (dissect.executable.elf.elf.SegmentTable method) (dissect.executable.elf.SectionTable method) (dissect.executable.elf.SegmentTable method) bytes (class in flow.record.fieldtypes) BYTES_IN_NUMBER (in module dissect.thumbcache.index) bytes_left() (in module dissect.etl.utils) bytes_per_index_buffer (dissect.ntfs.index.IndexRoot property) bytes_type (in module flow.record.fieldtypes) BytesInteger (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.bytesinteger) BZ2_MAGIC (in module flow.record.base) BZIP2 (dissect.target.tools.dump.utils.Compression attribute) C c_acquire (in module acquire.acquire.crypt) c_ad1 (in module dissect.evidence.ad1) c_adpolicy (in module dissect.target.plugins.os.windows.adpolicy) c_adtev (in module dissect.target.plugins.os.windows.regf.auditpol) c_apm (in module dissect.volume.disk.schemes.apm) c_appdb (in module dissect.target.plugins.os.windows.notifications) c_asdf (in module dissect.evidence.asdf.asdf) c_atop (in module dissect.target.plugins.os.unix.log.atop) c_bag (in module dissect.target.plugins.os.windows.regf.shellbags) c_bam (in module dissect.target.plugins.os.windows.regf.bam) c_bamdef (in module dissect.target.plugins.os.windows.regf.bam) c_blob (in module dissect.target.plugins.os.windows.dpapi.blob) c_bsd (in module dissect.volume.disk.schemes.bsd) c_btrfs (in module dissect.btrfs.c_btrfs) c_cim (in module dissect.cim.c_cim) c_cit (in module dissect.target.plugins.os.windows.regf.cit) c_clfs (in module dissect.clfs.c_clfs) c_common_elf (in module dissect.executable.elf.c_elf) c_ddf (in module dissect.volume.ddf.c_ddf) c_def (in module dissect.hypervisor.util.envelope) (in module dissect.target.plugins.os.windows.adpolicy) c_defender (in module dissect.target.plugins.os.windows.defender) c_dm (in module dissect.volume.dm.c_dm) c_elf_32 (in module dissect.executable.elf.c_elf) c_elf_64 (in module dissect.executable.elf.c_elf) c_envelope (in module dissect.hypervisor.util.envelope) c_esedb (in module dissect.esedb.c_esedb) c_esedb_def (in module dissect.esedb.c_esedb) c_etl (in module dissect.etl.etl) c_etl_definitions (in module dissect.etl.utils) c_etl_global (in module dissect.etl.utils) c_etl_headers (in module dissect.etl.utils) c_evt (in module dissect.eventlog.evt) c_ewf (in module dissect.evidence.ewf) c_exfat (in module dissect.fat.c_exfat) c_exfat_def (in module dissect.fat.c_exfat) c_ext (in module dissect.extfs.c_ext) c_fat (in module dissect.fat.c_fat) c_fat_def (in module dissect.fat.c_fat) c_ffs (in module dissect.ffs.c_ffs) c_global_def (in module dissect.etl.utils) c_gnulocate (in module dissect.target.plugins.os.unix.locate.gnulocate) c_gpt (in module dissect.volume.disk.schemes.gpt) c_hdd (in module dissect.hypervisor.disk.c_hdd) c_hyperv (in module dissect.hypervisor.descriptor.c_hyperv) c_jdb2 (in module dissect.extfs.c_jdb2) c_jffs2 (in module dissect.jffs.c_jffs2) c_journal (in module dissect.target.plugins.os.unix.log.journal) c_lastlog (in module dissect.target.plugins.os.unix.log.lastlog) c_ldm (in module dissect.volume.ldm) c_lnk (in module dissect.shellitem.lnk) (in module dissect.shellitem.lnk.c_lnk) c_lnk_def (in module dissect.shellitem.lnk.c_lnk) c_local (in module dissect.target.plugins.apps.container.docker) c_lvm (in module dissect.volume.lvm.c_lvm2) c_master_key (in module dissect.target.plugins.os.windows.dpapi.master_key) c_mbr (in module dissect.volume.disk.schemes.mbr) c_md (in module dissect.volume.md.c_md) c_mlocate (in module dissect.target.plugins.os.unix.locate.mlocate) c_ntfs (in module dissect.ntfs.c_ntfs) c_ole (in module dissect.ole.c_ole) c_parser (in module dissect.etl.manifest) c_pfwlog (in module dissect.target.plugins.apps.av.trendmicro) c_plocate (in module dissect.target.plugins.os.unix.locate.plocate) c_prefetch (in module dissect.target.plugins.os.windows.prefetch) c_qcow2 (in module dissect.hypervisor.disk.c_qcow2) c_recent_files (in module dissect.target.plugins.os.windows.regf.recentfilecache) c_recent_files_def (in module dissect.target.plugins.os.windows.regf.recentfilecache) c_recyclebin_i (in module dissect.target.plugins.os.windows.recyclebin) c_regf (in module dissect.regf.c_regf) c_regf_def (in module dissect.regf.c_regf) c_rfc4716 (in module dissect.target.helpers.ssh) c_rfc4716_def (in module dissect.target.helpers.ssh) c_sam (in module dissect.target.plugins.os.windows.sam) c_sam_def (in module dissect.target.plugins.os.windows.sam) c_shim (in module dissect.target.plugins.os.windows.regf.shimcache) c_shimdef (in module dissect.target.plugins.os.windows.regf.shimcache) c_sqlite3 (in module dissect.sql.c_sqlite3) c_squashfs (in module dissect.squashfs.c_squashfs) c_thumbcache_index (in module dissect.thumbcache.c_thumbcache) c_thumbcache_index_def (in module dissect.thumbcache.c_thumbcache) c_tz (in module dissect.target.plugins.os.windows.datetime) c_userassist (in module dissect.target.plugins.os.windows.regf.userassist) c_utmp (in module dissect.target.plugins.os.unix.log.utmp) c_vdi (in module dissect.hypervisor.disk.c_vdi) c_vhd (in module dissect.hypervisor.disk.c_vhd) c_vhdx (in module dissect.hypervisor.disk.c_vhdx) c_vma (in module dissect.hypervisor.backup.c_vma) c_vmdk (in module dissect.hypervisor.disk.c_vmdk) c_vmfs (in module dissect.vmfs.c_vmfs) c_vss (in module dissect.volume.vss) c_wevt_headers (in module dissect.eventlog.wevt) c_wim (in module dissect.archive.c_wim) c_xfs (in module dissect.xfs.c_xfs) Cache (class in dissect.target.helpers.cache) CACHE (in module dissect.etl.manifest) CACHE_FILENAME (dissect.target.plugins.apps.browser.iexplore.InternetExplorerPlugin attribute) cache_mode (dissect.volume.lvm.metadata.CachePoolSegment attribute) (dissect.volume.lvm.metadata.CacheSegment attribute) cache_offsets (dissect.thumbcache.index.IndexEntry property) (dissect.thumbcache.IndexEntry property) cache_path() (dissect.target.helpers.cache.Cache method) cache_pool (dissect.volume.lvm.metadata.CacheSegment attribute) CACHE_SIZE (in module dissect.target.helpers.mount) cached_sink_writers() (in module dissect.target.tools.dump.utils) CachePoolSegment (class in dissect.volume.lvm.metadata) CacheSegment (class in dissect.volume.lvm.metadata) CacheWriter (class in dissect.target.helpers.cache) CaddyPlugin (class in dissect.target.plugins.apps.webserver.caddy) CAGENT_TARGETD_ATTRS (in module acquire.acquire.utils) calc_descriptor_hash() (flow.record.base.RecordDescriptor static method) (flow.record.RecordDescriptor static method) calculate_last_activity() (in module dissect.target.plugins.os.unix.generic) calculate_samkey() (dissect.target.plugins.os.windows.sam.SamPlugin method) calculate_timestamp() (dissect.etl.ETL method) (dissect.etl.etl.ETL method) CalendarTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) call() (dissect.target.helpers.cache.Cache method) CALLBACK (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) camel_case_patterns (in module dissect.target.plugins.os.windows.wer) CAN_CYBER (in module dissect.target.helpers.cyber) CAP_AUDIT_CONTROL (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_AUDIT_READ (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_AUDIT_WRITE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_BLOCK_SUSPEND (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_BPF (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_CHECKPOINT_RESTORE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_CHOWN (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_DAC_OVERRIDE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_DAC_READ_SEARCH (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_FOWNER (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_FSETID (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_IPC_LOCK (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_IPC_OWNER (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_KILL (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_LEASE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_LINUX_IMMUTABLE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_MAC_ADMIN (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_MAC_OVERRIDE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_MKNOD (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_NET_ADMIN (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_NET_BIND_SERVICE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_NET_BROADCAST (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_NET_RAW (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_PERFMON (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SETFCAP (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SETGID (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SETPCAP (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SETUID (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_ADMIN (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_BOOT (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_CHROOT (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_MODULE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_NICE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_PACCT (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_PTRACE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_RAWIO (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_RESOURCE (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_TIME (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYS_TTY_CONFIG (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_SYSLOG (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) CAP_WAKE_ALARM (dissect.target.plugins.filesystem.unix.capability.Capabilities attribute) Capabilities (class in dissect.target.plugins.filesystem.unix.capability) capability_binaries() (dissect.target.plugins.filesystem.unix.capability.CapabilityPlugin method) CapabilityPlugin (class in dissect.target.plugins.filesystem.unix.capability) CapabilityRecord (in module dissect.target.plugins.filesystem.unix.capability) CASE (class in dissect.esedb.lcmapstring) case_sensitive (dissect.target.filesystem.RootFilesystem property) cat() (in module dissect.target.tools.fs) Catalog (class in dissect.esedb.table) (class in dissect.volume.vss) CATALOG_BLOCK_SIZE (in module dissect.volume.vss) CATALOG_COLUMNS (dissect.esedb.table.Catalog attribute) CATALOG_ENTRY_SIZE (in module dissect.volume.vss) catch_sigpipe() (in module dissect.target.tools.utils) (in module flow.record.utils) CATEGORIES (dissect.target.plugins.os.windows.regf.shellbags.CONTROL_PANEL_CATEGORY attribute) categorize_plugins() (in module dissect.target.plugins.general.plugins) catroot() (dissect.target.plugins.os.windows.catroot.CatrootPlugin method) CatrootPlugin (class in dissect.target.plugins.os.windows.catroot) CatrootRecord (in module dissect.target.plugins.os.windows.catroot) CB_TIMEFORMAT (in module dissect.target.filesystems.cb) CbFilesystem (class in dissect.target.filesystems.cb) CbFilesystemEntry (class in dissect.target.filesystems.cb) CbLoader (class in dissect.target.loaders.cb) CbRegistry (class in dissect.target.loaders.cb) CbRegistryHive (class in dissect.target.loaders.cb) CbRegistryKey (class in dissect.target.loaders.cb) CbRegistryValue (class in dissect.target.loaders.cb) CcGuid (in module dissect.etl.utils) cd (dissect.cim.cim.Class property) (dissect.cim.cim.Instance property) CDBURN (class in dissect.target.plugins.os.windows.regf.shellbags) Cell (class in dissect.sql.sqlite3) cell() (dissect.regf.regf.RegistryHive method) (dissect.regf.RegistryHive method) (dissect.sql.sqlite3.Page method) cells() (dissect.sql.SQLite3 method) (dissect.sql.sqlite3.Page method) (dissect.sql.sqlite3.SQLite3 method) cg() (dissect.ffs.ffs.INode method) cgbase() (in module dissect.ffs.ffs) cgdata() (in module dissect.ffs.ffs) cgdmin() (in module dissect.ffs.ffs) cgimin() (in module dissect.ffs.ffs) cgmeta() (in module dissect.ffs.ffs) cgsblock() (in module dissect.ffs.ffs) cgstart() (in module dissect.ffs.ffs) cgtod() (in module dissect.ffs.ffs) Chain (class in dissect.ole.ole) chain() (dissect.fat.fat.FAT method) (dissect.ole.OLE method) (dissect.ole.ole.OLE method) ChainStream (class in dissect.ole.ole) CHAN (class in dissect.eventlog.wevt_object) CHAR_TRANSLATION (in module dissect.eventlog.wevtutil) CharType (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.chartype) chdir() (dissect.target.tools.shell.RegistryCli method) (dissect.target.tools.shell.TargetCli method) check_and_set_acquire_args() (in module acquire.acquire.utils) check_and_set_log_args() (in module acquire.acquire.utils) check_compatible() (dissect.target.loaders.cb.CbRegistry method) (dissect.target.loaders.smb.SmbRegistry method) (dissect.target.plugin.NamespacePlugin method) (dissect.target.plugin.OSPlugin method) (dissect.target.plugin.Plugin method) (dissect.target.plugins.apps.av.mcafee.McAfeePlugin method) (dissect.target.plugins.apps.av.sophos.SophosPlugin method) (dissect.target.plugins.apps.av.symantec.SymantecPlugin method) (dissect.target.plugins.apps.av.trendmicro.TrendMicroPlugin method) (dissect.target.plugins.apps.browser.chromium.ChromiumMixin method) (dissect.target.plugins.apps.browser.firefox.FirefoxPlugin method) (dissect.target.plugins.apps.browser.iexplore.InternetExplorerPlugin method) (dissect.target.plugins.apps.container.docker.DockerPlugin method) (dissect.target.plugins.apps.remoteaccess.anydesk.AnydeskPlugin method) (dissect.target.plugins.apps.remoteaccess.teamviewer.TeamviewerPlugin method) (dissect.target.plugins.apps.shell.powershell.PowerShellHistoryPlugin method) (dissect.target.plugins.apps.ssh.openssh.OpenSSHPlugin method) (dissect.target.plugins.apps.ssh.opensshd.SSHServerPlugin method) (dissect.target.plugins.apps.ssh.putty.PuTTYPlugin method) (dissect.target.plugins.apps.vpn.openvpn.OpenVPNPlugin method) (dissect.target.plugins.apps.vpn.wireguard.WireGuardPlugin method) (dissect.target.plugins.apps.webhosting.cpanel.CPanelPlugin method) (dissect.target.plugins.apps.webserver.apache.ApachePlugin method) (dissect.target.plugins.apps.webserver.caddy.CaddyPlugin method) (dissect.target.plugins.apps.webserver.citrix.CitrixWebserverPlugin method) (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin method) (dissect.target.plugins.apps.webserver.nginx.NginxPlugin method) (dissect.target.plugins.child.esxi.ESXiChildTargetPlugin method) (dissect.target.plugins.child.hyperv.HyperVChildTargetPlugin method) (dissect.target.plugins.child.virtuozzo.VirtuozzoChildTargetPlugin method) (dissect.target.plugins.child.vmware_workstation.WorkstationChildTargetPlugin method) (dissect.target.plugins.child.wsl.WSLChildTargetPlugin method) (dissect.target.plugins.filesystem.acquire_handles.OpenHandlesPlugin method) (dissect.target.plugins.filesystem.acquire_hash.AcquireHashPlugin method) (dissect.target.plugins.filesystem.icat.ICatPlugin method) (dissect.target.plugins.filesystem.ntfs.mft.MftPlugin method) (dissect.target.plugins.filesystem.ntfs.mft_timeline.MftTimelinePlugin method) (dissect.target.plugins.filesystem.ntfs.usnjrnl.UsnjrnlPlugin method) (dissect.target.plugins.filesystem.resolver.ResolverPlugin method) (dissect.target.plugins.filesystem.unix.capability.CapabilityPlugin method) (dissect.target.plugins.filesystem.unix.suid.SuidPlugin method) (dissect.target.plugins.filesystem.walkfs.WalkFSPlugin method) (dissect.target.plugins.filesystem.yara.YaraPlugin method) (dissect.target.plugins.general.config.ConfigurationTreePlugin method) (dissect.target.plugins.general.example.ExamplePlugin method) (dissect.target.plugins.general.loaders.LoaderListPlugin method) (dissect.target.plugins.general.osinfo.OSInfoPlugin method) (dissect.target.plugins.general.plugins.PluginListPlugin method) (dissect.target.plugins.general.scrape.ScrapePlugin method) (dissect.target.plugins.general.users.UsersPlugin method) (dissect.target.plugins.os.unix.bsd.osx.user.UserPlugin method) (dissect.target.plugins.os.unix.cronjobs.CronjobPlugin method) (dissect.target.plugins.os.unix.datetime.DateTimePlugin method) (dissect.target.plugins.os.unix.generic.GenericPlugin method) (dissect.target.plugins.os.unix.history.CommandHistoryPlugin method) (dissect.target.plugins.os.unix.linux.cmdline.CmdlinePlugin method) (dissect.target.plugins.os.unix.linux.debian.apt.AptPlugin method) (dissect.target.plugins.os.unix.linux.debian.dpkg.DpkgPlugin method) (dissect.target.plugins.os.unix.linux.environ.EnvironPlugin method) (dissect.target.plugins.os.unix.linux.fortios.generic.GenericPlugin method) (dissect.target.plugins.os.unix.linux.fortios.locale.LocalePlugin method) (dissect.target.plugins.os.unix.linux.iptables.IptablesSavePlugin method) (dissect.target.plugins.os.unix.linux.modules.ModulePlugin method) (dissect.target.plugins.os.unix.linux.netstat.NetstatPlugin method) (dissect.target.plugins.os.unix.linux.proc.ProcPlugin method) (dissect.target.plugins.os.unix.linux.processes.ProcProcesses method) (dissect.target.plugins.os.unix.linux.redhat.yum.YumPlugin method) (dissect.target.plugins.os.unix.linux.services.ServicesPlugin method) (dissect.target.plugins.os.unix.linux.sockets.NetSocketPlugin method) (dissect.target.plugins.os.unix.linux.suse.zypper.ZypperPlugin method) (dissect.target.plugins.os.unix.locale.LocalePlugin method) (dissect.target.plugins.os.unix.locate.gnulocate.GNULocatePlugin method) (dissect.target.plugins.os.unix.locate.mlocate.MLocatePlugin method) (dissect.target.plugins.os.unix.locate.plocate.PLocatePlugin method) (dissect.target.plugins.os.unix.log.atop.AtopPlugin method) (dissect.target.plugins.os.unix.log.audit.AuditPlugin method) (dissect.target.plugins.os.unix.log.auth.AuthPlugin method) (dissect.target.plugins.os.unix.log.journal.JournalPlugin method) (dissect.target.plugins.os.unix.log.lastlog.LastLogPlugin method) (dissect.target.plugins.os.unix.log.messages.MessagesPlugin method) (dissect.target.plugins.os.unix.log.utmp.UtmpPlugin method) (dissect.target.plugins.os.unix.packagemanager.PackageManagerPlugin method) (dissect.target.plugins.os.unix.shadow.ShadowPlugin method) (dissect.target.plugins.os.windows.activitiescache.ActivitiesCachePlugin method) (dissect.target.plugins.os.windows.adpolicy.ADPolicyPlugin method) (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) (dissect.target.plugins.os.windows.catroot.CatrootPlugin method) (dissect.target.plugins.os.windows.cim.CimPlugin method) (dissect.target.plugins.os.windows.clfs.ClfsPlugin method) (dissect.target.plugins.os.windows.datetime.DateTimePlugin method) (dissect.target.plugins.os.windows.defender.MicrosoftDefenderPlugin method) (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin method) (dissect.target.plugins.os.windows.env.EnvironmentVariablePlugin method) (dissect.target.plugins.os.windows.exchange.exchange.ExchangePlugin method) (dissect.target.plugins.os.windows.generic.GenericPlugin method) (dissect.target.plugins.os.windows.lnk.LnkPlugin method) (dissect.target.plugins.os.windows.locale.LocalePlugin method) (dissect.target.plugins.os.windows.log.amcache.AmcacheInstallPlugin method) (dissect.target.plugins.os.windows.log.etl.EtlPlugin method) (dissect.target.plugins.os.windows.log.evt.WindowsEventlogsMixin method) (dissect.target.plugins.os.windows.log.pfro.PfroPlugin method) (dissect.target.plugins.os.windows.log.schedlgu.SchedLgUPlugin method) (dissect.target.plugins.os.windows.notifications.NotificationsPlugin method) (dissect.target.plugins.os.windows.prefetch.PrefetchPlugin method) (dissect.target.plugins.os.windows.recyclebin.RecyclebinPlugin method) (dissect.target.plugins.os.windows.regf.7zip.SevenZipPlugin method) (dissect.target.plugins.os.windows.regf.appxdebugkeys.AppxDebugKeysPlugin method) (dissect.target.plugins.os.windows.regf.auditpol.AuditpolPlugin method) (dissect.target.plugins.os.windows.regf.bam.BamDamPlugin method) (dissect.target.plugins.os.windows.regf.cit.CITPlugin method) (dissect.target.plugins.os.windows.regf.clsid.CLSIDPlugin method) (dissect.target.plugins.os.windows.regf.firewall.FirewallPlugin method) (dissect.target.plugins.os.windows.regf.mru.MRUPlugin method) (dissect.target.plugins.os.windows.regf.muicache.MuiCachePlugin method) (dissect.target.plugins.os.windows.regf.nethist.NethistPlugin method) (dissect.target.plugins.os.windows.regf.recentfilecache.RecentFileCachePlugin method) (dissect.target.plugins.os.windows.regf.regf.RegfPlugin method) (dissect.target.plugins.os.windows.regf.runkeys.RunKeysPlugin method) (dissect.target.plugins.os.windows.regf.shellbags.ShellBagsPlugin method) (dissect.target.plugins.os.windows.regf.shimcache.ShimcachePlugin method) (dissect.target.plugins.os.windows.regf.trusteddocs.TrustedDocumentsPlugin method) (dissect.target.plugins.os.windows.regf.usb.UsbPlugin method) (dissect.target.plugins.os.windows.regf.userassist.UserAssistPlugin method) (dissect.target.plugins.os.windows.registry.RegistryPlugin method) (dissect.target.plugins.os.windows.sam.SamPlugin method) (dissect.target.plugins.os.windows.services.ServicesPlugin method) (dissect.target.plugins.os.windows.sru.SRUPlugin method) (dissect.target.plugins.os.windows.startupinfo.StartupInfoPlugin method) (dissect.target.plugins.os.windows.syscache.SyscachePlugin method) (dissect.target.plugins.os.windows.tasks.TasksPlugin method) (dissect.target.plugins.os.windows.thumbcache.ThumbcachePlugin method) (dissect.target.plugins.os.windows.ual.UalPlugin method) (dissect.target.plugins.os.windows.wer.WindowsErrorReportingPlugin method) (dissect.target.tools.shell.RegistryCli static method) (dissect.target.tools.shell.TargetCmd static method) (dissect.target.tools.shell.UnixConfigTreeCli method) check_dir() (dissect.target.tools.shell.TargetCli method) check_file() (dissect.target.tools.shell.TargetCli method) check_key() (dissect.target.tools.shell.RegistryCli method) check_value() (dissect.target.tools.shell.RegistryCli method) checkbox (acquire.acquire.gui.win32.Win32 attribute) checkpoints() (dissect.sql.sqlite3.WAL method) (dissect.sql.WAL method) checksum_xor() (in module dissect.esedb.c_esedb) child (dissect.ole.ole.DirectoryEntry property) child() (dissect.cim.index.IndexPage method) child_plugins() (in module dissect.target.plugin) children() (dissect.cim.index.IndexPage method) ChildTargetPlugin (class in dissect.target.plugin) ChildTargetRecord (in module dissect.target.helpers.record) chmod() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) choose_folder() (acquire.acquire.gui.win32.Win32 method) choose_folder_button (acquire.acquire.gui.win32.Win32 attribute) ChromePlugin (class in dissect.target.plugins.apps.browser.chrome) CHROMIUM_DOWNLOAD_RECORD_FIELDS (in module dissect.target.plugins.apps.browser.chromium) ChromiumMixin (class in dissect.target.plugins.apps.browser.chromium) ChromiumPlugin (class in dissect.target.plugins.apps.browser.chromium) Chunk (class in dissect.btrfs.stream) CHUNK_SIZE (dissect.target.plugins.os.windows.log.evt.EvtPlugin attribute) (dissect.target.plugins.os.windows.log.evtx.EvtxPlugin attribute) chunk_size (dissect.volume.lvm.metadata.CachePoolSegment attribute) (dissect.volume.lvm.metadata.CacheSegment attribute) (dissect.volume.lvm.metadata.SnapshotSegment attribute) (dissect.volume.lvm.metadata.ThinPoolSegment attribute) CHUNK_SIZE (in module acquire.acquire.tools.decrypter) chunks() (acquire.acquire.tools.decrypter.EncryptedFile method) ChunkStream (class in dissect.btrfs.stream) ci (dissect.cim.cim.Instance property) (dissect.cim.cim.Namespace property) CIM (class in dissect.cim) (class in dissect.cim.cim) cim_def (in module dissect.cim.c_cim) CIM_TYPES (in module dissect.cim.c_cim) CIM_TYPES_MAP (in module dissect.cim.c_cim) CimPlugin (class in dissect.target.plugins.os.windows.cim) CIPHER_ALGORITHMS (in module dissect.target.plugins.os.windows.dpapi.crypto) CIPHER_KEY_SIZES (in module dissect.hypervisor.descriptor.vmx) CipherAlgorithm (class in dissect.target.plugins.os.windows.dpapi.crypto) CIT (class in dissect.target.plugins.os.windows.regf.cit) cit() (dissect.target.plugins.os.windows.regf.cit.CITPlugin method) cit_def (in module dissect.target.plugins.os.windows.regf.cit) CIT_RECORDS (in module dissect.target.plugins.os.windows.regf.cit) CITDPDurationRecord (in module dissect.target.plugins.os.windows.regf.cit) CITDPRecord (in module dissect.target.plugins.os.windows.regf.cit) CITModuleRecord (in module dissect.target.plugins.os.windows.regf.cit) CITPlugin (class in dissect.target.plugins.os.windows.regf.cit) CITPostUpdateUseInfoRecord (in module dissect.target.plugins.os.windows.regf.cit) CITProgramBitmapForegroundRecord (in module dissect.target.plugins.os.windows.regf.cit) CITProgramRecord (in module dissect.target.plugins.os.windows.regf.cit) CITRIX (dissect.target.plugin.OperatingSystem attribute) CITRIX_NETSCALER_BASH_HISTORY_RE (in module dissect.target.plugins.os.unix.bsd.citrix.history) CitrixCommandHistoryPlugin (class in dissect.target.plugins.os.unix.bsd.citrix.history) CitrixPlugin (class in dissect.target.plugins.os.unix.bsd.citrix._os) CitrixWebserverPlugin (class in dissect.target.plugins.apps.webserver.citrix) CITSystemBitmapDisplayPowerRecord (in module dissect.target.plugins.os.windows.regf.cit) CITSystemBitmapDisplayRequestChangeRecord (in module dissect.target.plugins.os.windows.regf.cit) CITSystemBitmapForegroundRecord (in module dissect.target.plugins.os.windows.regf.cit) CITSystemBitmapInputRecord (in module dissect.target.plugins.os.windows.regf.cit) CITSystemBitmapInputTouchRecord (in module dissect.target.plugins.os.windows.regf.cit) CITSystemBitmapUnknownRecord (in module dissect.target.plugins.os.windows.regf.cit) CITSystemRecord (in module dissect.target.plugins.os.windows.regf.cit) CITTelemetryRecord (in module dissect.target.plugins.os.windows.regf.cit) CJK_FIRST (dissect.esedb.lcmapstring.SCRIPT attribute) CJK_LAST (dissect.esedb.lcmapstring.SCRIPT attribute) Class (class in dissect.cim.cim) class_() (dissect.cim.cim.Namespace method) CLASS_FMT (in module dissect.etl.manifest) class_name (dissect.cim.classes.ClassDefinition property) (dissect.cim.classes.ClassInstance property) (dissect.target.helpers.regutil.KeyCollection property) (dissect.target.helpers.regutil.RegfKey property) (dissect.target.helpers.regutil.RegistryKey property) (dissect.target.helpers.regutil.VirtualKey property) class_object (dissect.target.plugin.PluginFunction attribute) ClassDefinition (class in dissect.cim.classes) ClassDefinitionProperty (class in dissect.cim.classes) ClassDefinitionPropertyState (in module dissect.cim.c_cim) classes (dissect.cim.cim.Namespace property) CLASSES (in module dissect.util.plist) ClassInstance (class in dissect.cim.classes) ClassInstanceProperty (class in dissect.cim.classes) ClassInstancePropertyState (in module dissect.cim.c_cim) ClassKey (class in dissect.target.loaders.itunes) clean() (dissect.target.helpers.configutil.ScopeManager method) clean_ips() (dissect.target.helpers.network_managers.NetworkManager static method) CLEANABLE (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) cleaner (dissect.volume.lvm.metadata.CacheSegment attribute) (dissect.volume.lvm.metadata.WriteCacheSegment attribute) clfs() (dissect.target.plugins.os.windows.clfs.ClfsPlugin method) CLFS_CONTROL_RECORD_MAGIC_VALUE (in module dissect.clfs.c_clfs) clfs_def (in module dissect.clfs.c_clfs) ClfsPlugin (class in dissect.target.plugins.os.windows.clfs) ClfsRecord (in module dissect.target.plugins.os.windows.clfs) cli_args (dissect.target.report.ExecutionReport attribute) CLI_ARGS_MODULE (in module acquire.acquire.acquire) client (flow.record.adapter.mongo.MongoReader attribute) (flow.record.adapter.mongo.MongoWriter attribute) client_access() (dissect.target.plugins.os.windows.ual.UalPlugin method) ClientAccessRecord (in module dissect.target.plugins.os.windows.ual) CLOSE (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) close() (acquire.acquire.collector.Collector method) (acquire.acquire.crypt.EncryptedStream method) (acquire.acquire.log.DelayedFileHandler method) (acquire.acquire.outputs.base.Output method) (acquire.acquire.outputs.dir.DirectoryOutput method) (acquire.acquire.outputs.tar.TarOutput method) (acquire.acquire.outputs.zip.ZipOutput method) (dissect.esedb.tools.impacket.ESENT_DB method) (dissect.evidence.asdf.asdf.AsdfWriter method) (dissect.evidence.asdf.AsdfWriter method) (dissect.evidence.asdf.streams.HashedStream method) (dissect.evidence.asdf.streams.SubStreamBase method) (dissect.evidence.tools.asdf.dd.Progress method) (dissect.target.container.Container method) (dissect.target.containers.asdf.AsdfContainer method) (dissect.target.containers.ewf.EwfContainer method) (dissect.target.containers.hdd.HddContainer method) (dissect.target.containers.hds.HdsContainer method) (dissect.target.containers.qcow2.QCow2Container method) (dissect.target.containers.split.SplitContainer method) (dissect.target.containers.vdi.VdiContainer method) (dissect.target.containers.vhd.VhdContainer method) (dissect.target.containers.vhdx.VhdxContainer method) (dissect.target.containers.vmdk.VmdkContainer method) (dissect.target.filesystems.smb.SmbStream method) (dissect.target.helpers.cache.CacheWriter method) (dissect.target.helpers.cache.LineWriter method) (dissect.target.loaders.remote.RemoteStreamConnection method) (dissect.target.tools.dump.utils.JsonLinesWriter method) (dissect.util.stream.AlignedStream method) (flow.record.adapter.AbstractReader method) (flow.record.adapter.AbstractWriter method) (flow.record.adapter.archive.ArchiveWriter method) (flow.record.adapter.avro.AvroReader method) (flow.record.adapter.avro.AvroWriter method) (flow.record.adapter.broker.BrokerReader method) (flow.record.adapter.broker.BrokerWriter method) (flow.record.adapter.csvfile.CsvfileReader method) (flow.record.adapter.csvfile.CsvfileWriter method) (flow.record.adapter.elastic.ElasticReader method) (flow.record.adapter.elastic.ElasticWriter method) (flow.record.adapter.jsonfile.JsonfileReader method) (flow.record.adapter.jsonfile.JsonfileWriter method) (flow.record.adapter.line.LineWriter method) (flow.record.adapter.mongo.MongoReader method) (flow.record.adapter.mongo.MongoWriter method) (flow.record.adapter.split.SplitWriter method) (flow.record.adapter.splunk.SplunkWriter method) (flow.record.adapter.sqlite.SqliteWriter method) (flow.record.adapter.stream.StreamReader method) (flow.record.adapter.stream.StreamWriter method) (flow.record.adapter.text.TextWriter method) (flow.record.adapter.xlsx.XlsxReader method) (flow.record.adapter.xlsx.XlsxWriter method) (flow.record.stream.PathTemplateWriter method) (flow.record.stream.RecordPrinter method) (flow.record.stream.RecordStreamReader method) (flow.record.stream.RecordStreamWriter method) close_handle() (in module acquire.acquire.dynamic.windows.ntdll) CLOSE_WAIT (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) CloseHandle (in module acquire.acquire.dynamic.windows.ntdll) CLOSING (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) clsid (dissect.shellitem.lnk.Lnk property) (dissect.shellitem.lnk.lnk.Lnk property) CLSIDPlugin (class in dissect.target.plugins.os.windows.regf.clsid) CLSIDRecord (in module dissect.target.plugins.os.windows.regf.clsid) CLSIDRecordDescriptor (in module dissect.target.plugins.os.windows.regf.clsid) cluster (dissect.fat.fat.DirectoryEntry property) (dissect.fat.fat.RootDirectory property) cluster_to_sector() (dissect.fat.ExFAT method) (dissect.fat.exfat.ExFAT method) clusters_per_index_buffer (dissect.ntfs.index.IndexRoot property) cmd_cat() (dissect.target.tools.shell.RegistryCli method) (dissect.target.tools.shell.TargetCli method) cmd_enter() (dissect.target.tools.shell.TargetCli method) cmd_file() (dissect.target.tools.shell.TargetCli method) cmd_find() (dissect.target.tools.shell.TargetCli method) cmd_hash() (dissect.target.tools.shell.TargetCli method) cmd_hexdump() (dissect.target.tools.shell.TargetCli method) cmd_less() (dissect.target.tools.shell.TargetCli method) cmd_ls() (dissect.target.tools.shell.RegistryCli method) (dissect.target.tools.shell.TargetCli method) CMD_PREFIX (dissect.target.tools.shell.TargetCmd attribute) cmd_readlink() (dissect.target.tools.shell.TargetCli method) cmd_registry() (dissect.target.tools.shell.TargetCli method) cmd_save() (dissect.target.tools.shell.TargetCli method) cmd_stat() (dissect.target.tools.shell.TargetCli method) cmd_zcat() (dissect.target.tools.shell.TargetCli method) cmd_zless() (dissect.target.tools.shell.TargetCli method) cmdline (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) cmdline() (dissect.target.plugins.os.unix.linux.cmdline.CmdlinePlugin method) CmdlinePlugin (class in dissect.target.plugins.os.unix.linux.cmdline) CmdlineRecord (in module dissect.target.plugins.os.unix.linux.cmdline) cocoatimestamp() (in module dissect.util.ts) CODEPAGE (in module dissect.esedb.c_esedb) codepage() (dissect.target.plugins.os.windows.generic.GenericPlugin method) CODEPAGE_MAP (in module dissect.esedb.c_esedb) codestyle module CodestyleException collapse (dissect.target.helpers.configutil.ParserConfig attribute) (dissect.target.helpers.configutil.ParserOptions attribute) collapse_inverse (dissect.target.helpers.configutil.ParserConfig attribute) (dissect.target.helpers.configutil.ParserOptions attribute) COLLATION (in module dissect.ntfs.c_ntfs) collation_rule (dissect.ntfs.index.IndexRoot property) collect() (acquire.acquire.collector.Collector method) collect_command_output() (acquire.acquire.collector.Collector method) collect_dir() (acquire.acquire.collector.Collector method) collect_file() (acquire.acquire.collector.Collector method) collect_glob() (acquire.acquire.collector.Collector method) collect_hashes() (in module acquire.acquire.hashes) collect_named_objects() (in module acquire.acquire.dynamic.windows.collect) collect_ntfs_secure() (acquire.acquire.acquire.NTFS class method) collect_open_handles() (in module acquire.acquire.dynamic.windows.collect) collect_path() (acquire.acquire.collector.Collector method) collect_symlink() (acquire.acquire.collector.Collector method) collect_usnjrnl() (acquire.acquire.acquire.NTFS class method) Collection (class in dissect.target.target) CollectionReport (class in acquire.acquire.collector) Collector (class in acquire.acquire.collector) Color (class in dissect.target.helpers.cyber) COLOR_BG_BLUE (in module dissect.cstruct.utils) COLOR_BG_CYAN (in module dissect.cstruct.utils) COLOR_BG_GREEN (in module dissect.cstruct.utils) COLOR_BG_PURPLE (in module dissect.cstruct.utils) COLOR_BG_RED (in module dissect.cstruct.utils) COLOR_BG_WHITE (in module dissect.cstruct.utils) COLOR_BG_YELLOW (in module dissect.cstruct.utils) COLOR_BLUE (in module dissect.cstruct.utils) COLOR_CYAN (in module dissect.cstruct.utils) COLOR_GREEN (in module dissect.cstruct.utils) COLOR_NORMAL (in module dissect.cstruct.utils) COLOR_PURPLE (in module dissect.cstruct.utils) COLOR_RED (in module dissect.cstruct.utils) COLOR_WHITE (in module dissect.cstruct.utils) COLOR_YELLOW (in module dissect.cstruct.utils) Column (class in dissect.esedb.table) (class in dissect.sql.sqlite3) column() (dissect.esedb.table.Table method) column_ids() (dissect.esedb.index.Index method) column_names (dissect.esedb.table.Table property) COLUMN_TYPE_MAP (in module dissect.esedb.c_esedb) COLUMN_TYPES (in module dissect.esedb.c_esedb) columns() (dissect.esedb.index.Index method) ColumnType (in module dissect.esedb.c_esedb) comctl32 (in module acquire.acquire.gui.win32) ComHandlerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) COMMAND (acquire.acquire.collector.ArtifactType attribute) command (dissect.target.plugins.os.windows.log.schedlgu.SchedLgU attribute) command() (dissect.target.helpers.targetd.CommandProxy method) COMMAND_HISTORY_ABSOLUTE_PATHS (dissect.target.plugins.os.unix.bsd.citrix.history.CitrixCommandHistoryPlugin attribute) COMMAND_HISTORY_RELATIVE_PATHS (dissect.target.plugins.os.unix.bsd.citrix.history.CitrixCommandHistoryPlugin attribute) (dissect.target.plugins.os.unix.history.CommandHistoryPlugin attribute) COMMAND_INFO (dissect.target.loaders.remote.RemoteStreamConnection attribute) COMMAND_OUTPUT_BASE (acquire.acquire.collector.Collector attribute) COMMAND_QUIT (dissect.target.loaders.remote.RemoteStreamConnection attribute) COMMAND_READ (dissect.target.loaders.remote.RemoteStreamConnection attribute) command_runner() (in module dissect.target.loaders.targetd) commandhistory() (dissect.target.plugins.os.unix.bsd.citrix.history.CitrixCommandHistoryPlugin method) (dissect.target.plugins.os.unix.history.CommandHistoryPlugin method) CommandHistoryPlugin (class in dissect.target.plugins.os.unix.history) CommandHistoryRecord (in module dissect.target.plugins.os.unix.history) commandprocautorun() (dissect.target.plugins.os.windows.generic.GenericPlugin method) CommandProcAutoRunRecord (in module dissect.target.plugins.os.windows.generic) CommandProxy (class in dissect.target.helpers.targetd) comment_example() (in module codestyle) comment_prefixes (dissect.target.helpers.configutil.ParserConfig attribute) (dissect.target.helpers.configutil.ParserOptions attribute) commit_time (dissect.volume.lvm.metadata.IntegritySegment attribute) CommitBlock (class in dissect.extfs.journal) commits() (dissect.extfs.JDB2 method) (dissect.extfs.journal.JDB2 method) commits_all() (dissect.extfs.JDB2 method) (dissect.extfs.journal.JDB2 method) common() (in module dissect.target.helpers.hashutil) COMMON_DIR_COMBINATIONS (acquire.acquire.acquire.History attribute) COMMON_ELEMENTS (in module dissect.target.plugins.apps.vpn.openvpn) (in module dissect.target.plugins.os.windows.log.amcache) COMMON_ELLEMENTS (in module dissect.target.plugins.apps.ssh.ssh) COMMON_SAVE_PATHS (dissect.target.plugins.os.unix.linux.iptables.IptablesSavePlugin attribute) commonpath() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) COMPACT_RECORD_TYPES (in module dissect.target.plugins.filesystem.ntfs.mft) compacted_formatter() (in module dissect.target.plugins.filesystem.ntfs.mft) CompactSystemHeader (class in dissect.etl.headers.system) compile() (dissect.cstruct.Compiler method) (dissect.cstruct.compiler.Compiler method) compile_file() (in module dissect.etl.manifest) COMPILE_TEMPLATE (dissect.cstruct.Compiler attribute) (dissect.cstruct.compiler.Compiler attribute) compile_xml() (in module dissect.etl.manifest) CompiledSelector (class in flow.record.selector) Compiler (class in dissect.cstruct) (class in dissect.cstruct.compiler) complete_enter() (dissect.target.tools.shell.TargetHubCli method) completedefault() (dissect.target.tools.shell.RegistryCli method) (dissect.target.tools.shell.TargetCli method) COMPONENT_ID (dissect.etl.headers.headers.EventProperty attribute) COMPR_2 (dissect.esedb.lcmapstring.CASE attribute) COMPR_4 (dissect.esedb.lcmapstring.CASE attribute) COMPR_6 (dissect.esedb.lcmapstring.CASE attribute) compress() (dissect.squashfs.compression.Compression method) (in module dissect.util.compression.sevenbit) COMPRESSED (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) COMPRESSED_FOLDER (class in dissect.target.plugins.os.windows.regf.shellbags) COMPRESSED_MASK (in module dissect.util.compression.lznt1) CompressedRunlistStream (class in dissect.ntfs.stream) CompressedStream (class in dissect.archive.wim) (class in dissect.evidence.asdf.streams) Compression (class in dissect.squashfs.compression) (class in dissect.target.tools.dump.utils) compression (dissect.btrfs.stream.Extent attribute) (dissect.target.tools.dump.state.DumpState attribute) COMPRESSION_FORMAT_DEFAULT (in module dissect.ntfs.c_ntfs) COMPRESSION_FORMAT_LZNT1 (in module dissect.ntfs.c_ntfs) COMPRESSION_FORMAT_NONE (in module dissect.ntfs.c_ntfs) COMPRESSION_SCHEME (in module dissect.esedb.c_esedb) COMPRESSION_TO_EXT (in module dissect.target.tools.dump.utils) compression_unit (dissect.ntfs.attr.AttributeHeader property) (dissect.ntfs.AttributeHeader property) CONFIG (in module acquire.acquire.acquire) config() (dissect.hypervisor.backup.vma.VMA method) (dissect.target.plugins.apps.ssh.opensshd.SSHServerPlugin method) (dissect.target.plugins.apps.vpn.openvpn.OpenVPNPlugin method) (dissect.target.plugins.apps.vpn.wireguard.WireGuardPlugin method) CONFIG_COMMENT_SPLIT_REGEX (in module dissect.target.plugins.apps.vpn.openvpn) CONFIG_CRT (dissect.target.loaders.remote.RemoteStreamConnection attribute) config_globs (dissect.target.plugins.apps.vpn.openvpn.OpenVPNPlugin attribute) CONFIG_GLOBS (dissect.target.plugins.apps.vpn.wireguard.WireGuardPlugin attribute) CONFIG_KEY (dissect.target.loaders.remote.RemoteStreamConnection attribute) CONFIG_MAP (in module dissect.target.helpers.configutil) CONFIG_NAME (in module dissect.target.helpers.config) ConfigNode (class in dissect.target.plugins.os.unix.linux.fortios._os) configs() (dissect.hypervisor.backup.vma.VMA method) configstore() (dissect.target.plugins.os.unix.esxi._os.ESXiPlugin method) Configuration (class in dissect.volume.raid.raid) ConfigurationEntry (class in dissect.target.filesystems.config) ConfigurationFilesystem (class in dissect.target.filesystems.config) ConfigurationParser (class in dissect.target.helpers.configutil) ConfigurationParsingError ConfigurationTreePlugin (class in dissect.target.plugins.general.config) configure() (dissect.target.loaders.remote.RemoteStreamConnection static method) configure_generic_arguments() (in module dissect.target.tools.utils) configure_logging() (in module dissect.target.tools.logging) congestion_window (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) connect() (dissect.target.loaders.remote.RemoteStreamConnection method) CONNECTED (dissect.target.plugins.os.unix.linux.proc.Sockets.SocketStateType attribute) CONSOLE_FE_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) CONSOLE_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) ConsoleHostHistoryRecord (in module dissect.target.plugins.apps.shell.powershell) construct_public_key() (in module dissect.target.plugins.apps.ssh.putty) consume() (dissect.cstruct.expression.ExpressionTokenizer method) (dissect.cstruct.parser.TokenConsumer method) ConsumerBindingRecord (in module dissect.target.plugins.os.windows.cim) consumerbindings() (dissect.target.plugins.os.windows.cim.CimPlugin method) Container (class in dissect.clfs.container) (class in dissect.target.container) (in module dissect.clfs.blf) ContainerAppcompatRecord (in module dissect.target.plugins.os.windows.amcache) ContainerError CONTAINERS (in module dissect.target.container) containers() (dissect.target.plugins.apps.container.docker.DockerPlugin method) contains() (dissect.evidence.asdf.asdf.AsdfSnapshot method) (dissect.evidence.asdf.AsdfSnapshot method) (dissect.evidence.AsdfSnapshot method) contents (dissect.executable.elf.elf.Segment property) (dissect.executable.elf.Segment property) (dissect.target.plugins.os.unix.linux.proc.Environ attribute) contents() (dissect.executable.elf.elf.Section method) (dissect.executable.elf.Section method) Context (in module dissect.clfs.blf) CONTROL_PANEL (class in dissect.target.plugins.os.windows.regf.shellbags) CONTROL_PANEL_CATEGORY (class in dissect.target.plugins.os.windows.regf.shellbags) CONTROL_PANEL_CPL_FILE (class in dissect.target.plugins.os.windows.regf.shellbags) control_records() (dissect.clfs.blf.BLF method) ControllerData (class in dissect.volume.ddf.ddf) ControlRecord (class in dissect.clfs.blf) CONTROLSET_REGEX (in module dissect.target.plugins.os.windows.registry) controlsets (dissect.target.plugins.os.windows.registry.RegistryPlugin property) convert_day_num_to_date() (in module dissect.esedb.tools.ual) convert_ports() (in module dissect.target.plugins.apps.container.docker) convert_timestamp() (in module dissect.target.plugins.apps.container.docker) cookies() (dissect.target.plugins.apps.browser.brave.BravePlugin method) (dissect.target.plugins.apps.browser.chrome.ChromePlugin method) (dissect.target.plugins.apps.browser.chromium.ChromiumMixin method) (dissect.target.plugins.apps.browser.chromium.ChromiumPlugin method) (dissect.target.plugins.apps.browser.edge.EdgePlugin method) (dissect.target.plugins.apps.browser.firefox.FirefoxPlugin method) (dissect.target.plugins.apps.browser.iexplore.WebCache method) copy() (dissect.target.helpers.fsutil.stat_result class method) copy_block() (dissect.evidence.asdf.asdf.AsdfWriter method) (dissect.evidence.asdf.AsdfWriter method) copy_bytes() (dissect.evidence.asdf.asdf.AsdfWriter method) (dissect.evidence.asdf.AsdfWriter method) copy_cstruct() (in module dissect.executable.elf.c_elf) copy_runlist() (dissect.evidence.asdf.asdf.AsdfWriter method) (dissect.evidence.asdf.AsdfWriter method) copy_stream() (in module dissect.evidence.tools.asdf.dd) CopyHistoryRecord (in module dissect.target.plugins.os.windows.regf.7zip) CorruptDataError count (dissect.eventlog.wevtutil.WevtutilWrapper attribute) count_contiguous_subclusters() (in module dissect.hypervisor.disk.qcow2) cow_store (dissect.volume.lvm.metadata.SnapshotSegment attribute) COWD_MAGIC (in module dissect.hypervisor.disk.c_vmdk) cp() (in module dissect.target.tools.fs) CPANEL_LASTLOGIN (in module dissect.target.plugins.apps.webhosting.cpanel) CPANEL_LASTLOGIN_PATTERN (in module dissect.target.plugins.apps.webhosting.cpanel) CPANEL_LOGS_PATH (in module dissect.target.plugins.apps.webhosting.cpanel) CPanelLastloginRecord (in module dissect.target.plugins.apps.webhosting.cpanel) CPanelPlugin (class in dissect.target.plugins.apps.webhosting.cpanel) CPIO_MAGIC_CRC (in module dissect.util.cpio) CPIO_MAGIC_NEW (in module dissect.util.cpio) CPIO_MAGIC_OLD (in module dissect.util.cpio) CpioFile() (in module dissect.util.cpio) CpioFilesystem (class in dissect.target.filesystems.cpio) CpioInfo (class in dissect.util.cpio) CPU_FREQ (dissect.etl.headers.logfile.ReservedFlags attribute) cpu_speed_in_MHz (dissect.etl.headers.logfile.LogfileHeader property) cpu_threads (dissect.volume.lvm.metadata.VdoPoolSegment attribute) crc32_filobj() (in module dissect.evidence.tools.asdf.verify) crc32c() (in module dissect.util.crc32c) Crc32Stream (class in dissect.evidence.asdf.streams) CRC_SIZE (in module dissect.util.compression.xz) CRCMismatchException create() (dissect.target.loaders.profile.ProfileOSPlugin class method) (dissect.target.loaders.res.ResOSPlugin class method) (dissect.target.plugin.OSPlugin class method) (dissect.target.plugins.general.default.DefaultPlugin class method) (dissect.target.plugins.os.unix._os.UnixPlugin class method) (dissect.target.plugins.os.unix.bsd.citrix._os.CitrixPlugin class method) (dissect.target.plugins.os.unix.bsd.ios._os.IOSPlugin class method) (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin class method) (dissect.target.plugins.os.unix.esxi._os.ESXiPlugin class method) (dissect.target.plugins.os.unix.linux.android._os.AndroidPlugin class method) (dissect.target.plugins.os.unix.linux.fortios._os.FortiOSPlugin class method) (dissect.target.plugins.os.windows._os.WindowsPlugin class method) create_argument_parser() (in module acquire.acquire.utils) (in module dissect.thumbcache.tools.utils) create_cipher() (dissect.target.loaders.itunes.FileInfo method) create_cli() (in module dissect.target.tools.shell) create_config() (dissect.target.helpers.network_managers.Template method) create_descriptor_table() (in module flow.record.adapter.sqlite) create_extended_descriptor() (in module dissect.target.helpers.record) create_map() (dissect.eventlog.bxml.Template method) create_parser() (dissect.target.helpers.configutil.ParserConfig method) create_record() (in module dissect.target.plugins.os.windows.log.amcache) create_records() (dissect.target.plugins.os.windows.regf.clsid.CLSIDPlugin method) create_sink() (dissect.target.tools.dump.state.DumpState method) create_state() (in module dissect.target.tools.dump.state) creation_host (dissect.volume.lvm.metadata.LogicalVolume attribute) creation_time (dissect.hypervisor.backup.vma.VMA property) (dissect.ntfs.attr.FileName property) (dissect.ntfs.attr.StandardInformation property) (dissect.target.plugins.os.windows.regf.shellbags.MTP_FILE_ENTRY property) (dissect.target.plugins.os.windows.regf.shellbags.SHITEM property) (dissect.volume.lvm.metadata.HistoricalLogicalVolume attribute) (dissect.volume.lvm.metadata.LogicalVolume attribute) creation_time() (dissect.archive.wim.DirectoryEntry method) creation_time_ns (dissect.ntfs.attr.FileName property) (dissect.ntfs.attr.StandardInformation property) creation_time_ns() (dissect.archive.wim.DirectoryEntry method) creator_back_trace_index (acquire.acquire.dynamic.windows.types.SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX property) CredSystem (class in dissect.target.plugins.os.windows.dpapi.master_key) CRIM (class in dissect.eventlog) (class in dissect.eventlog.wevt) CritSecGuid (in module dissect.etl.utils) CronjobPlugin (class in dissect.target.plugins.os.unix.cronjobs) CronjobRecord (in module dissect.target.plugins.os.unix.cronjobs) cronjobs() (dissect.target.plugins.os.unix.cronjobs.CronjobPlugin method) crop_metadata (dissect.volume.lvm.metadata.ThinPoolSegment attribute) crtime (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.xfs.xfs.INode property) crtime_ns (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.xfs.xfs.INode property) crypt_session_key_type1() (in module dissect.target.plugins.os.windows.dpapi.crypto) crypt_session_key_type2() (in module dissect.target.plugins.os.windows.dpapi.crypto) CS_HREDRAW (in module acquire.acquire.gui.win32) CS_VREDRAW (in module acquire.acquire.gui.win32) cstruct (class in dissect.cstruct) (class in dissect.cstruct.cstruct) CStyleParser (class in dissect.cstruct.parser) CSV_COLUMNS (in module acquire.acquire.hashes) CsvfileReader (class in flow.record.adapter.csvfile) CsvfileWriter (class in flow.record.adapter.csvfile) ctime (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.fat.fat.DirectoryEntry property) (dissect.fat.fat.RootDirectory property) (dissect.xfs.xfs.INode property) ctime() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.vmfs.vmfs.FileDescriptor method) ctime_ns (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.xfs.xfs.INode property) ctime_ns() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) ctype (dissect.cim.cim.Property property) ctype() (dissect.esedb.table.Column method) ctypes() (in module dissect.cstruct) (in module dissect.cstruct.cstruct) ctypes_type() (in module dissect.cstruct) (in module dissect.cstruct.cstruct) ctz() (in module dissect.hypervisor.disk.c_qcow2) current_offset (dissect.eventlog.bxml.Bxml property) CURRENT_VERSION_KEY (dissect.target.plugins.os.windows._os.WindowsPlugin attribute) Cursor (class in dissect.btrfs.tree) (class in dissect.esedb.cursor) cursor() (dissect.btrfs.tree.BTree method) custom() (in module dissect.target.helpers.hashutil) custom_obj_renderer() (in module dissect.target.tools.logging) CW_USEDEFAULT (in module acquire.acquire.gui.win32) cwd() (dissect.target.helpers.compat.path_310.TargetPath class method) (dissect.target.helpers.compat.path_311.TargetPath class method) (dissect.target.helpers.compat.path_312.TargetPath class method) (dissect.target.helpers.compat.path_39.TargetPath class method) CYAN (dissect.target.helpers.cyber.Color attribute) cyber() (in module dissect.target.helpers.cyber) cyber_print() (in module dissect.target.helpers.cyber) CyberIO (class in dissect.target.helpers.cyber) CyberLoader (class in dissect.target.loaders.cyber) cylinder_group() (dissect.ffs.FFS method) (dissect.ffs.ffs.FFS method) cylinder_groups() (dissect.ffs.FFS method) (dissect.ffs.ffs.FFS method) CylinderGroup (class in dissect.ffs.ffs) CYRILLIC (dissect.esedb.lcmapstring.SCRIPT attribute) D D (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) DailyTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) DARWIN_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) data (dissect.etl.Buffer property) (dissect.etl.etl.Buffer property) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) (dissect.regf.regf.KeyValue property) (dissect.sql.sqlite3.Cell property) (dissect.sql.sqlite3.WALFrame property) (dissect.thumbcache.thumbcache_file.ThumbcacheEntry property) (dissect.thumbcache.ThumbcacheEntry property) (dissect.volume.lvm.metadata.CachePoolSegment attribute) (dissect.volume.lvm.metadata.VdoPoolSegment attribute) data() (dissect.btrfs.tree.Cursor method) (dissect.cim.objects.DataPage method) (dissect.ntfs.attr.Attribute method) (dissect.ntfs.attr.AttributeHeader method) (dissect.ntfs.Attribute method) (dissect.ntfs.AttributeHeader method) (dissect.ntfs.index.IndexEntry method) (dissect.ntfs.IndexEntry method) (dissect.target.loaders.cb.CbRegistryKey method) (dissect.target.plugins.os.windows.regf.cit.CIT method) data_block() (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) DATA_CLUSTER_MAX (in module dissect.fat.c_fat) DATA_CLUSTER_MIN (in module dissect.fat.c_fat) data_copies (dissect.volume.lvm.metadata.RAIDSegment attribute) (dissect.volume.lvm.metadata.Segment attribute) data_extents (dissect.xfs.xfs.INode property) data_id (dissect.cim.index.Key property) (dissect.volume.lvm.metadata.CacheSegment attribute) data_len (dissect.volume.lvm.metadata.CacheSegment attribute) data_length (dissect.cim.index.Key property) data_offset (dissect.etl.Buffer property) (dissect.etl.etl.Buffer property) (dissect.volume.lvm.metadata.RAIDSegment attribute) data_offset() (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) data_page (dissect.cim.index.Key property) DATA_PAGE_SIZE (in module dissect.cim.c_cim) data_sectors (dissect.volume.lvm.metadata.IntegritySegment attribute) data_size (dissect.etl.headers.headers.Header property) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) (dissect.target.plugins.os.windows.regf.shellbags.EXTENSION_BLOCK property) data_start (dissect.volume.lvm.metadata.CacheSegment attribute) data_stripes (dissect.btrfs.stream.Chunk attribute) datafork() (dissect.xfs.xfs.INode method) DataPage (class in dissect.cim.objects) DataRegion (class in dissect.cim.classes) dataruns() (dissect.extfs.extfs.INode method) (dissect.extfs.INode method) (dissect.fat.fat.DirectoryEntry method) (dissect.fat.fat.RootDirectory method) (dissect.ffs.ffs.INode method) (dissect.ntfs.attr.Attribute method) (dissect.ntfs.attr.AttributeHeader method) (dissect.ntfs.Attribute method) (dissect.ntfs.AttributeHeader method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.ntfs.util.AttributeCollection method) (dissect.xfs.xfs.INode method) DataStream (class in dissect.jffs.jffs2) datetime (class in flow.record.fieldtypes) DateTimePlugin (class in dissect.target.plugins.os.unix.datetime) (class in dissect.target.plugins.os.windows.datetime) db_insert_record() (in module flow.record.adapter.sqlite) dbe_type (dissect.target.plugins.os.unix.locate.mlocate.MLocate attribute) DbgPrintGuid (in module dissect.etl.utils) dbtofsb() (in module dissect.ffs.ffs) DDF (class in dissect.volume.ddf.ddf) ddf (in module dissect.target.volume) ddf_def (in module dissect.volume.ddf.c_ddf) DDFConfiguration (class in dissect.volume.ddf.ddf) DDFError DDFPhysicalDisk (class in dissect.volume.ddf.ddf) DDFVirtualDisk (class in dissect.volume.ddf.ddf) DdfVolumeSystem (class in dissect.target.volumes.ddf) DebianPlugin (class in dissect.target.plugins.os.unix.linux.debian._os) DEBUG (in module dissect.volume.vss) DECADE (in module dissect.volume.ddf.ddf) decode() (dissect.util.compression.lzxpress_huffman.BitString method) decode_bit() (in module dissect.esedb.c_esedb) decode_extent() (in module dissect.btrfs.stream) decode_guid() (in module dissect.esedb.c_esedb) decode_name() (in module dissect.regf.regf) (in module dissect.target.plugins.os.windows.regf.cit) decode_rfc4716() (in module dissect.target.helpers.ssh) decode_text() (in module dissect.esedb.c_esedb) decode_value() (dissect.target.plugins.os.unix.log.journal.JournalFile method) decode_varint() (in module dissect.target.helpers.protobuf) DECOLOR (in module dissect.ole.c_ole) decompose() (dissect.cstruct.FlagInstance method) (dissect.cstruct.types.flag.FlagInstance method) (dissect.cstruct.types.FlagInstance method) decompress() (dissect.squashfs.compression.Compression method) (dissect.squashfs.compression.NativeLZ4 method) (dissect.squashfs.compression.NativeLZMA method) (dissect.squashfs.compression.NativeLZO method) (dissect.squashfs.compression.NativeXZ method) (dissect.squashfs.compression.NativeZlib method) (dissect.squashfs.compression.NativeZSTD method) (dissect.squashfs.compression.PythonLZ4 method) (dissect.squashfs.compression.PythonLZO method) (dissect.target.plugins.os.unix.log.atop.AtopFile method) (in module dissect.esedb.compression) (in module dissect.util.compression.lz4) (in module dissect.util.compression.lznt1) (in module dissect.util.compression.lzo) (in module dissect.util.compression.lzxpress) (in module dissect.util.compression.lzxpress_huffman) (in module dissect.util.compression.sevenbit) decompress_size() (in module dissect.esedb.compression) DECOMPRESSOR_MAP (in module dissect.archive.c_wim) decrypt() (dissect.hypervisor.util.envelope.Envelope method) (dissect.target.plugins.os.windows.dpapi.blob.Blob method) (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm method) DECRYPT_CHUNK_SIZE (in module dissect.hypervisor.util.envelope) decrypt_header() (in module acquire.acquire.tools.decrypter) decrypt_password() (in module dissect.target.plugins.os.unix.linux.fortios._os) decrypt_rootfs() (in module dissect.target.plugins.os.unix.linux.fortios._os) decrypt_single_hash() (in module dissect.target.plugins.os.windows.sam) decrypt_system_blob() (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin method) decrypt_with_hash() (dissect.target.plugins.os.windows.dpapi.master_key.MasterKey method) (dissect.target.plugins.os.windows.dpapi.master_key.MasterKeyFile method) decrypt_with_hash_10() (dissect.target.plugins.os.windows.dpapi.master_key.MasterKey method) decrypt_with_hmac() (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm method) decrypt_with_key() (dissect.target.plugins.os.windows.dpapi.master_key.MasterKey method) (dissect.target.plugins.os.windows.dpapi.master_key.MasterKeyFile method) decrypt_with_password() (dissect.target.plugins.os.windows.dpapi.master_key.MasterKey method) (dissect.target.plugins.os.windows.dpapi.master_key.MasterKeyFile method) decrypted (dissect.target.plugins.os.windows.dpapi.master_key.MasterKeyFile property) DEF_CSTYLE (dissect.cstruct.cstruct attribute) (dissect.cstruct.cstruct.cstruct attribute) DEF_LEGACY (dissect.cstruct.cstruct attribute) (dissect.cstruct.cstruct.cstruct attribute) defang() (in module flow.record.fieldtypes) DEFAULT (acquire.acquire.acquire.BsdProfile attribute) (acquire.acquire.acquire.ESXiProfile attribute) (acquire.acquire.acquire.ExecutionOrder attribute) (acquire.acquire.acquire.LinuxProfile attribute) (acquire.acquire.acquire.OSXProfile attribute) (acquire.acquire.acquire.VolatileProfile attribute) (acquire.acquire.acquire.WindowsProfile attribute) Default (class in dissect.target.helpers.configutil) default() (dissect.cstruct.Array method) (dissect.cstruct.BaseType method) (dissect.cstruct.BytesInteger method) (dissect.cstruct.CharType method) (dissect.cstruct.Enum method) (dissect.cstruct.PackedType method) (dissect.cstruct.RawType method) (dissect.cstruct.Structure method) (dissect.cstruct.types.Array method) (dissect.cstruct.types.base.Array method) (dissect.cstruct.types.base.BaseType method) (dissect.cstruct.types.base.RawType method) (dissect.cstruct.types.BaseType method) (dissect.cstruct.types.BytesInteger method) (dissect.cstruct.types.bytesinteger.BytesInteger method) (dissect.cstruct.types.CharType method) (dissect.cstruct.types.chartype.CharType method) (dissect.cstruct.types.Enum method) (dissect.cstruct.types.enum.Enum method) (dissect.cstruct.types.PackedType method) (dissect.cstruct.types.packedtype.PackedType method) (dissect.cstruct.types.RawType method) (dissect.cstruct.types.Structure method) (dissect.cstruct.types.structure.Structure method) (dissect.cstruct.types.WcharType method) (dissect.cstruct.types.wchartype.WcharType method) (dissect.cstruct.WcharType method) (dissect.esedb.table.Column method) (dissect.target.tools.shell.TargetCmd method) (dissect.target.tools.shell.TargetHubCli method) (flow.record.base.FieldType class method) (flow.record.FieldType class method) (flow.record.fieldtypes.digest class method) (flow.record.fieldtypes.FieldType class method) (flow.record.fieldtypes.typedlist class method) default_array() (dissect.cstruct.BaseType method) (dissect.cstruct.BytesInteger method) (dissect.cstruct.CharType method) (dissect.cstruct.Enum method) (dissect.cstruct.PackedType method) (dissect.cstruct.types.base.BaseType method) (dissect.cstruct.types.BaseType method) (dissect.cstruct.types.BytesInteger method) (dissect.cstruct.types.bytesinteger.BytesInteger method) (dissect.cstruct.types.CharType method) (dissect.cstruct.types.chartype.CharType method) (dissect.cstruct.types.Enum method) (dissect.cstruct.types.enum.Enum method) (dissect.cstruct.types.PackedType method) (dissect.cstruct.types.packedtype.PackedType method) (dissect.cstruct.types.WcharType method) (dissect.cstruct.types.wchartype.WcharType method) (dissect.cstruct.WcharType method) DEFAULT_ASN_DB (in module flow.record.tools.geoip) DEFAULT_BLOCK_SIZE (in module dissect.evidence.asdf.asdf) DEFAULT_CHUNK_SIZE (in module dissect.archive.wim) DEFAULT_CITY_DB (in module flow.record.tools.geoip) DEFAULT_CLUSTER_SIZE (in module dissect.ntfs.c_ntfs) DEFAULT_CONFIG_PATHS (dissect.target.plugins.apps.webserver.apache.ApachePlugin attribute) DEFAULT_ELEMENTS (in module dissect.target.plugins.os.unix.linux.services) DEFAULT_EXTENSIONS (acquire.acquire.acquire.FileHashes attribute) DEFAULT_FILE_FILTERS (acquire.acquire.acquire.FileHashes attribute) DEFAULT_HASH_FUNCS (acquire.acquire.acquire.FileHashes attribute) DEFAULT_INDEX_SIZE (in module dissect.ntfs.c_ntfs) DEFAULT_LOG_DIRS (dissect.target.plugins.apps.webserver.apache.ApachePlugin attribute) DEFAULT_LOG_PATHS (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin attribute) DEFAULT_MAX_SIZE (dissect.target.plugins.filesystem.yara.YaraPlugin attribute) DEFAULT_PATHS (acquire.acquire.acquire.FileHashes attribute) DEFAULT_RECORD_COUNT (in module flow.record.adapter.split) DEFAULT_RECORD_SIZE (in module dissect.ntfs.c_ntfs) DEFAULT_SECTOR_SIZE (in module dissect.ntfs.c_ntfs) (in module dissect.volume.ddf.c_ddf) DEFAULT_SUFFIX_LENGTH (in module flow.record.adapter.split) DEFAULT_TEMPLATE (flow.record.stream.PathTemplateWriter attribute) DEFAULT_TOP_GUID (in module dissect.hypervisor.disk.hdd) DEFAULT_TS_LOG_FORMAT (in module dissect.target.plugins.os.unix.log.messages) default_value (dissect.cim.cim.Property property) (dissect.cim.classes.ClassInstanceProperty property) DefaultMissing (class in flow.record.adapter.text) DefaultPlugin (class in dissect.target.plugins.general.default) defender_def (in module dissect.target.plugins.os.windows.defender) DEFENDER_EVTX_FIELDS (in module dissect.target.plugins.os.windows.defender) DEFENDER_EXCLUSION_KEY (in module dissect.target.plugins.os.windows.defender) DEFENDER_KNOWN_DETECTION_TYPES (in module dissect.target.plugins.os.windows.defender) DEFENDER_LOG_DIR (in module dissect.target.plugins.os.windows.defender) DEFENDER_LOG_FILENAME_GLOB (in module dissect.target.plugins.os.windows.defender) DEFENDER_QUARANTINE_DIR (in module dissect.target.plugins.os.windows.defender) DEFENDER_QUARANTINE_RC4_KEY (in module dissect.target.plugins.os.windows.defender) DefenderExclusionRecord (in module dissect.target.plugins.os.windows.defender) DefenderFileQuarantineRecord (in module dissect.target.plugins.os.windows.defender) DefenderLogRecord (in module dissect.target.plugins.os.windows.defender) DefenderQuarantineRecord (in module dissect.target.plugins.os.windows.defender) definition() (flow.record.base.RecordDescriptor method) (flow.record.RecordDescriptor method) DelayedFileHandler (class in acquire.acquire.log) DELEGATE (class in dissect.target.plugins.os.windows.regf.shellbags) DELEGATE_ITEM_IDENTIFIER (in module dissect.target.plugins.os.windows.regf.shellbags) DELETABLE (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) dereference() (dissect.cstruct.PointerInstance method) (dissect.cstruct.types.pointer.PointerInstance method) (dissect.cstruct.types.PointerInstance method) (dissect.ntfs.index.IndexEntry method) (dissect.ntfs.IndexEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) derivation (dissect.cim.cim.Class property) derive_key() (dissect.target.loaders.itunes.ITunesBackup method) (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm method) derive_password_hash() (in module dissect.target.plugins.os.windows.dpapi.crypto) DESC (acquire.acquire.acquire.ActiveDirectory attribute) (acquire.acquire.acquire.ActivitiesCache attribute) (acquire.acquire.acquire.Appcompat attribute) (acquire.acquire.acquire.AV attribute) (acquire.acquire.acquire.BITS attribute) (acquire.acquire.acquire.Bootbanks attribute) (acquire.acquire.acquire.DHCP attribute) (acquire.acquire.acquire.DNS attribute) (acquire.acquire.acquire.Drivers attribute) (acquire.acquire.acquire.ESXi attribute) (acquire.acquire.acquire.ETL attribute) (acquire.acquire.acquire.EventLogs attribute) (acquire.acquire.acquire.Exchange attribute) (acquire.acquire.acquire.FileHashes attribute) (acquire.acquire.acquire.History attribute) (acquire.acquire.acquire.IIS attribute) (acquire.acquire.acquire.Misc attribute) (acquire.acquire.acquire.Module attribute) (acquire.acquire.acquire.Netstat attribute) (acquire.acquire.acquire.NTFS attribute) (acquire.acquire.acquire.OpenHandles attribute) (acquire.acquire.acquire.OSX attribute) (acquire.acquire.acquire.OSXApplicationsInfo attribute) (acquire.acquire.acquire.PCA attribute) (acquire.acquire.acquire.PowerShell attribute) (acquire.acquire.acquire.Prefetch attribute) (acquire.acquire.acquire.Proc attribute) (acquire.acquire.acquire.QuarantinedFiles attribute) (acquire.acquire.acquire.Recents attribute) (acquire.acquire.acquire.RecycleBin attribute) (acquire.acquire.acquire.Registry attribute) (acquire.acquire.acquire.RemoteAccess attribute) (acquire.acquire.acquire.Startup attribute) (acquire.acquire.acquire.Sys attribute) (acquire.acquire.acquire.Syscache attribute) (acquire.acquire.acquire.ThumbnailCache attribute) (acquire.acquire.acquire.VMFS attribute) (acquire.acquire.acquire.WBEM attribute) (acquire.acquire.acquire.WebHosting attribute) (acquire.acquire.acquire.WER attribute) (acquire.acquire.acquire.WinArpCache attribute) (acquire.acquire.acquire.WinDnsClientCache attribute) (acquire.acquire.acquire.WindowsNotifications attribute) (acquire.acquire.acquire.WinMemDump attribute) (acquire.acquire.acquire.WinMemFiles attribute) (acquire.acquire.acquire.WinProcEnv attribute) (acquire.acquire.acquire.WinProcesses attribute) (acquire.acquire.acquire.WinRDPSessions attribute) descendants (dissect.volume.lvm.metadata.HistoricalLogicalVolume attribute) DESCRIPTIONS (in module dissect.target.helpers.shell_folder_ids) Descriptor (class in dissect.hypervisor.disk.hdd) descriptor (dissect.etl.headers.event.EventHeader property) descriptor() (dissect.vmfs.vmfs.FileDescriptor method) descriptor_hash (flow.record.base.RecordDescriptor property) (flow.record.RecordDescriptor property) DESCRIPTOR_MASK (dissect.eventlog.bxml.BxmlTemplateDescriptor attribute) descriptor_to_schema() (in module flow.record.adapter.avro) DescriptorBlock (class in dissect.extfs.journal) DescriptorBlockTag (class in dissect.extfs.journal) descriptors() (dissect.ntfs.Secure method) (dissect.ntfs.secure.Secure method) descs (flow.record.stream.RecordStreamReader attribute) DESKTOP (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) DEST_DIR_CACHE_SIZE (in module dissect.target.tools.dump.utils) DEST_FILENAME_CACHE_SIZE (in module dissect.target.tools.dump.utils) details (acquire.acquire.collector.Record attribute) detect() (dissect.target.container.Container class method) (dissect.target.filesystem.Filesystem class method) (dissect.target.filesystem.RootFilesystem static method) (dissect.target.filesystem.VirtualFilesystem static method) (dissect.target.filesystems.cb.CbFilesystem static method) (dissect.target.filesystems.smb.SmbFilesystem static method) (dissect.target.helpers.network_managers.NetworkManager method) (dissect.target.loader.Loader static method) (dissect.target.loaders.ad1.AD1Loader static method) (dissect.target.loaders.asdf.AsdfLoader static method) (dissect.target.loaders.cb.CbLoader static method) (dissect.target.loaders.cyber.CyberLoader static method) (dissect.target.loaders.dir.DirLoader static method) (dissect.target.loaders.hyperv.HyperVLoader static method) (dissect.target.loaders.itunes.ITunesLoader static method) (dissect.target.loaders.kape.KapeLoader static method) (dissect.target.loaders.local.LocalLoader static method) (dissect.target.loaders.log.LogLoader static method) (dissect.target.loaders.multiraw.MultiRawLoader static method) (dissect.target.loaders.ova.OvaLoader static method) (dissect.target.loaders.ovf.OvfLoader static method) (dissect.target.loaders.phobos.PhobosLoader static method) (dissect.target.loaders.profile.ProfileLoader static method) (dissect.target.loaders.profile.ProfileOSPlugin class method) (dissect.target.loaders.pvm.PvmLoader static method) (dissect.target.loaders.pvs.PvsLoader static method) (dissect.target.loaders.raw.RawLoader static method) (dissect.target.loaders.remote.RemoteLoader static method) (dissect.target.loaders.res.ResLoader static method) (dissect.target.loaders.res.ResOSPlugin class method) (dissect.target.loaders.smb.SmbLoader static method) (dissect.target.loaders.tanium.TaniumLoader static method) (dissect.target.loaders.tar.TarLoader static method) (dissect.target.loaders.target.TargetLoader static method) (dissect.target.loaders.targetd.TargetdLoader static method) (dissect.target.loaders.utm.UtmLoader static method) (dissect.target.loaders.vb.VBLoader static method) (dissect.target.loaders.vbox.VBoxLoader static method) (dissect.target.loaders.velociraptor.VelociraptorLoader static method) (dissect.target.loaders.vma.VmaLoader static method) (dissect.target.loaders.vmwarevm.VmwarevmLoader static method) (dissect.target.loaders.vmx.VmxLoader static method) (dissect.target.loaders.xva.XvaLoader static method) (dissect.target.plugin.OSPlugin class method) (dissect.target.plugins.general.default.DefaultPlugin class method) (dissect.target.plugins.os.unix._os.UnixPlugin class method) (dissect.target.plugins.os.unix.bsd._os.BsdPlugin class method) (dissect.target.plugins.os.unix.bsd.citrix._os.CitrixPlugin class method) (dissect.target.plugins.os.unix.bsd.freebsd._os.FreeBsdPlugin class method) (dissect.target.plugins.os.unix.bsd.ios._os.IOSPlugin class method) (dissect.target.plugins.os.unix.bsd.openbsd._os.OpenBsdPlugin class method) (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin class method) (dissect.target.plugins.os.unix.esxi._os.ESXiPlugin class method) (dissect.target.plugins.os.unix.linux._os.LinuxPlugin class method) (dissect.target.plugins.os.unix.linux.android._os.AndroidPlugin class method) (dissect.target.plugins.os.unix.linux.debian._os.DebianPlugin class method) (dissect.target.plugins.os.unix.linux.debian.vyos._os.VyosPlugin class method) (dissect.target.plugins.os.unix.linux.fortios._os.FortiOSPlugin class method) (dissect.target.plugins.os.unix.linux.redhat._os.RedHat class method) (dissect.target.plugins.os.unix.linux.suse._os.SuSEPlugin class method) (dissect.target.plugins.os.windows._os.WindowsPlugin class method) (dissect.target.volume.VolumeSystem class method) detect_fh() (dissect.target.container.Container class method) detect_header() (in module dissect.util.cpio) detect_id() (dissect.target.filesystem.Filesystem class method) detect_path() (dissect.target.container.Container static method) (dissect.target.containers.asdf.AsdfContainer static method) (dissect.target.containers.ewf.EwfContainer static method) (dissect.target.containers.hdd.HddContainer static method) (dissect.target.containers.hds.HdsContainer static method) (dissect.target.containers.qcow2.QCow2Container static method) (dissect.target.containers.raw.RawContainer static method) (dissect.target.containers.split.SplitContainer static method) (dissect.target.containers.vdi.VdiContainer static method) (dissect.target.containers.vhd.VhdContainer static method) (dissect.target.containers.vhdx.VhdxContainer static method) (dissect.target.containers.vmdk.VmdkContainer static method) detect_volume() (dissect.target.volume.LogicalVolumeSystem class method) dev (dissect.volume.lvm.metadata.PhysicalVolume property) DEV_BSIZE (in module dissect.ffs.ffs) dev_size (dissect.volume.lvm.metadata.PhysicalVolume attribute) dev_start (dissect.volume.raid.stream.Zone attribute) dev_uuid (dissect.btrfs.stream.Stripe attribute) DEVICE (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) Device (class in dissect.hypervisor.backup.vma) (class in dissect.volume.md) (class in dissect.volume.md.md) device (dissect.volume.lvm.metadata.PhysicalVolume attribute) device() (dissect.hypervisor.backup.vma.VMA method) DEVICE_CONTAINERS (dissect.target.plugins.os.windows.regf.usb.UsbPlugin attribute) device_containers() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) device_count (dissect.volume.lvm.metadata.RAIDSegment attribute) device_id (dissect.volume.lvm.metadata.PhysicalVolume attribute) (dissect.volume.lvm.metadata.ThinSegment attribute) device_id_type (dissect.volume.lvm.metadata.PhysicalVolume attribute) DEVICE_SUBST (in module acquire.acquire.utils) DeviceDataStream (class in dissect.hypervisor.backup.vma) DeviceDescriptor (in module dissect.volume.md.md) devices (dissect.volume.raid.stream.Zone attribute) devices() (dissect.hypervisor.backup.vma.VMA method) devid (dissect.btrfs.stream.Stripe attribute) DGRAM (dissect.target.plugins.os.unix.linux.proc.Sockets.SocketStreamType attribute) DHCP (class in acquire.acquire.acquire) dhcp (dissect.target.helpers.network_managers.NetworkManager property) dhcp() (dissect.target.plugins.os.unix.linux._os.LinuxPlugin method) dictify_module_recursive() (in module dissect.target.plugins.general.plugins) dictionary (acquire.acquire.dynamic.windows.types.Handle property) dictlist (class in flow.record.fieldtypes) digest (class in flow.record.fieldtypes) digest() (dissect.evidence.asdf.streams.Crc32Stream method) (dissect.evidence.asdf.streams.HashedStream method) digest_length (dissect.target.plugins.os.windows.dpapi.crypto.HashAlgorithm attribute) DIGIT (dissect.esedb.lcmapstring.SCRIPT attribute) digit() (dissect.cstruct.expression.ExpressionTokenizer method) DIR (acquire.acquire.collector.ArtifactType attribute) DIR_COMBINATIONS (acquire.acquire.acquire.History attribute) DIR_ENTRY_SIZE (in module dissect.fat.c_exfat) DIRECTORY (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) directory() (dissect.ole.OLE method) (dissect.ole.ole.OLE method) DIRECTORY_ALL_ACCESS (acquire.acquire.dynamic.windows.ntdll.ACCESS_MASK attribute) DIRECTORY_CREATE_OBJECT (acquire.acquire.dynamic.windows.ntdll.ACCESS_MASK attribute) DIRECTORY_CREATE_SUBDIRECTORY (acquire.acquire.dynamic.windows.ntdll.ACCESS_MASK attribute) DIRECTORY_QUERY (acquire.acquire.dynamic.windows.ntdll.ACCESS_MASK attribute) DIRECTORY_TRAVERSE (acquire.acquire.dynamic.windows.ntdll.ACCESS_MASK attribute) DirectoryEntry (class in dissect.archive.wim) (class in dissect.fat.fat) (class in dissect.ole.ole) DirectoryFilesystem (class in dissect.target.filesystems.dir) DirectoryFilesystemEntry (class in dissect.target.filesystems.dir) DirectoryOutput (class in acquire.acquire.outputs.dir) DirEntry (class in dissect.jffs.jffs2) dirlist (dissect.extfs.extfs.INode attribute) (dissect.extfs.INode attribute) (dissect.ole.OLE attribute) (dissect.ole.ole.OLE attribute) (dissect.xfs.xfs.INode attribute) DirLoader (class in dissect.target.loaders.dir) dirname (flow.record.fieldtypes.uri property) dirname() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) DIRS (dissect.target.plugins.apps.av.mcafee.McAfeePlugin attribute) (dissect.target.plugins.apps.browser.brave.BravePlugin attribute) (dissect.target.plugins.apps.browser.chrome.ChromePlugin attribute) (dissect.target.plugins.apps.browser.chromium.ChromiumMixin attribute) (dissect.target.plugins.apps.browser.chromium.ChromiumPlugin attribute) (dissect.target.plugins.apps.browser.edge.EdgePlugin attribute) (dissect.target.plugins.apps.browser.firefox.FirefoxPlugin attribute) (dissect.target.plugins.apps.browser.iexplore.InternetExplorerPlugin attribute) DIRTY_NEEDLE (in module dissect.eventlog.evt) discards (dissect.volume.lvm.metadata.ThinPoolSegment attribute) discover() (dissect.target.helpers.network_managers.LinuxNetworkManager method) Disk (class in dissect.hypervisor.disk.vhd) (class in dissect.volume.disk) (class in dissect.volume.disk.disk) disk (in module dissect.target.volume) DISK_DRIVE_XPATH (dissect.hypervisor.descriptor.ovf.OVF attribute) disk_length (dissect.btrfs.stream.Extent attribute) disk_offset (dissect.btrfs.stream.Extent attribute) DISK_XPATH (dissect.hypervisor.descriptor.ovf.OVF attribute) DiskCollection (class in dissect.target.target) DiskDescriptor (class in dissect.hypervisor.disk.vmdk) DiskError, [1] DiskIoGuid (in module dissect.etl.utils) disks() (dissect.evidence.asdf.asdf.AsdfSnapshot method) (dissect.evidence.asdf.AsdfSnapshot method) (dissect.evidence.AsdfSnapshot method) (dissect.hypervisor.backup.xva.XVA method) (dissect.hypervisor.descriptor.ovf.OVF method) (dissect.hypervisor.descriptor.pvs.PVS method) (dissect.hypervisor.descriptor.vbox.VBox method) (dissect.hypervisor.descriptor.vmx.VMX method) DISPLACEMENT_TABLE (in module dissect.util.compression.lznt1) DISPLAY_TZINFO (in module flow.record.fieldtypes) dissect.archive module dissect.archive.c_wim module dissect.archive.exceptions module dissect.archive.wim module dissect.btrfs module dissect.btrfs.btrfs module dissect.btrfs.c_btrfs module dissect.btrfs.exceptions module dissect.btrfs.stream module dissect.btrfs.tree module dissect.cim module dissect.cim.c_cim module dissect.cim.cim module dissect.cim.classes module dissect.cim.exceptions module dissect.cim.index module dissect.cim.mappings module dissect.cim.objects module dissect.cim.utils module dissect.clfs module dissect.clfs.blf module dissect.clfs.c_clfs module dissect.clfs.container module dissect.clfs.exceptions module dissect.cstruct module dissect.cstruct.bitbuffer module dissect.cstruct.compiler module dissect.cstruct.cstruct module dissect.cstruct.exceptions module dissect.cstruct.expression module dissect.cstruct.parser module dissect.cstruct.types module dissect.cstruct.types.base module dissect.cstruct.types.bytesinteger module dissect.cstruct.types.chartype module dissect.cstruct.types.enum module dissect.cstruct.types.flag module dissect.cstruct.types.instance module dissect.cstruct.types.packedtype module dissect.cstruct.types.pointer module dissect.cstruct.types.structure module dissect.cstruct.types.voidtype module dissect.cstruct.types.wchartype module dissect.cstruct.utils module dissect.esedb module dissect.esedb.c_esedb module dissect.esedb.compression module dissect.esedb.cursor module dissect.esedb.esedb module dissect.esedb.exceptions module dissect.esedb.index module dissect.esedb.lcmapstring module dissect.esedb.page module dissect.esedb.record module dissect.esedb.sorting_table module dissect.esedb.table module dissect.esedb.tools module dissect.esedb.tools.impacket module dissect.esedb.tools.sru module dissect.esedb.tools.ual module dissect.etl module dissect.etl.etl module dissect.etl.exceptions module dissect.etl.headers module dissect.etl.headers.event module dissect.etl.headers.headers module dissect.etl.headers.logfile module dissect.etl.headers.system module dissect.etl.headers.utils module dissect.etl.manifest module dissect.etl.manifests module dissect.etl.utils module dissect.eventlog module dissect.eventlog.bxml module dissect.eventlog.evt module dissect.eventlog.evtx module dissect.eventlog.exceptions module dissect.eventlog.utils module dissect.eventlog.wevt module dissect.eventlog.wevt_object module dissect.eventlog.wevtutil module dissect.evidence module dissect.evidence.ad1 module dissect.evidence.asdf module dissect.evidence.asdf.asdf module dissect.evidence.asdf.streams module dissect.evidence.ewf module dissect.evidence.exceptions module dissect.evidence.tools module dissect.evidence.tools.asdf module dissect.evidence.tools.asdf.dd module dissect.evidence.tools.asdf.meta module dissect.evidence.tools.asdf.repair module dissect.evidence.tools.asdf.verify module dissect.executable module dissect.executable.elf module dissect.executable.elf.c_elf module dissect.executable.elf.elf module dissect.executable.exception module dissect.executable.macho module dissect.executable.pe module dissect.extfs module dissect.extfs.c_ext module dissect.extfs.c_jdb2 module dissect.extfs.exceptions module dissect.extfs.extfs module dissect.extfs.journal module dissect.fat module dissect.fat.c_exfat module dissect.fat.c_fat module dissect.fat.exceptions module dissect.fat.exfat module dissect.fat.fat module dissect.ffs module dissect.ffs.c_ffs module dissect.ffs.exceptions module dissect.ffs.ffs module dissect.hypervisor module dissect.hypervisor.backup module dissect.hypervisor.backup.c_vma module dissect.hypervisor.backup.vma module dissect.hypervisor.backup.xva module dissect.hypervisor.descriptor module dissect.hypervisor.descriptor.c_hyperv module dissect.hypervisor.descriptor.hyperv module dissect.hypervisor.descriptor.ovf module dissect.hypervisor.descriptor.pvs module dissect.hypervisor.descriptor.vbox module dissect.hypervisor.descriptor.vmx module dissect.hypervisor.disk module dissect.hypervisor.disk.c_hdd module dissect.hypervisor.disk.c_qcow2 module dissect.hypervisor.disk.c_vdi module dissect.hypervisor.disk.c_vhd module dissect.hypervisor.disk.c_vhdx module dissect.hypervisor.disk.c_vmdk module dissect.hypervisor.disk.hdd module dissect.hypervisor.disk.qcow2 module dissect.hypervisor.disk.vdi module dissect.hypervisor.disk.vhd module dissect.hypervisor.disk.vhdx module dissect.hypervisor.disk.vmdk module dissect.hypervisor.exceptions module dissect.hypervisor.tools module dissect.hypervisor.tools.envelope module dissect.hypervisor.tools.vma module dissect.hypervisor.util module dissect.hypervisor.util.envelope module dissect.hypervisor.util.vmtar module dissect.jffs module dissect.jffs.c_jffs2 module dissect.jffs.exceptions module dissect.jffs.jffs2 module dissect.ntfs module dissect.ntfs.attr module dissect.ntfs.c_ntfs module dissect.ntfs.exceptions module dissect.ntfs.index module dissect.ntfs.mft module dissect.ntfs.ntfs module dissect.ntfs.secure module dissect.ntfs.stream module dissect.ntfs.usnjrnl module dissect.ntfs.util module dissect.ole module dissect.ole.c_ole module dissect.ole.exceptions module dissect.ole.ole module dissect.regf module dissect.regf.c_regf module dissect.regf.exceptions module dissect.regf.regf module dissect.shellitem module dissect.shellitem.lnk module dissect.shellitem.lnk.c_lnk module dissect.shellitem.lnk.lnk module dissect.shellitem.tools module dissect.shellitem.tools.lnk module dissect.sql module dissect.sql.c_sqlite3 module dissect.sql.exceptions module dissect.sql.sqlite3 module dissect.sql.utils module dissect.squashfs module dissect.squashfs.c_squashfs module dissect.squashfs.compression module dissect.squashfs.exceptions module dissect.squashfs.squashfs module dissect.target module dissect.target.container module dissect.target.containers module dissect.target.containers.asdf module dissect.target.containers.ewf module dissect.target.containers.hdd module dissect.target.containers.hds module dissect.target.containers.qcow2 module dissect.target.containers.raw module dissect.target.containers.split module dissect.target.containers.vdi module dissect.target.containers.vhd module dissect.target.containers.vhdx module dissect.target.containers.vmdk module dissect.target.exceptions module dissect.target.filesystem module dissect.target.filesystems module dissect.target.filesystems.ad1 module dissect.target.filesystems.btrfs module dissect.target.filesystems.cb module dissect.target.filesystems.config module dissect.target.filesystems.cpio module dissect.target.filesystems.dir module dissect.target.filesystems.exfat module dissect.target.filesystems.extfs module dissect.target.filesystems.fat module dissect.target.filesystems.ffs module dissect.target.filesystems.itunes module dissect.target.filesystems.jffs module dissect.target.filesystems.ntfs module dissect.target.filesystems.smb module dissect.target.filesystems.squashfs module dissect.target.filesystems.tar module dissect.target.filesystems.vmfs module dissect.target.filesystems.vmtar module dissect.target.filesystems.xfs module dissect.target.filesystems.zip module dissect.target.helpers module dissect.target.helpers.cache module dissect.target.helpers.compat module dissect.target.helpers.compat.path_310 module dissect.target.helpers.compat.path_311 module dissect.target.helpers.compat.path_312 module dissect.target.helpers.compat.path_39 module dissect.target.helpers.compat.path_common module dissect.target.helpers.config module dissect.target.helpers.configutil module dissect.target.helpers.cyber module dissect.target.helpers.descriptor_extensions module dissect.target.helpers.docs module dissect.target.helpers.fsutil module dissect.target.helpers.hashutil module dissect.target.helpers.keychain module dissect.target.helpers.lazy module dissect.target.helpers.loaderutil module dissect.target.helpers.localeutil module dissect.target.helpers.mount module dissect.target.helpers.mui module dissect.target.helpers.network_managers module dissect.target.helpers.polypath module dissect.target.helpers.protobuf module dissect.target.helpers.record module dissect.target.helpers.record_modifier module dissect.target.helpers.regutil module dissect.target.helpers.shell_folder_ids module dissect.target.helpers.ssh module dissect.target.helpers.targetd module dissect.target.helpers.utils module dissect.target.loader module dissect.target.loaders module dissect.target.loaders.ad1 module dissect.target.loaders.asdf module dissect.target.loaders.cb module dissect.target.loaders.cyber module dissect.target.loaders.dir module dissect.target.loaders.hyperv module dissect.target.loaders.itunes module dissect.target.loaders.kape module dissect.target.loaders.local module dissect.target.loaders.log module dissect.target.loaders.multiraw module dissect.target.loaders.ova module dissect.target.loaders.ovf module dissect.target.loaders.phobos module dissect.target.loaders.profile module dissect.target.loaders.pvm module dissect.target.loaders.pvs module dissect.target.loaders.raw module dissect.target.loaders.remote module dissect.target.loaders.res module dissect.target.loaders.smb module dissect.target.loaders.tanium module dissect.target.loaders.tar module dissect.target.loaders.target module dissect.target.loaders.targetd module dissect.target.loaders.utm module dissect.target.loaders.vb module dissect.target.loaders.vbox module dissect.target.loaders.velociraptor module dissect.target.loaders.vma module dissect.target.loaders.vmwarevm module dissect.target.loaders.vmx module dissect.target.loaders.xva module dissect.target.plugin module dissect.target.plugins module dissect.target.plugins.apps module dissect.target.plugins.apps.av module dissect.target.plugins.apps.av.mcafee module dissect.target.plugins.apps.av.sophos module dissect.target.plugins.apps.av.symantec module dissect.target.plugins.apps.av.trendmicro module dissect.target.plugins.apps.browser module dissect.target.plugins.apps.browser.brave module dissect.target.plugins.apps.browser.browser module dissect.target.plugins.apps.browser.chrome module dissect.target.plugins.apps.browser.chromium module dissect.target.plugins.apps.browser.edge module dissect.target.plugins.apps.browser.firefox module dissect.target.plugins.apps.browser.iexplore module dissect.target.plugins.apps.container module dissect.target.plugins.apps.container.docker module dissect.target.plugins.apps.remoteaccess module dissect.target.plugins.apps.remoteaccess.anydesk module dissect.target.plugins.apps.remoteaccess.remoteaccess module dissect.target.plugins.apps.remoteaccess.teamviewer module dissect.target.plugins.apps.shell module dissect.target.plugins.apps.shell.powershell module dissect.target.plugins.apps.ssh module dissect.target.plugins.apps.ssh.openssh module dissect.target.plugins.apps.ssh.opensshd module dissect.target.plugins.apps.ssh.putty module dissect.target.plugins.apps.ssh.ssh module dissect.target.plugins.apps.vpn module dissect.target.plugins.apps.vpn.openvpn module dissect.target.plugins.apps.vpn.wireguard module dissect.target.plugins.apps.webhosting module dissect.target.plugins.apps.webhosting.cpanel module dissect.target.plugins.apps.webserver module dissect.target.plugins.apps.webserver.apache module dissect.target.plugins.apps.webserver.caddy module dissect.target.plugins.apps.webserver.citrix module dissect.target.plugins.apps.webserver.iis module dissect.target.plugins.apps.webserver.nginx module dissect.target.plugins.apps.webserver.webserver module dissect.target.plugins.child module dissect.target.plugins.child.esxi module dissect.target.plugins.child.hyperv module dissect.target.plugins.child.virtuozzo module dissect.target.plugins.child.vmware_workstation module dissect.target.plugins.child.wsl module dissect.target.plugins.filesystem module dissect.target.plugins.filesystem.acquire_handles module dissect.target.plugins.filesystem.acquire_hash module dissect.target.plugins.filesystem.icat module dissect.target.plugins.filesystem.ntfs module dissect.target.plugins.filesystem.ntfs.mft module dissect.target.plugins.filesystem.ntfs.mft_timeline module dissect.target.plugins.filesystem.ntfs.usnjrnl module dissect.target.plugins.filesystem.ntfs.utils module dissect.target.plugins.filesystem.resolver module dissect.target.plugins.filesystem.unix module dissect.target.plugins.filesystem.unix.capability module dissect.target.plugins.filesystem.unix.suid module dissect.target.plugins.filesystem.walkfs module dissect.target.plugins.filesystem.yara module dissect.target.plugins.general module dissect.target.plugins.general.config module dissect.target.plugins.general.default module dissect.target.plugins.general.example module dissect.target.plugins.general.loaders module dissect.target.plugins.general.osinfo module dissect.target.plugins.general.plugins module dissect.target.plugins.general.scrape module dissect.target.plugins.general.users module dissect.target.plugins.os module dissect.target.plugins.os.unix module dissect.target.plugins.os.unix._os module dissect.target.plugins.os.unix.bsd._os module dissect.target.plugins.os.unix.bsd.citrix module dissect.target.plugins.os.unix.bsd.citrix._os module dissect.target.plugins.os.unix.bsd.citrix.history module dissect.target.plugins.os.unix.bsd.freebsd module dissect.target.plugins.os.unix.bsd.freebsd._os module dissect.target.plugins.os.unix.bsd.ios module dissect.target.plugins.os.unix.bsd.ios._os module dissect.target.plugins.os.unix.bsd.openbsd module dissect.target.plugins.os.unix.bsd.openbsd._os module dissect.target.plugins.os.unix.bsd.osx module dissect.target.plugins.os.unix.bsd.osx._os module dissect.target.plugins.os.unix.bsd.osx.user module dissect.target.plugins.os.unix.cronjobs module dissect.target.plugins.os.unix.datetime module dissect.target.plugins.os.unix.esxi module dissect.target.plugins.os.unix.esxi._os module dissect.target.plugins.os.unix.etc module dissect.target.plugins.os.unix.generic module dissect.target.plugins.os.unix.history module dissect.target.plugins.os.unix.linux module dissect.target.plugins.os.unix.linux._os module dissect.target.plugins.os.unix.linux.android module dissect.target.plugins.os.unix.linux.android._os module dissect.target.plugins.os.unix.linux.cmdline module dissect.target.plugins.os.unix.linux.debian module dissect.target.plugins.os.unix.linux.debian._os module dissect.target.plugins.os.unix.linux.debian.apt module dissect.target.plugins.os.unix.linux.debian.dpkg module dissect.target.plugins.os.unix.linux.debian.vyos module dissect.target.plugins.os.unix.linux.debian.vyos._os module dissect.target.plugins.os.unix.linux.environ module dissect.target.plugins.os.unix.linux.fortios module dissect.target.plugins.os.unix.linux.fortios._keys module dissect.target.plugins.os.unix.linux.fortios._os module dissect.target.plugins.os.unix.linux.fortios.generic module dissect.target.plugins.os.unix.linux.fortios.locale module dissect.target.plugins.os.unix.linux.iptables module dissect.target.plugins.os.unix.linux.modules module dissect.target.plugins.os.unix.linux.netstat module dissect.target.plugins.os.unix.linux.proc module dissect.target.plugins.os.unix.linux.processes module dissect.target.plugins.os.unix.linux.redhat module dissect.target.plugins.os.unix.linux.redhat._os module dissect.target.plugins.os.unix.linux.redhat.yum module dissect.target.plugins.os.unix.linux.services module dissect.target.plugins.os.unix.linux.sockets module dissect.target.plugins.os.unix.linux.suse module dissect.target.plugins.os.unix.linux.suse._os module dissect.target.plugins.os.unix.linux.suse.zypper module dissect.target.plugins.os.unix.locale module dissect.target.plugins.os.unix.locate module dissect.target.plugins.os.unix.locate.gnulocate module dissect.target.plugins.os.unix.locate.locate module dissect.target.plugins.os.unix.locate.mlocate module dissect.target.plugins.os.unix.locate.plocate module dissect.target.plugins.os.unix.log module dissect.target.plugins.os.unix.log.atop module dissect.target.plugins.os.unix.log.audit module dissect.target.plugins.os.unix.log.auth module dissect.target.plugins.os.unix.log.journal module dissect.target.plugins.os.unix.log.lastlog module dissect.target.plugins.os.unix.log.messages module dissect.target.plugins.os.unix.log.utmp module dissect.target.plugins.os.unix.packagemanager module dissect.target.plugins.os.unix.shadow module dissect.target.plugins.os.windows module dissect.target.plugins.os.windows._os module dissect.target.plugins.os.windows.activitiescache module dissect.target.plugins.os.windows.adpolicy module dissect.target.plugins.os.windows.amcache module dissect.target.plugins.os.windows.catroot module dissect.target.plugins.os.windows.cim module dissect.target.plugins.os.windows.clfs module dissect.target.plugins.os.windows.datetime module dissect.target.plugins.os.windows.defender module dissect.target.plugins.os.windows.dpapi module dissect.target.plugins.os.windows.dpapi.blob module dissect.target.plugins.os.windows.dpapi.crypto module dissect.target.plugins.os.windows.dpapi.dpapi module dissect.target.plugins.os.windows.dpapi.master_key module dissect.target.plugins.os.windows.env module dissect.target.plugins.os.windows.exchange module dissect.target.plugins.os.windows.exchange.exchange module dissect.target.plugins.os.windows.generic module dissect.target.plugins.os.windows.lnk module dissect.target.plugins.os.windows.locale module dissect.target.plugins.os.windows.log module dissect.target.plugins.os.windows.log.amcache module dissect.target.plugins.os.windows.log.etl module dissect.target.plugins.os.windows.log.evt module dissect.target.plugins.os.windows.log.evtx module dissect.target.plugins.os.windows.log.pfro module dissect.target.plugins.os.windows.log.schedlgu module dissect.target.plugins.os.windows.notifications module dissect.target.plugins.os.windows.prefetch module dissect.target.plugins.os.windows.recyclebin module dissect.target.plugins.os.windows.regf module dissect.target.plugins.os.windows.regf.7zip module dissect.target.plugins.os.windows.regf.appxdebugkeys module dissect.target.plugins.os.windows.regf.auditpol module dissect.target.plugins.os.windows.regf.bam module dissect.target.plugins.os.windows.regf.cit module dissect.target.plugins.os.windows.regf.clsid module dissect.target.plugins.os.windows.regf.firewall module dissect.target.plugins.os.windows.regf.mru module dissect.target.plugins.os.windows.regf.muicache module dissect.target.plugins.os.windows.regf.nethist module dissect.target.plugins.os.windows.regf.recentfilecache module dissect.target.plugins.os.windows.regf.regf module dissect.target.plugins.os.windows.regf.runkeys module dissect.target.plugins.os.windows.regf.shellbags module dissect.target.plugins.os.windows.regf.shimcache module dissect.target.plugins.os.windows.regf.trusteddocs module dissect.target.plugins.os.windows.regf.usb module dissect.target.plugins.os.windows.regf.userassist module dissect.target.plugins.os.windows.registry module dissect.target.plugins.os.windows.sam module dissect.target.plugins.os.windows.services module dissect.target.plugins.os.windows.sru module dissect.target.plugins.os.windows.startupinfo module dissect.target.plugins.os.windows.syscache module dissect.target.plugins.os.windows.task_helpers module dissect.target.plugins.os.windows.task_helpers.tasks_job module dissect.target.plugins.os.windows.task_helpers.tasks_records module dissect.target.plugins.os.windows.task_helpers.tasks_xml module dissect.target.plugins.os.windows.tasks module dissect.target.plugins.os.windows.thumbcache module dissect.target.plugins.os.windows.ual module dissect.target.plugins.os.windows.wer module dissect.target.report module dissect.target.target module dissect.target.tools module dissect.target.tools.build_pluginlist module dissect.target.tools.dd module dissect.target.tools.dump module dissect.target.tools.dump.run module dissect.target.tools.dump.state module dissect.target.tools.dump.utils module dissect.target.tools.fs module dissect.target.tools.info module dissect.target.tools.logging module dissect.target.tools.mount module dissect.target.tools.query module dissect.target.tools.reg module dissect.target.tools.shell module dissect.target.tools.utils module dissect.target.volume module dissect.target.volumes module dissect.target.volumes.bde module dissect.target.volumes.ddf module dissect.target.volumes.disk module dissect.target.volumes.luks module dissect.target.volumes.lvm module dissect.target.volumes.md module dissect.target.volumes.vmfs module dissect.thumbcache module dissect.thumbcache.c_thumbcache module dissect.thumbcache.exceptions module dissect.thumbcache.index module dissect.thumbcache.thumbcache module dissect.thumbcache.thumbcache_file module dissect.thumbcache.tools module dissect.thumbcache.tools.extract_images module dissect.thumbcache.tools.extract_with_index module dissect.thumbcache.tools.utils module dissect.thumbcache.util module dissect.util module dissect.util.compression module dissect.util.compression.lz4 module dissect.util.compression.lznt1 module dissect.util.compression.lzo module dissect.util.compression.lzxpress module dissect.util.compression.lzxpress_huffman module dissect.util.compression.sevenbit module dissect.util.compression.xz module dissect.util.cpio module dissect.util.crc32c module dissect.util.encoding module dissect.util.encoding.surrogateescape module dissect.util.exceptions module dissect.util.feature module dissect.util.plist module dissect.util.sid module dissect.util.stream module dissect.util.tools module dissect.util.tools.dump_nskeyedarchiver module dissect.util.ts module dissect.util.xmemoryview module dissect.vmfs module dissect.vmfs.c_vmfs module dissect.vmfs.exceptions module dissect.vmfs.lvm module dissect.vmfs.resource module dissect.vmfs.vmfs module dissect.volume module dissect.volume.ddf module dissect.volume.ddf.c_ddf module dissect.volume.ddf.ddf module dissect.volume.disk module dissect.volume.disk.disk module dissect.volume.disk.partition module dissect.volume.disk.schemes module dissect.volume.disk.schemes.apm module dissect.volume.disk.schemes.bsd module dissect.volume.disk.schemes.gpt module dissect.volume.disk.schemes.mbr module dissect.volume.dm module dissect.volume.dm.btree module dissect.volume.dm.c_dm module dissect.volume.dm.thin module dissect.volume.exceptions module dissect.volume.ldm module dissect.volume.lvm module dissect.volume.lvm.c_lvm2 module dissect.volume.lvm.lvm2 module dissect.volume.lvm.metadata module dissect.volume.lvm.physical module dissect.volume.md module dissect.volume.md.c_md module dissect.volume.md.md module dissect.volume.raid module dissect.volume.raid.raid module dissect.volume.raid.stream module dissect.volume.vss module dissect.xfs module dissect.xfs.c_xfs module dissect.xfs.exceptions module dissect.xfs.xfs module DISSECT_FEATURES_DEFAULT (in module dissect.util.feature) DISSECT_FEATURES_ENV (in module dissect.util.feature) DissectMount (class in dissect.target.helpers.mount) DissectVolumeSystem (class in dissect.target.volumes.disk) dm_def (in module dissect.volume.dm.c_dm) DMError DNS (class in acquire.acquire.acquire) dns (dissect.target.helpers.network_managers.NetworkManager property) dns() (dissect.target.plugins.os.unix.linux._os.LinuxPlugin method) (dissect.target.plugins.os.unix.linux.fortios._os.FortiOSPlugin method) do_cd() (dissect.target.tools.shell.RegistryCli method) (dissect.target.tools.shell.TargetCli method) do_clear() (dissect.target.tools.shell.TargetCmd method) do_cyber() (dissect.target.tools.shell.TargetCmd method) do_disks() (dissect.target.tools.shell.TargetCli method) do_enter() (dissect.target.tools.shell.TargetHubCli method) do_exit() (dissect.target.tools.shell.TargetCmd method) (dissect.target.tools.shell.TargetHubCli method) do_filesystems() (dissect.target.tools.shell.TargetCli method) do_info() (dissect.target.tools.shell.TargetCli method) do_list() (dissect.target.tools.shell.TargetHubCli method) do_pwd() (dissect.target.tools.shell.RegistryCli method) (dissect.target.tools.shell.TargetCli method) do_python() (dissect.target.tools.shell.TargetCmd method) (dissect.target.tools.shell.TargetHubCli method) do_recommend() (dissect.target.tools.shell.RegistryCli method) do_up() (dissect.target.tools.shell.RegistryCli method) do_volumes() (dissect.target.tools.shell.TargetCli method) doc_header (dissect.target.tools.shell.TargetHubCli attribute) DOCID_SIZE_BYTES (dissect.target.plugins.os.unix.locate.plocate.PLocateFile attribute) DockerContainerRecord (in module dissect.target.plugins.apps.container.docker) DockerImageRecord (in module dissect.target.plugins.apps.container.docker) DockerLogRecord (in module dissect.target.plugins.apps.container.docker) DockerPlugin (class in dissect.target.plugins.apps.container.docker) document_stream() (flow.record.adapter.elastic.ElasticWriter method) domain() (dissect.target.plugins.os.unix._os.UnixPlugin method) (dissect.target.plugins.os.unix.esxi._os.ESXiPlugin method) (dissect.target.plugins.os.windows.generic.GenericPlugin method) DOMAIN_TRANSLATION (in module dissect.target.loaders.itunes) domains_seen() (dissect.target.plugins.os.windows.ual.UalPlugin method) DomainSeenRecord (in module dissect.target.plugins.os.windows.ual) dostimestamp() (in module dissect.util.ts) DOUBLE (dissect.eventlog.bxml.BxmlType attribute) Downgrade (dissect.target.plugins.os.unix.packagemanager.OperationTypes attribute) downloads() (dissect.target.plugins.apps.browser.brave.BravePlugin method) (dissect.target.plugins.apps.browser.chrome.ChromePlugin method) (dissect.target.plugins.apps.browser.chromium.ChromiumMixin method) (dissect.target.plugins.apps.browser.chromium.ChromiumPlugin method) (dissect.target.plugins.apps.browser.edge.EdgePlugin method) (dissect.target.plugins.apps.browser.firefox.FirefoxPlugin method) (dissect.target.plugins.apps.browser.iexplore.InternetExplorerPlugin method) (dissect.target.plugins.apps.browser.iexplore.WebCache method) dp() (dissect.target.plugins.os.windows.regf.cit.CITPlugin method) dpapi_hmac() (in module dissect.target.plugins.os.windows.dpapi.crypto) DPAPIPlugin (class in dissect.target.plugins.os.windows.dpapi.dpapi) DpcGuid (in module dissect.etl.utils) DpkgPackageLogRecord (in module dissect.target.plugins.os.unix.linux.debian.dpkg) DpkgPackageStatusRecord (in module dissect.target.plugins.os.unix.linux.debian.dpkg) DpkgPlugin (class in dissect.target.plugins.os.unix.linux.debian.dpkg) DRIVE_CONTROLLER_GUIDS (in module dissect.target.loaders.hyperv) DRIVE_LETTER_RE (in module dissect.target.plugins.filesystem.ntfs.utils) DRIVER (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) Drivers (class in acquire.acquire.acquire) drivers() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) drop_dirty_sinks() (dissect.target.tools.dump.state.DumpState method) drop_invalid_sinks() (dissect.target.tools.dump.state.DumpState method) drops (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) dst() (dissect.target.plugins.os.windows.datetime.WindowsTimezone method) (dissect.util.ts.UTC method) DT_CENTER (in module acquire.acquire.gui.win32) DT_MAP (in module dissect.jffs.c_jffs2) DT_SINGLELINE (in module acquire.acquire.gui.win32) DT_VCENTER (in module acquire.acquire.gui.win32) dtime (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) DTYPE_NAMES (in module dissect.volume.disk.schemes.bsd) DUMMY (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) (dissect.target.plugins.os.unix.linux.proc.Sockets.UDPStates attribute) dump() (dissect.executable.ELF method) (dissect.executable.elf.ELF method) (dissect.executable.elf.elf.ELF method) dump_data() (dissect.executable.elf.elf.SectionTable method) (dissect.executable.elf.elf.SegmentTable method) (dissect.executable.elf.SectionTable method) (dissect.executable.elf.SegmentTable method) dump_entry_data() (in module dissect.thumbcache.tools.extract_images) dump_entry_data_through_index() (in module dissect.thumbcache.tools.extract_with_index) dump_table() (dissect.executable.elf.elf.SectionTable method) (dissect.executable.elf.elf.SegmentTable method) (dissect.executable.elf.SectionTable method) (dissect.executable.elf.SegmentTable method) dumps() (dissect.cstruct.BaseType method) (dissect.cstruct.Instance method) (dissect.cstruct.types.base.BaseType method) (dissect.cstruct.types.BaseType method) (dissect.cstruct.types.Instance method) (dissect.cstruct.types.instance.Instance method) DumpState (class in dissect.target.tools.dump.state) dumpstruct() (in module dissect.cstruct) (in module dissect.cstruct.utils) DUPLICATE_CLOSE_SOURCE (acquire.acquire.dynamic.windows.types.DuplicateHandleFlags attribute) duplicate_handle() (in module acquire.acquire.dynamic.windows.handles) DUPLICATE_SAME_ACCESS (acquire.acquire.dynamic.windows.types.DuplicateHandleFlags attribute) DUPLICATE_SAME_ATTRIBUTES (acquire.acquire.dynamic.windows.types.DuplicateHandleFlags attribute) DuplicateFilter (class in acquire.acquire.dynamic.windows.handles) DuplicateHandle (in module acquire.acquire.dynamic.windows.handles) DuplicateHandleFlags (class in acquire.acquire.dynamic.windows.types) dynamic (class in flow.record.fieldtypes) (dissect.executable.ELF property) (dissect.executable.elf.ELF property) (dissect.executable.elf.elf.ELF property) dynamic_fieldtype (in module flow.record) (in module flow.record.base) DynamicDescriptor() (in module dissect.target.helpers.record) (in module flow.record) (in module flow.record.base) DynamicDisk (class in dissect.hypervisor.disk.vhd) DynamicFieldtypeModule (class in flow.record.base) DynpropQualifier (class in dissect.cim.classes) Dynprops (class in dissect.cim.classes) DYNPROPS_STATES (in module dissect.cim.c_cim) E each() (dissect.target.loaders.targetd.TargetdLoader method) EASTASIA_SPECIAL (dissect.esedb.lcmapstring.SCRIPT attribute) EdgePlugin (class in dissect.target.plugins.apps.browser.edge) ElasticReader (class in flow.record.adapter.elastic) ElasticWriter (class in flow.record.adapter.elastic) ELF (class in dissect.executable) (class in dissect.executable.elf) (class in dissect.executable.elf.elf) elf_32_def (in module dissect.executable.elf.c_elf) elf_64_def (in module dissect.executable.elf.c_elf) elf_def (in module dissect.executable.elf.c_elf) Elf_Type (in module dissect.executable.elf.c_elf) ElfChnk (class in dissect.eventlog.evtx) EM_SETPASSWORDCHAR (in module acquire.acquire.gui.win32) emit() (acquire.acquire.log.DelayedFileHandler method) emit_last_message() (dissect.target.exceptions.FatalError method) EMPTY (acquire.acquire.collector.Outcome attribute) Empty (class in dissect.sql.sqlite3) EMPTY_LM (dissect.target.loaders.smb.SmbLoader attribute) EMPTY_NT (dissect.target.loaders.smb.SmbLoader attribute) EmptyDirectoryError, [1] emptyline() (dissect.target.tools.shell.TargetCmd method) (dissect.target.tools.shell.TargetHubCli method) EmptyRecord (in module dissect.target.helpers.record) encode_key() (in module dissect.esedb.index) encode_varint() (in module dissect.target.helpers.protobuf) encoding (dissect.cstruct.types.WcharType property) (dissect.cstruct.types.wchartype.WcharType property) (dissect.cstruct.WcharType property) ENCODING (in module dissect.sql.c_sqlite3) encoding() (dissect.esedb.table.Column method) encrypted (dissect.hypervisor.descriptor.vmx.VMX property) ENCRYPTED_VOLUME_MANAGERS (in module dissect.target.volume) EncryptedFile (class in acquire.acquire.tools.decrypter) EncryptedFileStream (class in dissect.target.filesystems.itunes) EncryptedStream (class in acquire.acquire.crypt) EncryptedVolumeSystem (class in dissect.target.volume) encryption (dissect.btrfs.stream.Extent attribute) encryption_key (dissect.target.loaders.itunes.FileInfo property) end (dissect.executable.elf.elf.Segment property) (dissect.executable.elf.Segment property) (dissect.hypervisor.disk.hdd.Storage attribute) END_OF_CLUSTER_MAX (in module dissect.fat.c_fat) END_OF_CLUSTER_MIN (in module dissect.fat.c_fat) end_pos (dissect.target.tools.dump.run.RecordStreamElement attribute) end_time (dissect.etl.headers.logfile.LogfileHeader property) ENDIANNESS_MAP (in module dissect.cstruct.utils) energy_estimator() (dissect.target.plugins.os.windows.sru.SRUPlugin method) energy_usage() (dissect.target.plugins.os.windows.sru.SRUPlugin method) energy_usage_lt() (dissect.target.plugins.os.windows.sru.SRUPlugin method) EnergyEstimatorRecord (in module dissect.target.plugins.os.windows.sru) EnergyUsageLTRecord (in module dissect.target.plugins.os.windows.sru) EnergyUsageRecord (in module dissect.target.plugins.os.windows.sru) ensure_volume() (in module dissect.ntfs.util) entries() (dissect.esedb.tools.sru.SRU method) (dissect.ntfs.Index method) (dissect.ntfs.index.Index method) (dissect.ntfs.index.IndexBuffer method) (dissect.ntfs.index.IndexRoot method) (dissect.thumbcache.index.ThumbnailIndex method) (dissect.thumbcache.Thumbcache method) (dissect.thumbcache.thumbcache.Thumbcache method) (dissect.thumbcache.thumbcache_file.ThumbcacheFile method) (dissect.thumbcache.ThumbcacheFile method) (dissect.thumbcache.ThumbnailIndex method) Entry (class in dissect.esedb.tools.sru) (class in dissect.target.plugins.os.windows.regf.cit) ENTRY (dissect.hypervisor.disk.vhd.BlockAllocationTable attribute) entry (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry attribute) (dissect.target.filesystems.jffs.JFFSFilesystemEntry attribute) (dissect.target.filesystems.smb.SmbFilesystemEntry attribute) entry() (dissect.evidence.ad1.AD1 method) (dissect.hypervisor.disk.qcow2.L2Table method) entry_object_offsets() (dissect.target.plugins.os.unix.log.journal.JournalFile method) EntryList (class in dissect.target.filesystem) EntryType (in module dissect.evidence.ad1) Enum (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.enum) EnumInstance (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.enum) env (dissect.target.plugins.os.windows.env.EnvironmentVariablePlugin property) Envelope (class in dissect.hypervisor.util.envelope) ENVELOPE_ATTRIBUTE_TYPE_MAP (in module dissect.hypervisor.util.envelope) ENVELOPE_BLOCK_SIZE (in module dissect.hypervisor.util.envelope) EnvelopeAttribute (in module dissect.hypervisor.util.envelope) Environ (class in dissect.target.plugins.os.unix.linux.proc) environ() (dissect.target.plugins.os.unix.linux.environ.EnvironPlugin method) (dissect.target.plugins.os.unix.linux.proc.ProcProcess method) ENVIRONMENT_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) environment_variable_paths() (in module dissect.target.plugin) environment_variables() (dissect.target.plugins.os.windows.env.EnvironmentVariablePlugin method) EnvironmentRecord (in module dissect.target.plugins.os.windows.env) EnvironmentVariablePlugin (class in dissect.target.plugins.os.windows.env) EnvironmentVariableRecord (in module dissect.target.plugins.os.unix.cronjobs) (in module dissect.target.plugins.os.unix.linux.environ) EnvironPlugin (class in dissect.target.plugins.os.unix.linux.environ) EnvVarDetails (in module dissect.target.plugins.os.windows.env) EOC (in module dissect.fat.c_exfat) eol() (dissect.cstruct.expression.ExpressionTokenizer method) (dissect.cstruct.parser.TokenConsumer method) EPOCH (in module dissect.target.filesystems.cb) (in module flow.record.adapter.avro) Equal (dissect.ntfs.index.Match attribute) equal() (dissect.cstruct.expression.ExpressionTokenizer method) Error, [1], [2], [3], [4], [5], [6], [7], [8], [9], [10], [11], [12], [13], [14], [15], [16], [17], [18], [19], [20], [21], [22], [23], [24], [25], [26], [27], [28], [29], [30], [31], [32], [33], [34], [35], [36], [37], [38], [39], [40], [41], [42] error() (dissect.target.plugins.apps.webserver.apache.ApachePlugin method) ERROR_ACCESS_DENIED (acquire.acquire.dynamic.windows.types.ErrorCode attribute) error_handler() (in module dissect.util.encoding.surrogateescape) ERROR_INVALID_PARAMETER (acquire.acquire.dynamic.windows.types.ErrorCode attribute) ERROR_LOG_NAMES (dissect.target.plugins.apps.webserver.apache.ApachePlugin attribute) (dissect.target.plugins.apps.webserver.citrix.CitrixWebserverPlugin attribute) ERROR_NOT_ALL_ASSIGNED (acquire.acquire.dynamic.windows.types.ErrorCode attribute) ERROR_PARTIAL_COPY (acquire.acquire.dynamic.windows.types.ErrorCode attribute) ERROR_SUCCESS (acquire.acquire.dynamic.windows.types.ErrorCode attribute) ErrorCode (class in acquire.acquire.dynamic.windows.types) ErrorHeader (class in dissect.etl.headers.headers) ErrorSegment (class in dissect.volume.lvm.metadata) ES_PASSWORD (in module acquire.acquire.gui.win32) ES_WANTRETURN (in module acquire.acquire.gui.win32) EseDB (class in dissect.esedb) (class in dissect.esedb.esedb) ESENT_DB (class in dissect.esedb.tools.impacket) ESTABLISHED (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) (dissect.target.plugins.os.unix.linux.proc.Sockets.UDPStates attribute) esxconf() (dissect.target.plugins.os.unix.esxi._os.ESXiPlugin method) ESXi (class in acquire.acquire.acquire) ESXI (dissect.target.plugin.OperatingSystem attribute) ESXI_DEV_DIR (in module dissect.target.loaders.local) esxi_memory_context_manager() (in module acquire.acquire.esxi) ESXiChildTargetPlugin (class in dissect.target.plugins.child.esxi) EsxiMemoryManager (class in acquire.acquire.esxi) ESXiPlugin (class in dissect.target.plugins.os.unix.esxi._os) ESXiProfile (class in acquire.acquire.acquire) Etc (class in acquire.acquire.acquire) EtcTree (class in dissect.target.plugins.os.unix.etc) ETH_P_802_2 (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_802_3 (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_ALL (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_ARCNET (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_AX25 (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_CAN (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_CONTROL (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_DDCMP (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_DSA (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_ECONET (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_HDLC (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_IEEE802154 (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_IRDA (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_LOCALTALK (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_MOBITEX (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_PHONET (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_PPP_MP (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_PPPTALK (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_SNAP (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_TR_802_2 (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_TRAILER (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETH_P_WAN_PPP (dissect.target.plugins.os.unix.linux.proc.Sockets.PacketProtocolTypes attribute) ETL (class in acquire.acquire.acquire) (class in dissect.etl) (class in dissect.etl.etl) etl() (dissect.target.plugins.os.windows.log.etl.EtlPlugin method) EtlPlugin (class in dissect.target.plugins.os.windows.log.etl) EtlRecordBuilder (class in dissect.target.plugins.os.windows.log.etl) ETW_REGISTRATION (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) eval() (flow.record.selector.RecordContextMatcher method) evaluate() (dissect.cstruct.Expression method) (dissect.cstruct.expression.Expression method) evaluate_exp() (dissect.cstruct.Expression method) (dissect.cstruct.expression.Expression method) EVENT (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) Event (class in dissect.etl.etl) (class in dissect.target.target) event (dissect.etl.etl.EventRecord property) EVENT_KEY (dissect.etl.headers.event.ExtType attribute) event_property (dissect.etl.headers.headers.MessageTraceHeader property) EVENT_SCHEMA_TL (dissect.etl.headers.event.ExtType attribute) event_values() (dissect.etl.etl.Event method) EventDescriptor (class in dissect.etl.headers.event) EventHandler (class in flow.record.utils) EventHeader (class in dissect.etl.headers.event) EventHeaderExtendedDataItem (class in dissect.etl.headers.event) EventInstanceGUIDHeader (class in dissect.etl.headers.headers) EventInstanceHeader (class in dissect.etl.headers.headers) EVENTLOG_REGISTRY_KEY (dissect.target.plugins.os.windows.log.evt.WindowsEventlogsMixin attribute) EVENTLOGRECORD_SIZE (in module dissect.eventlog.evt) EventLogs (class in acquire.acquire.acquire) EventProperty (class in dissect.etl.headers.headers) EventRecord (class in dissect.etl.etl) EventTraceConfigGuid (in module dissect.etl.utils) EventTraceGuid (in module dissect.etl.utils) EventTraceHeader (class in dissect.etl.headers.headers) EventTraceSpare1 (in module dissect.etl.utils) EventTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) EVNT (class in dissect.eventlog.wevt_object) Evt (class in dissect.eventlog) (class in dissect.eventlog.evt) evt() (dissect.target.plugins.os.windows.log.evt.EvtPlugin method) EVT_GLOB (in module dissect.target.plugins.os.windows.log.evt) EVTHANDLE (dissect.eventlog.bxml.BxmlType attribute) EvtPlugin (class in dissect.target.plugins.os.windows.log.evt) EvtRecordDescriptor (in module dissect.target.plugins.os.windows.log.evt) Evtx (class in dissect.eventlog) (class in dissect.eventlog.evtx) evtx (in module dissect.eventlog.evtx) evtx() (dissect.target.plugins.os.windows.defender.MicrosoftDefenderPlugin method) (dissect.target.plugins.os.windows.log.evtx.EvtxPlugin method) EVTX_GLOB (in module dissect.target.plugins.os.windows.log.evtx) EVTX_PROVIDER_NAME (in module dissect.target.plugins.os.windows.defender) EVTXML (dissect.eventlog.bxml.BxmlType attribute) EvtxNameReader (class in dissect.eventlog.bxml) EvtxPlugin (class in dissect.target.plugins.os.windows.log.evtx) EWF (class in dissect.evidence) (class in dissect.evidence.ewf) ewf_def (in module dissect.evidence.ewf) EwfContainer (class in dissect.target.containers.ewf) EWFError EWFStream (class in dissect.evidence.ewf) example() (dissect.target.plugins.general.example.ExamplePlugin method) example_internal() (dissect.target.plugins.general.example.ExamplePlugin method) example_none() (dissect.target.plugins.general.example.ExamplePlugin method) example_record() (dissect.target.plugins.general.example.ExamplePlugin method) example_user_registry_record() (dissect.target.plugins.general.example.ExamplePlugin method) example_yield() (dissect.target.plugins.general.example.ExamplePlugin method) ExamplePlugin (class in dissect.target.plugins.general.example) ExampleRecordRecord (in module dissect.target.plugins.general.example) ExampleUserRegistryRecord (in module dissect.target.plugins.general.example) Exchange (class in acquire.acquire.acquire) ExchangePlugin (class in dissect.target.plugins.os.windows.exchange.exchange) exclusions() (dissect.target.plugins.os.windows.defender.MicrosoftDefenderPlugin method) EXEC_ORDER (acquire.acquire.acquire.Module attribute) (acquire.acquire.acquire.Netstat attribute) (acquire.acquire.acquire.Proc attribute) (acquire.acquire.acquire.Sys attribute) (acquire.acquire.acquire.WinArpCache attribute) (acquire.acquire.acquire.WinDnsClientCache attribute) (acquire.acquire.acquire.WinMemDump attribute) (acquire.acquire.acquire.WinProcEnv attribute) (acquire.acquire.acquire.WinProcesses attribute) (acquire.acquire.acquire.WinRDPSessions attribute) ExecRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) execute_function() (in module dissect.target.tools.dump.run) execute_function_on_target() (in module dissect.target.tools.utils) execute_functions() (in module dissect.target.tools.dump.run) execute_pipeline() (in module dissect.target.tools.dump.run) ExecutionOrder (class in acquire.acquire.acquire) ExecutionReport (class in dissect.target.report) ExFAT (class in dissect.fat) (class in dissect.fat.exfat) ExfatFilesystem (class in dissect.target.filesystems.exfat) ExfatFilesystemEntry (class in dissect.target.filesystems.exfat) ExfatFileTree (in module dissect.target.filesystems.exfat) exists() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) exit_code (dissect.target.plugins.os.windows.log.schedlgu.SchedLgU attribute) expand_config_file_paths() (dissect.target.helpers.network_managers.Parser method) expand_des_key() (in module dissect.target.plugins.os.windows.sam) expand_env() (dissect.target.plugins.os.windows.env.EnvironmentVariablePlugin method) expanduser() (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) EXPANSION (dissect.esedb.lcmapstring.SCRIPT attribute) explain_selector() (flow.record.selector.Selector method) export() (in module dissect.target.plugin) Expression (class in dissect.cstruct) (class in dissect.cstruct.expression) EXPRESSION (dissect.sql.sqlite3.Column attribute) ExpressionParserError ExpressionTokenizer (class in dissect.cstruct.expression) ExpressionTokenizerError EXT2 (in module dissect.extfs.c_ext) EXT3 (in module dissect.extfs.c_ext) EXT4 (in module dissect.extfs.c_ext) ext_def (in module dissect.extfs.c_ext) EXT_TYPE (flow.record.packer.RecordPacker attribute) extend() (flow.record.base.RecordDescriptor method) (flow.record.RecordDescriptor method) extend_record() (in module flow.record) (in module flow.record.base) ExtendableRecordDescriptor (class in dissect.target.helpers.record) extended_data_item_reader (in module dissect.etl.headers.event) ExtendedDataItemException, [1] extension (dissect.thumbcache.thumbcache_file.ThumbcacheEntry property) (dissect.thumbcache.ThumbcacheEntry property) extension() (dissect.target.plugins.os.windows.regf.shellbags.SHITEM method) EXTENSION_A (dissect.esedb.lcmapstring.SCRIPT attribute) EXTENSION_BLOCK (class in dissect.target.plugins.os.windows.regf.shellbags) EXTENSION_BLOCK_BEEF0004 (class in dissect.target.plugins.os.windows.regf.shellbags) EXTENSION_BLOCK_BEEF0005 (class in dissect.target.plugins.os.windows.regf.shellbags) EXTENSIONS (in module dissect.target.loaders.res) extensions() (dissect.target.plugins.apps.browser.brave.BravePlugin method) (dissect.target.plugins.apps.browser.chrome.ChromePlugin method) (dissect.target.plugins.apps.browser.chromium.ChromiumMixin method) (dissect.target.plugins.apps.browser.chromium.ChromiumPlugin method) (dissect.target.plugins.apps.browser.edge.EdgePlugin method) EXTENSIVE (acquire.acquire.acquire.VolatileProfile attribute) Extent (class in dissect.btrfs.stream) (class in dissect.hypervisor.backup.vma) (class in dissect.vmfs) (class in dissect.vmfs.lvm) extent_count (dissect.volume.lvm.metadata.Segment attribute) extent_size (dissect.volume.lvm.metadata.VolumeGroup attribute) extents() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.hypervisor.backup.vma.VMA method) extents_moved (dissect.volume.lvm.metadata.MirrorSegment attribute) ExtentStream (class in dissect.btrfs.stream) external_origin (dissect.volume.lvm.metadata.ThinSegment attribute) ExtFilesystem (class in dissect.target.filesystems.extfs) ExtFilesystemEntry (class in dissect.target.filesystems.extfs) ExtFS (class in dissect.extfs) (class in dissect.extfs.extfs) EXTFS_NEEDLE (in module dissect.target.loaders.phobos) EXTFS_NEEDLE_OFFSET (in module dissect.target.loaders.phobos) EXTRA_DATA_BLOCK_SIGNATURES (class in dissect.shellitem.lnk.c_lnk) extract_crypt_details() (in module dissect.target.plugins.os.unix.shadow) extract_drive_letter() (in module dissect.target.loaders.velociraptor) extract_name() (dissect.eventlog.wevt_object.WevtObject method) extract_path_info() (in module dissect.target.helpers.loaderutil) Extras (class in dissect.target.plugins.filesystem.ntfs.mft_timeline) ExtType (class in dissect.etl.headers.event) F failed() (in module dissect.target.plugin) FailedImport (class in dissect.target.helpers.lazy) FAILURE (acquire.acquire.collector.Outcome attribute) FALLBACK_LS_COLORS (in module dissect.target.tools.shell) FALLBACK_SEARCH_PATHS (in module dissect.target.plugins.filesystem.resolver) FastLeaf (class in dissect.regf.regf) FAT (class in dissect.fat.fat) fat() (dissect.ole.OLE method) (dissect.ole.ole.OLE method) FAT12_EOC (in module dissect.fat.c_fat) FAT_ENTRY_SIZE (in module dissect.fat.c_exfat) FatalError FatFilesystem (class in dissect.target.filesystems.fat) FatFilesystemEntry (class in dissect.target.filesystems.fat) FATFS (class in dissect.fat) (class in dissect.fat.fat) Fattype (in module dissect.fat.c_fat) fbb (dissect.vmfs.resource.ResourceManager property) fdc (dissect.vmfs.resource.ResourceManager property) fDerived (dissect.esedb.record.TagField attribute) Feature (class in dissect.util.feature) feature() (in module dissect.util.feature) feature_enabled() (in module dissect.util.feature) feature_flags() (in module dissect.util.feature) FeatureException FFS (class in dissect.ffs) (class in dissect.ffs.ffs) ffs_def (in module dissect.ffs.c_ffs) FfsFilesystem (class in dissect.target.filesystems.ffs) FfsFilesystemEntry (class in dissect.target.filesystems.ffs) fh (dissect.btrfs.stream.Stripe attribute) FID (in module dissect.fat.c_exfat) Field (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.structure) field_contains() (in module flow.record.selector) field_equals() (in module flow.record.selector) FIELD_IDENTIFIER (in module dissect.target.plugins.os.windows.defender) FIELD_MAP (dissect.target.plugins.os.windows.regf.firewall.FirewallPlugin attribute) (in module dissect.etl.manifest) (in module flow.record.adapter.sqlite) FIELD_MAPPINGS (in module dissect.target.plugins.os.windows.sru) FIELD_NAME_INVALID_CHARS_RE (in module dissect.target.plugins.apps.webserver.iis) FIELD_NAME_MAP (in module dissect.target.plugins.os.windows.ual) FIELD_NAMES (dissect.target.plugins.os.windows.regf.muicache.MuiCachePlugin attribute) field_regex() (in module flow.record.selector) fields (flow.record.base.RecordDescriptor property) (flow.record.RecordDescriptor property) FieldType (class in flow.record) (class in flow.record.base) (class in flow.record.fieldtypes) fieldtype() (in module flow.record.base) fieldtype_for_value() (in module flow.record.fieldtypes) FILE (acquire.acquire.collector.ArtifactType attribute) (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) File (class in dissect.target.loaders.res) file (dissect.hypervisor.disk.hdd.Image attribute) FILE (dissect.target.helpers.keychain.KeyType attribute) file() (dissect.ntfs.usnjrnl.UsnRecord method) (dissect.ntfs.UsnRecord method) FILE_ATTRIBUTE (in module dissect.archive.c_wim) file_attributes (dissect.ntfs.attr.FileName property) (dissect.ntfs.attr.StandardInformation property) file_descriptor() (dissect.vmfs.VMFS method) (dissect.vmfs.vmfs.VMFS method) FILE_ENTRY (class in dissect.target.plugins.os.windows.regf.shellbags) (in module dissect.fat.c_exfat) FILE_FILE_NAME_INDEX_PRESENT (in module dissect.ntfs.c_ntfs) file_filter() (acquire.acquire.collector.Collector method) FILE_FORMATTER (in module acquire.acquire.log) file_header (acquire.acquire.tools.decrypter.EncryptedFile property) FILE_HEADER_MAGIC (in module dissect.hypervisor.util.envelope) FILE_INFORMATION (dissect.target.plugins.filesystem.ntfs.utils.InformationType attribute) FILE_INFORMATION_CLASS (class in acquire.acquire.dynamic.windows.types) FILE_MAGIC (in module acquire.acquire.crypt) (in module dissect.evidence.asdf) (in module dissect.evidence.asdf.asdf) file_name (dissect.ntfs.attr.FileName property) FILE_NAME_DOS (in module dissect.ntfs.c_ntfs) FILE_NAME_NTFS (in module dissect.ntfs.c_ntfs) FILE_NUMBER_ATTRDEF (in module dissect.ntfs.c_ntfs) FILE_NUMBER_BADCLUS (in module dissect.ntfs.c_ntfs) FILE_NUMBER_BITMAP (in module dissect.ntfs.c_ntfs) FILE_NUMBER_BOOT (in module dissect.ntfs.c_ntfs) FILE_NUMBER_EXTEND (in module dissect.ntfs.c_ntfs) FILE_NUMBER_LOGFILE (in module dissect.ntfs.c_ntfs) FILE_NUMBER_MFT (in module dissect.ntfs.c_ntfs) FILE_NUMBER_MFTMIRR (in module dissect.ntfs.c_ntfs) FILE_NUMBER_ROOT (in module dissect.ntfs.c_ntfs) FILE_NUMBER_SECURE (in module dissect.ntfs.c_ntfs) FILE_NUMBER_UPCASE (in module dissect.ntfs.c_ntfs) FILE_NUMBER_VOLUME (in module dissect.ntfs.c_ntfs) file_object_pointer (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) FILE_PARAMETERS_GUID (in module dissect.hypervisor.disk.c_vhdx) FILE_RECORD_SEGMENT_IN_USE (in module dissect.ntfs.c_ntfs) file_reference (dissect.target.plugins.os.windows.regf.shellbags.SHITEM property) file_size (dissect.eventlog.CRIM property) (dissect.eventlog.wevt.CRIM property) (dissect.ntfs.attr.FileName property) (dissect.target.plugins.os.windows.regf.shellbags.SHITEM property) FILE_VERSION (in module acquire.acquire.crypt) FILE_XPATH (dissect.hypervisor.descriptor.ovf.OVF attribute) FileAppcompatRecord (in module dissect.target.plugins.os.windows.amcache) FileDescriptor (class in dissect.vmfs.vmfs) FileDescriptorResource (class in dissect.vmfs.resource) FileEntry (class in dissect.evidence.ad1) FileHashes (class in acquire.acquire.acquire) FileInfo (class in dissect.target.loaders.itunes) FileIoGuid (in module dissect.etl.utils) FileMeta (class in dissect.evidence.ad1) FileName (class in dissect.ntfs.attr) filename (flow.record.fieldtypes.uri property) filename() (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) FILENAME_ENTRY (in module dissect.fat.c_exfat) filename_index() (dissect.target.plugins.os.unix.locate.plocate.PLocateFile method) FileNameInformation (acquire.acquire.dynamic.windows.types.FILE_INFORMATION_CLASS attribute) FilenameNotAvailableError filenames() (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) FileNotFoundError, [1], [2], [3], [4], [5], [6], [7], [8], [9], [10], [11], [12], [13], [14], [15], [16], [17], [18] FileObject (class in dissect.evidence.ad1) filerenameop() (dissect.target.plugins.os.windows.generic.GenericPlugin method) FileRenameOperationRecord (in module dissect.target.plugins.os.windows.generic) files() (dissect.target.loaders.itunes.ITunesBackup method) (dissect.target.loaders.res.UPF method) (dissect.target.plugins.os.windows.amcache.AmcachePluginOldMixin method) filesize (class in flow.record.fieldtypes) FileStream (class in dissect.squashfs) (class in dissect.squashfs.squashfs) Filesystem (class in dissect.target.filesystem) FilesystemCollection (class in dissect.target.target) FilesystemEntry (class in dissect.target.filesystem) FilesystemError FilesystemFilenameCompactRecord (in module dissect.target.plugins.filesystem.ntfs.mft) FilesystemFilenameRecord (in module dissect.target.plugins.filesystem.ntfs.mft) FilesystemRecord (in module dissect.target.plugins.filesystem.walkfs) FILESYSTEMS (in module dissect.target.filesystem) FILESYSTEMS_ROOT (in module dissect.target.loaders.velociraptor) FilesystemStdCompactRecord (in module dissect.target.plugins.filesystem.ntfs.mft) FilesystemStdRecord (in module dissect.target.plugins.filesystem.ntfs.mft) FILETIME (dissect.etl.headers.logfile.ReservedFlags attribute) (dissect.eventlog.bxml.BxmlType attribute) filetype (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.xfs.xfs.INode property) FileType (in module dissect.vmfs.c_vmfs) FILETYPES (in module dissect.extfs.c_ext) (in module dissect.xfs.c_xfs) fill() (dissect.ole.ole.Chain method) fill_zero() (in module dissect.evidence.tools.asdf.dd) filled_bytes (dissect.etl.Buffer property) (dissect.etl.etl.Buffer property) filter() (acquire.acquire.dynamic.windows.handles.DuplicateFilter method) FILTER_CONNECTION_PORT (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) filter_out_by_path_match() (in module acquire.acquire.hashes) filter_out_by_value_match() (in module acquire.acquire.hashes) filter_out_huge_files() (in module acquire.acquire.hashes) filter_out_nonfiles() (in module acquire.acquire.hashes) filter_records() (in module dissect.target.plugins.os.windows.defender) FIN_WAIT1 (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) FIN_WAIT2 (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) finalize() (acquire.acquire.crypt.EncryptedStream method) (dissect.evidence.asdf.streams.CompressedStream method) (dissect.evidence.asdf.streams.Crc32Stream method) (dissect.evidence.asdf.streams.SubStreamBase method) find() (dissect.btrfs.tree.BTree method) (dissect.executable.elf.elf.Table method) (dissect.ntfs.util.AttributeMap method) (dissect.target.plugins.general.users.UsersPlugin method) find_adapter_for_stream() (in module flow.record.base) find_all() (dissect.target.loader.Loader static method) find_and_map_dirs() (in module dissect.target.loaders.dir) find_containers() (dissect.target.plugins.apps.browser.iexplore.WebCache method) find_current_mapping() (in module dissect.cim.utils) find_dirs() (in module dissect.target.loaders.dir) find_enc_files() (in module acquire.acquire.tools.decrypter) find_entry_path() (in module dissect.target.loaders.dir) find_files() (in module dissect.evidence.ewf) (in module dissect.target.containers.split) find_fs_directories() (in module dissect.target.loaders.velociraptor) find_image() (dissect.hypervisor.disk.hdd.Storage method) find_installs() (in module dissect.target.plugins.apps.container.docker) find_mdb_files() (dissect.target.plugins.os.windows.ual.UalPlugin method) find_needle() (in module dissect.eventlog.evt) find_needle_chunks() (dissect.target.plugins.general.scrape.ScrapePlugin method) find_needles() (dissect.target.plugins.general.scrape.ScrapePlugin method) find_node() (in module dissect.esedb.cursor) find_plugin_functions() (in module dissect.target.plugin) find_profile() (dissect.target.plugins.os.windows.regf.nethist.NethistPlugin method) find_pwr_dir() (in module dissect.target.loaders.res) find_py_files() (in module dissect.target.plugin) find_shot() (dissect.hypervisor.disk.hdd.Snapshots method) find_sid() (dissect.target.plugins.os.windows.recyclebin.RecyclebinPlugin method) find_sshd_directory() (in module dissect.target.plugins.apps.ssh.openssh) find_subvolume() (dissect.btrfs.Btrfs method) (dissect.btrfs.btrfs.Btrfs method) find_super_block() (in module dissect.volume.md.md) find_vm_inventory() (in module dissect.target.plugins.child.vmware_workstation) find_wsl_installs() (in module dissect.target.plugins.child.wsl) findall() (in module dissect.target.plugins.os.windows.catroot) finish() (acquire.acquire.gui.base.GUI method) (acquire.acquire.gui.base.Stub method) (acquire.acquire.gui.win32.Win32 method) (acquire.acquire.uploaders.minio.MinIO method) (acquire.acquire.uploaders.plugin.UploaderPlugin method) finished_sinks (dissect.target.tools.dump.state.DumpState property) FirefoxPlugin (class in dissect.target.plugins.apps.browser.firefox) firewall() (dissect.target.plugins.apps.av.symantec.SymantecPlugin method) (dissect.target.plugins.os.windows.regf.firewall.FirewallPlugin method) FirewallPlugin (class in dissect.target.plugins.os.windows.regf.firewall) first() (dissect.btrfs.tree.Cursor method) FixedDisk (class in dissect.hypervisor.disk.vhd) Flag (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.flag) flag() (dissect.shellitem.lnk.Lnk method) (dissect.shellitem.lnk.lnk.Lnk method) (dissect.shellitem.lnk.lnk.LnkInfo method) FlagInstance (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.flag) flags (dissect.etl.headers.headers.Marker property) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) (dissect.ntfs.attr.AttributeHeader property) (dissect.ntfs.attr.FileName property) (dissect.ntfs.AttributeHeader property) (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) (dissect.thumbcache.index.IndexEntry property) (dissect.thumbcache.IndexEntry property) (dissect.volume.lvm.metadata.LogicalVolume attribute) (dissect.volume.lvm.metadata.Segment property) (dissect.volume.lvm.metadata.VolumeGroup attribute) float (class in flow.record.fieldtypes) FLOAT (dissect.eventlog.bxml.BxmlType attribute) float_type (in module flow.record.fieldtypes) flow.record module flow.record.adapter module flow.record.adapter.archive module flow.record.adapter.avro module flow.record.adapter.broker module flow.record.adapter.csvfile module flow.record.adapter.elastic module flow.record.adapter.jsonfile module flow.record.adapter.line module flow.record.adapter.mongo module flow.record.adapter.split module flow.record.adapter.splunk module flow.record.adapter.sqlite module flow.record.adapter.stream module flow.record.adapter.text module flow.record.adapter.xlsx module flow.record.base module flow.record.exceptions module flow.record.fieldtypes module flow.record.fieldtypes.credential module flow.record.fieldtypes.net module flow.record.fieldtypes.net.ip module flow.record.fieldtypes.net.ipv4 module flow.record.fieldtypes.net.tcp module flow.record.fieldtypes.net.udp module flow.record.jsonpacker module flow.record.packer module flow.record.selector module flow.record.stream module flow.record.tools module flow.record.tools.geoip module flow.record.tools.rdump module flow.record.utils module flow.record.whitelist module flow_record_tz() (in module flow.record.fieldtypes) flush() (dissect.cstruct.BitBuffer method) (dissect.cstruct.bitbuffer.BitBuffer method) (dissect.target.tools.dump.utils.JsonLinesWriter method) (flow.record.adapter.AbstractWriter method) (flow.record.adapter.archive.ArchiveWriter method) (flow.record.adapter.avro.AvroWriter method) (flow.record.adapter.broker.BrokerWriter method) (flow.record.adapter.csvfile.CsvfileWriter method) (flow.record.adapter.elastic.ElasticWriter method) (flow.record.adapter.jsonfile.JsonfileWriter method) (flow.record.adapter.line.LineWriter method) (flow.record.adapter.mongo.MongoWriter method) (flow.record.adapter.split.SplitWriter method) (flow.record.adapter.splunk.SplunkWriter method) (flow.record.adapter.sqlite.SqliteWriter method) (flow.record.adapter.stream.StreamWriter method) (flow.record.adapter.text.TextWriter method) (flow.record.adapter.xlsx.XlsxWriter method) (flow.record.stream.RecordPrinter method) (flow.record.stream.RecordStreamWriter method) flush_cache() (acquire.acquire.log.DelayedFileHandler method) fmt() (in module dissect.util.tools.dump_nskeyedarchiver) fmt_ls_colors() (in module dissect.target.tools.shell) fname (in module dissect.target.loaders.res) fNullSmallPage (dissect.esedb.record.TagField attribute) folder (acquire.acquire.gui.base.GUI attribute) Folder (class in dissect.target.loaders.res) FolderHistoryRecord (in module dissect.target.plugins.os.windows.regf.7zip) folders() (dissect.target.loaders.res.UPF method) footer (acquire.acquire.tools.decrypter.EncryptedFile property) FOOTER_AEAD_MAGIC (in module dissect.hypervisor.util.envelope) FOOTER_CRYPTO_MAGIC (in module dissect.hypervisor.util.envelope) FOOTER_MAGIC (in module acquire.acquire.crypt) (in module dissect.evidence.asdf.asdf) format (dissect.volume.lvm.metadata.VolumeGroup attribute) format() (dissect.target.plugins.filesystem.ntfs.mft_timeline.Extras method) FORMAT_CPIO_BIN (in module dissect.util.cpio) FORMAT_CPIO_CRC (in module dissect.util.cpio) FORMAT_CPIO_HPBIN (in module dissect.util.cpio) FORMAT_CPIO_HPODC (in module dissect.util.cpio) FORMAT_CPIO_NEWC (in module dissect.util.cpio) FORMAT_CPIO_ODC (in module dissect.util.cpio) FORMAT_CPIO_UNKNOWN (in module dissect.util.cpio) FORMAT_INFO (in module dissect.target.plugins.filesystem.ntfs.mft_timeline) format_info() (in module dissect.target.plugins.filesystem.ntfs.mft_timeline) format_none_value() (in module dissect.target.plugins.filesystem.ntfs.mft_timeline) format_output_name() (in module acquire.acquire.utils) format_target_report() (in module dissect.target.report) format_value() (in module dissect.target.plugins.os.windows.log.evtx) formatter() (in module dissect.target.plugins.filesystem.ntfs.mft) FORTIOS (dissect.target.plugin.OperatingSystem attribute) FortiOSConfig (class in dissect.target.plugins.os.unix.linux.fortios._os) FortiOSPlugin (class in dissect.target.plugins.os.unix.linux.fortios._os) FortiOSUserRecord (in module dissect.target.plugins.os.unix.linux.fortios._os) fp (flow.record.adapter.avro.AvroReader attribute) (flow.record.adapter.avro.AvroWriter attribute) (flow.record.adapter.jsonfile.JsonfileReader attribute) (flow.record.adapter.jsonfile.JsonfileWriter attribute) (flow.record.adapter.line.LineWriter attribute) (flow.record.adapter.stream.StreamReader attribute) (flow.record.adapter.stream.StreamWriter attribute) (flow.record.adapter.text.TextWriter attribute) (flow.record.adapter.xlsx.XlsxReader attribute) (flow.record.adapter.xlsx.XlsxWriter attribute) (flow.record.stream.RecordPrinter attribute) (flow.record.stream.RecordStreamReader attribute) (flow.record.stream.RecordStreamWriter attribute) fragment (flow.record.fieldtypes.uri property) frame() (dissect.sql.sqlite3.WAL method) (dissect.sql.WAL method) frames() (dissect.sql.sqlite3.WAL method) (dissect.sql.WAL method) FREE_CLUSTER (in module dissect.fat.c_fat) FreeBsdPlugin (class in dissect.target.plugins.os.unix.bsd.freebsd._os) FreeClusterError, [1] FreeSegment (class in dissect.volume.lvm.metadata) from_bag_dict() (dissect.target.loaders.itunes.ClassKey class method) from_bytes() (dissect.ntfs.attr.Attribute class method) (dissect.ntfs.attr.AttributeHeader class method) (dissect.ntfs.Attribute class method) (dissect.ntfs.AttributeHeader class method) (dissect.ntfs.mft.MftRecord class method) (dissect.ntfs.MftRecord class method) from_dict() (dissect.target.tools.dump.state.DumpState class method) (dissect.volume.lvm.metadata.MetaBase class method) (dissect.volume.lvm.metadata.Segment class method) from_directory() (dissect.cim.CIM class method) (dissect.cim.cim.CIM class method) from_directory_information() (acquire.acquire.dynamic.windows.named_objects.NamedObject class method) from_elf() (dissect.executable.elf.elf.SectionTable class method) (dissect.executable.elf.elf.SegmentTable class method) (dissect.executable.elf.SectionTable class method) (dissect.executable.elf.SegmentTable class method) from_fh() (dissect.ntfs.attr.Attribute class method) (dissect.ntfs.attr.AttributeRecord class method) (dissect.ntfs.Attribute class method) (dissect.ntfs.AttributeRecord class method) (dissect.ntfs.mft.MftRecord class method) (dissect.ntfs.MftRecord class method) (dissect.target.plugins.os.unix.linux.fortios._os.FortiOSConfig class method) from_header() (dissect.archive.wim.Resource class method) from_id() (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm class method) (dissect.target.plugins.os.windows.dpapi.crypto.HashAlgorithm class method) from_line() (dissect.target.plugins.os.unix.linux.proc.NetSocket class method) (dissect.target.plugins.os.unix.linux.proc.PacketSocket class method) (dissect.target.plugins.os.unix.linux.proc.UnixSocket class method) (dissect.target.plugins.os.windows.log.schedlgu.SchedLgU class method) from_name() (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm class method) (dissect.target.plugins.os.windows.dpapi.crypto.HashAlgorithm class method) from_path() (dissect.target.tools.dump.state.DumpState class method) from_posix() (flow.record.fieldtypes.path class method) from_section_table() (dissect.executable.elf.elf.Section class method) (dissect.executable.elf.Section class method) from_segment_table() (dissect.executable.elf.elf.Segment class method) (dissect.executable.elf.Segment class method) from_short_header() (dissect.archive.wim.Resource class method) from_str() (acquire.acquire.dynamic.windows.types.UNICODE_STRING class method) from_stream() (dissect.eventlog.bxml.BxmlTemplateDescriptor class method) from_symbol_table() (dissect.executable.elf.elf.Symbol class method) (dissect.executable.elf.Symbol class method) from_text() (dissect.hypervisor.descriptor.vmx.KeySafe class method) (dissect.hypervisor.util.envelope.KeyStore class method) from_unix() (in module dissect.util.ts) from_unix_ms() (in module dissect.util.ts) from_unix_ns() (in module dissect.util.ts) from_unix_us() (in module dissect.util.ts) from_user_home() (in module acquire.acquire.acquire) from_windows() (flow.record.fieldtypes.path class method) (flow.record.fieldtypes.uri class method) from_xml() (dissect.hypervisor.disk.hdd.XMLEntry class method) frombuf() (dissect.hypervisor.util.vmtar.VisorTarInfo class method) (dissect.util.cpio.CpioInfo class method) fromtarfile() (dissect.util.cpio.CpioInfo class method) fs (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry attribute) (dissect.target.filesystems.jffs.JFFSFilesystemEntry attribute) (dissect.target.filesystems.smb.SmbFilesystemEntry attribute) fs_attrs() (in module dissect.target.helpers.fsutil) FS_NAMES (in module dissect.volume.disk.schemes.bsd) FS_NEEDLES (in module dissect.target.loaders.phobos) FS_SUPPORTED (dissect.target.plugins.filesystem.icat.ICatPlugin attribute) fsb_to_bb() (in module dissect.xfs.xfs) fsbtodb() (in module dissect.ffs.ffs) FT_MAP (in module dissect.btrfs.c_btrfs) fua (dissect.volume.lvm.metadata.WriteCacheSegment attribute) FULL (acquire.acquire.acquire.BsdProfile attribute) (acquire.acquire.acquire.ESXiProfile attribute) (acquire.acquire.acquire.LinuxProfile attribute) (acquire.acquire.acquire.OSXProfile attribute) (acquire.acquire.acquire.WindowsProfile attribute) full_path (dissect.btrfs.btrfs.INode property) (dissect.btrfs.INode property) full_path() (dissect.ntfs.attr.FileName method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.ntfs.usnjrnl.UsnRecord method) (dissect.ntfs.UsnRecord method) full_paths() (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) fullmap() (dissect.eventlog.wevtutil.WevtutilWrapper method) FULLSIZE (dissect.esedb.lcmapstring.CASE attribute) FULLWIDTH (dissect.esedb.lcmapstring.CASE attribute) func (dissect.target.tools.dump.run.RecordStreamElement attribute) (dissect.target.tools.dump.state.Sink attribute) FUNC_DOC_TEMPLATE (in module dissect.target.helpers.docs) func_errors (dissect.target.report.TargetExecutionReport attribute) FUNC_EXEC (dissect.target.target.Event attribute) FUNC_EXEC_ERROR (dissect.target.target.Event attribute) func_execs (dissect.target.report.TargetExecutionReport attribute) FUNCTION_OUTPUT_DESCRIPTION (in module dissect.target.helpers.docs) FUNCTION_WHITELIST (in module flow.record.selector) function_with_an_exception() (in module codestyle) functions (dissect.target.tools.dump.state.DumpState attribute) FunctionTuple (in module dissect.target.target) FUSE_VERSION (in module dissect.target.tools.mount) FW_ACTION (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_APPLICATION (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_BEGIN_TIME (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_DIRECTION (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_END_TIME (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_LOCAL_IP (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_LOCAL_IP6 (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_LOCAL_PORT (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_LOCATION (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_PROTOCOL (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_REMOTE_HOST_NAME (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_REMOTE_IP (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_REMOTE_IP6 (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_REMOTE_PORT (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_REPETITION (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_RULE_ID (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_RULE_NAME (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_SEVERITY (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_TIMESTAMP (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) FW_USER (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) G GAME_FOLDER (class in dissect.target.plugins.os.windows.regf.shellbags) gateway (dissect.target.helpers.network_managers.NetworkManager property) gateway() (dissect.target.plugins.os.unix.linux._os.LinuxPlugin method) gdi32 (in module acquire.acquire.gui.win32) gen_dynamic_block() (dissect.cstruct.Compiler method) (dissect.cstruct.compiler.Compiler method) gen_read_block() (dissect.cstruct.Compiler method) (dissect.cstruct.compiler.Compiler method) gen_struct_class() (dissect.cstruct.Compiler method) (dissect.cstruct.compiler.Compiler method) generate() (in module dissect.target.plugin) generate_addr() (in module dissect.target.helpers.fsutil) generate_argparse_for_bound_method() (in module dissect.target.tools.utils) generate_argparse_for_plugin() (in module dissect.target.tools.utils) generate_argparse_for_plugin_class() (in module dissect.target.tools.utils) generate_argparse_for_unbound_method() (in module dissect.target.tools.utils) generate_from_file() (in module dissect.etl.manifest) generate_from_xml() (in module dissect.etl.manifest) generate_record() (in module dissect.target.plugins.filesystem.walkfs) GENERATED (in module dissect.target.plugin) GENERIC_COOKIE_FIELDS (in module dissect.target.plugins.apps.browser.browser) GENERIC_DOWNLOAD_RECORD_FIELDS (in module dissect.target.plugins.apps.browser.browser) GENERIC_EXTENSION_RECORD_FIELDS (in module dissect.target.plugins.apps.browser.browser) GENERIC_HISTORY_RECORD_FIELDS (in module dissect.target.plugins.apps.browser.browser) GENERIC_THUMBCACHE_FIELDS (in module dissect.target.plugins.os.windows.thumbcache) GenericPlugin (class in dissect.target.plugins.os.unix.generic) (class in dissect.target.plugins.os.unix.linux.fortios.generic) (class in dissect.target.plugins.os.windows.generic) GeoRecord (in module flow.record.tools.geoip) georecord_for_ip() (in module flow.record.tools.geoip) get() (acquire.acquire.uploaders.plugin_registry.PluginRegistry method) (dissect.archive.wim.Image method) (dissect.btrfs.Btrfs method) (dissect.btrfs.btrfs.Btrfs method) (dissect.btrfs.btrfs.INode method) (dissect.btrfs.btrfs.Subvolume method) (dissect.btrfs.INode method) (dissect.btrfs.Subvolume method) (dissect.btrfs.tree.Cursor method) (dissect.cim.objects.Objects method) (dissect.esedb.record.Record method) (dissect.esedb.record.RecordData method) (dissect.eventlog.bxml.BxmlSub method) (dissect.evidence.ad1.AD1 method) (dissect.extfs.ExtFS method) (dissect.extfs.extfs.ExtFS method) (dissect.fat.fat.FAT method) (dissect.fat.fat.FATFS method) (dissect.fat.FATFS method) (dissect.ffs.FFS method) (dissect.ffs.ffs.FFS method) (dissect.hypervisor.disk.vhd.BlockAllocationTable method) (dissect.hypervisor.disk.vhdx.BlockAllocationTable method) (dissect.hypervisor.disk.vhdx.MetadataTable method) (dissect.hypervisor.disk.vhdx.RegionTable method) (dissect.jffs.JFFS2 method) (dissect.jffs.jffs2.JFFS2 method) (dissect.ntfs.Mft method) (dissect.ntfs.mft.Mft method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.ole.OLE method) (dissect.ole.ole.OLE method) (dissect.sql.sqlite3.Row method) (dissect.sql.sqlite3.WALCheckpoint method) (dissect.squashfs.SquashFS method) (dissect.squashfs.squashfs.SquashFS method) (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.RootFilesystem method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualFilesystem method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.ad1.AD1Filesystem method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsFilesystem method) (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsSubvolumeFilesystem method) (dissect.target.filesystems.cb.CbFilesystem method) (dissect.target.filesystems.cb.CbFilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.config.ConfigurationFilesystem method) (dissect.target.filesystems.dir.DirectoryFilesystem method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.exfat.ExfatFilesystem method) (dissect.target.filesystems.exfat.ExfatFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystem method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.fat.FatFilesystem method) (dissect.target.filesystems.fat.FatFilesystemEntry method) (dissect.target.filesystems.ffs.FfsFilesystem method) (dissect.target.filesystems.ffs.FfsFilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystem method) (dissect.target.filesystems.jffs.JFFSFilesystem method) (dissect.target.filesystems.jffs.JFFSFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystem method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.smb.SmbFilesystem method) (dissect.target.filesystems.smb.SmbFilesystemEntry method) (dissect.target.filesystems.squashfs.SquashFSFilesystem method) (dissect.target.filesystems.squashfs.SquashFSFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystem method) (dissect.target.filesystems.vmfs.VmfsFilesystem method) (dissect.target.filesystems.vmfs.VmfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystem method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) (dissect.target.filesystems.zip.ZipFilesystem method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) (dissect.target.helpers.configutil.ConfigurationParser method) (dissect.target.helpers.regutil.KeyCollection method) (dissect.target.helpers.regutil.RegistryKey method) (dissect.target.loaders.itunes.FileInfo method) (dissect.target.plugins.general.config.ConfigurationTreePlugin method) (dissect.target.plugins.general.users.UsersPlugin method) (dissect.target.plugins.os.unix.linux.proc.ProcProcess method) (dissect.util.plist.NSKeyedArchiver method) (dissect.util.plist.NSObject method) (dissect.vmfs.resource.ResourceFile method) (dissect.vmfs.resource.ResourceManager method) (dissect.vmfs.VMFS method) (dissect.vmfs.vmfs.VMFS method) (dissect.xfs.XFS method) (dissect.xfs.xfs.XFS method) get_actions() (dissect.target.plugins.os.windows.task_helpers.tasks_job.AtTask method) (dissect.target.plugins.os.windows.task_helpers.tasks_xml.XmlTask method) get_all_fields() (flow.record.base.RecordDescriptor method) (flow.record.RecordDescriptor method) get_all_keys() (in module dissect.target.helpers.keychain) get_all_records() (dissect.target.plugin.Plugin method) get_allocation_group() (dissect.xfs.XFS method) (dissect.xfs.xfs.XFS method) get_array() (dissect.cim.classes.DataRegion method) get_cache_paths() (dissect.target.plugins.os.windows.thumbcache.ThumbcachePlugin method) get_children_info() (in module dissect.target.tools.info) get_class_definition() (dissect.cim.CIM method) (dissect.cim.cim.CIM method) get_class_instance() (dissect.cim.CIM method) (dissect.cim.cim.CIM method) get_cluster_chain() (dissect.fat.ExFAT method) (dissect.fat.exfat.ExFAT method) get_cluster_type() (in module dissect.hypervisor.disk.qcow2) get_config_value() (dissect.target.helpers.network_managers.LinuxNetworkManager method) get_counts_per_module_per_outcome() (acquire.acquire.collector.CollectionReport method) get_current_utc_time() (in module dissect.target.tools.dump.utils) get_data_path() (in module dissect.target.plugins.apps.container.docker) get_days_of_week() (dissect.target.plugins.os.windows.task_helpers.tasks_job.AtTask method) get_description_dict() (in module dissect.target.plugins.general.plugins) get_descriptor() (dissect.volume.vss.BlockMap method) get_descriptors_on_nonprivate_methods() (in module dissect.target.plugin) get_device() (dissect.target.loaders.cb.CbLoader method) get_disks_info() (in module dissect.target.tools.info) get_docstring() (in module dissect.target.helpers.docs) get_drive_letter() (in module dissect.target.plugins.filesystem.ntfs.utils) get_dst_range() (in module dissect.target.plugins.os.windows.datetime) get_element() (dissect.target.plugins.os.windows.task_helpers.tasks_xml.XmlTask method) get_entry() (dissect.cim.mappings.Mapping method) get_exported_plugins() (in module dissect.target.plugins.general.plugins) get_external_module_paths() (in module dissect.target.plugin) get_field_tuples() (flow.record.base.RecordDescriptor method) (flow.record.RecordDescriptor method) get_file_handler() (in module acquire.acquire.log) get_file_object() (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry method) get_filetime_for_event() (dissect.etl.ETL method) (dissect.etl.etl.ETL method) get_flags_data() (dissect.target.plugins.os.windows.task_helpers.tasks_job.AtTask method) get_formatted_exception() (in module acquire.acquire.utils) get_formatted_report() (dissect.target.report.ExecutionReport method) get_full_formatted_report() (in module acquire.acquire.collector) get_full_func_name() (in module dissect.target.helpers.docs) get_full_path() (in module dissect.ntfs.util) get_full_sink_path() (dissect.target.tools.dump.state.DumpState method) get_func_description() (in module dissect.target.helpers.docs) get_func_details() (in module dissect.target.helpers.docs) get_function() (dissect.target.Target method) (dissect.target.target.Target method) get_handle_name() (in module acquire.acquire.dynamic.windows.handles) get_handle_type_info() (in module acquire.acquire.dynamic.windows.handles) get_handles() (in module acquire.acquire.dynamic.windows.handles) get_inode() (dissect.extfs.ExtFS method) (dissect.extfs.extfs.ExtFS method) (dissect.xfs.XFS method) (dissect.xfs.xfs.AllocationGroup method) (dissect.xfs.xfs.XFS method) get_invalid_sinks() (dissect.target.tools.dump.state.DumpState method) get_kernel_hash() (in module dissect.target.plugins.os.unix.linux.fortios._os) get_keys_for_identifier() (dissect.target.volume.EncryptedVolumeSystem method) get_keys_for_identifiers() (dissect.target.volume.EncryptedVolumeSystem method) get_keys_for_provider() (in module dissect.target.helpers.keychain) get_keys_without_identifier() (dissect.target.volume.EncryptedVolumeSystem method) get_keys_without_provider() (in module dissect.target.helpers.keychain) get_log_dirs() (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin method) get_log_files() (dissect.target.plugins.apps.av.mcafee.McAfeePlugin method) get_log_paths() (dissect.target.plugins.apps.webserver.apache.ApachePlugin method) (dissect.target.plugins.apps.webserver.caddy.CaddyPlugin method) (dissect.target.plugins.apps.webserver.nginx.NginxPlugin method) (dissect.target.plugins.os.unix.log.audit.AuditPlugin method) get_logs() (dissect.target.plugins.os.windows.log.evt.WindowsEventlogsMixin method) get_logs_from_dir() (dissect.target.plugins.os.windows.log.evt.WindowsEventlogsMixin method) get_logs_from_registry() (dissect.target.plugins.os.windows.log.evt.WindowsEventlogsMixin method) get_long_value() (dissect.esedb.table.Table method) get_modifier_function() (in module dissect.target.helpers.record_modifier) get_months_of_year() (dissect.target.plugins.os.windows.task_helpers.tasks_job.AtTask method) get_name() (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES class method) get_names() (dissect.target.tools.shell.TargetCmd method) get_nested_attr() (in module dissect.target.tools.dump.utils) get_nonprivate_attribute_names() (in module dissect.target.plugin) get_nonprivate_attributes() (in module dissect.target.plugin) get_nonprivate_methods() (in module dissect.target.plugin) get_optional() (in module dissect.target.plugins.os.unix.log.journal) get_optional_func() (in module dissect.target.tools.info) get_owner_and_group() (in module dissect.target.plugins.filesystem.ntfs.utils) get_path_details() (in module acquire.acquire.hashes) get_paths_from_dir() (in module acquire.acquire.hashes) get_plugin_class_for_func() (in module dissect.target.helpers.docs) get_plugin_description() (in module dissect.target.helpers.docs) (in module dissect.target.plugins.general.plugins) get_plugin_functions_desc() (in module dissect.target.helpers.docs) get_plugin_overview() (in module dissect.target.helpers.docs) get_plugins_by_func_name() (in module dissect.target.plugin) get_plugins_by_namespace() (in module dissect.target.plugin) get_primary_key_from_constraint() (in module dissect.sql.utils) get_quarantine_entries() (dissect.target.plugins.os.windows.defender.MicrosoftDefenderPlugin method) get_raw() (dissect.target.plugins.os.windows.task_helpers.tasks_xml.XmlTask method) get_real_func_obj() (in module dissect.target.helpers.docs) get_record_by_type() (flow.record.base.GroupedRecord method) (flow.record.GroupedRecord method) get_record_size() (in module dissect.target.plugins.filesystem.ntfs.utils) get_records_per_module_per_outcome() (acquire.acquire.collector.CollectionReport method) get_relative_inode() (dissect.xfs.XFS method) (dissect.xfs.xfs.XFS method) get_relative_sink_path() (in module dissect.target.tools.dump.utils) get_report_summary() (in module acquire.acquire.collector) get_required_fields() (flow.record.base.RecordDescriptor static method) (flow.record.RecordDescriptor static method) get_resource() (dissect.vmfs.resource.ResourceFile method) (dissect.vmfs.resource.ResourceManager method) get_resource_stream() (in module dissect.etl.manifest) get_resource_string() (in module dissect.etl.manifest) (in module dissect.target.helpers.localeutil) get_runs() (dissect.hypervisor.disk.vmdk.SparseDisk method) get_sink() (dissect.target.tools.dump.state.DumpState method) get_sink_dir_by_func() (in module dissect.target.tools.dump.utils) get_sink_dir_by_target() (in module dissect.target.tools.dump.utils) get_sink_filename() (in module dissect.target.tools.dump.utils) get_sink_writer() (in module dissect.target.tools.dump.utils) get_snapshot_chain() (dissect.hypervisor.disk.hdd.Descriptor method) get_spec_additions() (acquire.acquire.acquire.ActiveDirectory class method) (acquire.acquire.acquire.DHCP class method) (acquire.acquire.acquire.EventLogs class method) (acquire.acquire.acquire.Exchange class method) (acquire.acquire.acquire.History class method) (acquire.acquire.acquire.IIS class method) (acquire.acquire.acquire.Module class method) (acquire.acquire.acquire.NTDS class method) (acquire.acquire.acquire.Registry class method) (acquire.acquire.acquire.WER class method) (acquire.acquire.acquire.WinArpCache class method) (acquire.acquire.acquire.WinMemFiles class method) (acquire.acquire.acquire.WinRDPSessions class method) get_specs() (acquire.acquire.acquire.FileHashes class method) get_state_path() (dissect.target.tools.dump.state.DumpState class method) get_string() (dissect.cim.classes.DataRegion method) get_subcluster_range_type() (in module dissect.hypervisor.disk.qcow2) get_subcluster_type() (in module dissect.hypervisor.disk.qcow2) get_table() (dissect.esedb.tools.sru.SRU method) get_table_entries() (dissect.esedb.tools.sru.SRU method) get_table_records() (dissect.esedb.tools.ual.UAL method) get_tables() (dissect.esedb.tools.ual.UAL method) get_target_attribute() (in module dissect.target.tools.utils) get_target_info() (in module dissect.target.tools.info) get_target_report() (dissect.target.report.ExecutionReport method) get_targets() (in module dissect.target.tools.dump.run) get_tasks() (dissect.target.plugins.os.windows.task_helpers.tasks_xml.ScheduledTasks method) get_token() (dissect.cstruct.expression.ExpressionTokenizer method) get_triggers() (dissect.target.plugins.os.windows.task_helpers.tasks_job.AtTask method) (dissect.target.plugins.os.windows.task_helpers.tasks_xml.XmlTask method) get_type() (in module flow.record.selector) get_user() (dissect.target.plugins.os.windows.registry.RegistryPlugin method) get_user_details() (dissect.target.plugins.os.windows.registry.RegistryPlugin method) get_user_name() (in module acquire.acquire.utils) get_utc_now() (in module acquire.acquire.utils) get_utc_now_str() (in module acquire.acquire.utils) get_value() (dissect.cim.classes.DataRegion method) get_volume_identifier() (in module dissect.target.plugins.filesystem.ntfs.utils) get_volumes_info() (in module dissect.target.tools.info) getattr() (dissect.target.helpers.mount.DissectMount method) GetCurrentProcessId (in module acquire.acquire.dynamic.windows.handles) getfields() (flow.record.base.RecordDescriptor method) (flow.record.RecordDescriptor method) GetLastError (in module acquire.acquire.dynamic.windows.handles) getlogger() (in module dissect.target.target) getNextRow() (dissect.esedb.tools.impacket.ESENT_DB method) gettypename() (flow.record.base.DynamicFieldtypeModule method) getxattr (dissect.target.helpers.mount.DissectMount attribute) gid (dissect.squashfs.INode property) (dissect.squashfs.squashfs.INode property) gid() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.jffs.jffs2.INode method) GLOB (acquire.acquire.collector.ArtifactType attribute) glob() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) glob_ext() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.plugins.os.windows.registry.RegistryPlugin method) (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.regutil) glob_ext0() (in module dissect.target.helpers.regutil) glob_ext1() (in module dissect.target.helpers.regutil) GLOB_INDEX_REGEX (in module dissect.target.helpers.regutil) GLOB_MAGIC_REGEX (in module dissect.target.helpers.regutil) GLOB_PATHS (dissect.target.plugins.os.windows.tasks.TasksPlugin attribute) glob_split() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.regutil) GLOBAL (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin attribute) GLOBS (dissect.target.plugins.apps.remoteaccess.teamviewer.TeamviewerPlugin attribute) gnulocate_def (in module dissect.target.plugins.os.unix.locate.gnulocate) GNULocateFile (class in dissect.target.plugins.os.unix.locate.gnulocate) GNULocatePlugin (class in dissect.target.plugins.os.unix.locate.gnulocate) GNULocateRecord (in module dissect.target.plugins.os.unix.locate.gnulocate) GPT (class in dissect.volume.disk.schemes) (class in dissect.volume.disk.schemes.gpt) gpt_def (in module dissect.volume.disk.schemes.gpt) granted_access (acquire.acquire.dynamic.windows.types.SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX property) Greater (dissect.ntfs.index.Match attribute) GREEK (dissect.esedb.lcmapstring.SCRIPT attribute) GREEN (dissect.target.helpers.cyber.Color attribute) group (dissect.etl.headers.system.SystemSpecificHeader property) group() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) GROUP_GUID_MAP (in module dissect.etl.utils) GroupedPrefetchRecord (in module dissect.target.plugins.os.windows.prefetch) GroupedRecord (class in flow.record) (class in flow.record.base) GUI (class in acquire.acquire.gui.base) gui() (acquire.acquire.gui.base.GUI class method) gui_display_text (acquire.acquire.gui.win32.Win32 attribute) GUID (dissect.etl.headers.headers.EventProperty attribute) (dissect.eventlog.bxml.BxmlType attribute) guid (dissect.hypervisor.disk.hdd.Image attribute) (dissect.hypervisor.disk.hdd.Shot attribute) (dissect.squashfs.INode property) (dissect.squashfs.squashfs.INode property) GUIError GZIP (dissect.target.tools.dump.utils.Compression attribute) GZIP_MAGIC (in module flow.record.base) H Handle (class in acquire.acquire.dynamic.windows.types) handle() (dissect.target.loaders.smb.SmbRegistryKey method) handle_attributes (acquire.acquire.dynamic.windows.types.SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX property) handle_cat() (in module dissect.evidence.tools.asdf.meta) handle_hash() (in module dissect.evidence.tools.asdf.meta) handle_ls() (in module dissect.evidence.tools.asdf.meta) handle_value (acquire.acquire.dynamic.windows.types.SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX property) HandleNotClosedSuccessfullyError hardlink_to() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) HAS_AVRO (in module flow.record.base) has_backing_file (dissect.hypervisor.disk.qcow2.QCow2 property) HAS_BZ2 (in module flow.record.base) has_child (dissect.ole.ole.DirectoryEntry property) has_data_file (dissect.hypervisor.disk.qcow2.QCow2 property) has_default_value (dissect.cim.cim.Property property) (dissect.cim.classes.ClassInstanceProperty property) has_dynprops (dissect.cim.classes.Dynprops property) HAS_ENVELOPE (in module dissect.target.plugins.os.unix.esxi._os) HAS_FCNTL (in module acquire.acquire.volatilestream) has_field() (in module flow.record.selector) has_function() (dissect.target.Target method) (dissect.target.target.Target method) HAS_FUSE3 (in module dissect.target.helpers.mount), [1] has_glob_magic() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.regutil) has_left_sibling (dissect.ole.ole.DirectoryEntry property) HAS_LZ4 (in module dissect.target.tools.dump.utils) (in module flow.record.base) has_offset() (dissect.volume.vss.StoreBitmap method) has_phrase() (dissect.hypervisor.descriptor.vmx.Pair method) HAS_PYCRYPTODOME (in module acquire.acquire.crypt) (in module dissect.hypervisor.descriptor.vmx) (in module dissect.hypervisor.util.envelope) (in module dissect.target.loaders.itunes) (in module dissect.target.plugins.os.unix.linux.fortios._os) HAS_PYSTANDALONE (in module dissect.hypervisor.descriptor.vmx) (in module dissect.hypervisor.util.envelope) (in module dissect.target.loaders.itunes) has_right_sibling (dissect.ole.ole.DirectoryEntry property) has_small_pages() (dissect.esedb.EseDB method) (dissect.esedb.esedb.EseDB method) has_stream() (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) has_subclusters (dissect.hypervisor.disk.qcow2.QCow2 property) HAS_TQDM (in module dissect.evidence.tools.asdf.dd) HAS_ZONE_INFO (in module flow.record.fieldtypes) HAS_ZSTD (in module dissect.btrfs.stream) (in module dissect.hypervisor.disk.qcow2) (in module dissect.target.plugins.os.unix.locate.plocate) (in module dissect.target.tools.dump.utils) (in module flow.record.base) HASH (dissect.target.helpers.record_modifier.Modifier attribute) hash (dissect.thumbcache.thumbcache_file.ThumbcacheEntry property) (dissect.thumbcache.ThumbcacheEntry property) hash() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) HASH_ALGORITHMS (in module dissect.target.plugins.os.windows.dpapi.crypto) hash_fileobj() (in module dissect.evidence.tools.asdf.verify) hash_to_image_id() (in module dissect.target.plugins.apps.container.docker) hash_uri() (in module dissect.target.helpers.hashutil) hash_uri_records() (in module dissect.target.helpers.hashutil) hash_zone_threads (dissect.volume.lvm.metadata.VdoPoolSegment attribute) HashAlgorithm (class in dissect.target.plugins.os.windows.dpapi.crypto) HashedStream (class in dissect.evidence.asdf.streams) hashfileobj() (in module dissect.evidence.tools.asdf.meta) HashFunc (class in acquire.acquire.hashes) HashLeaf (class in dissect.regf.regf) hashname() (in module dissect.regf.regf) hashtable() (dissect.target.plugins.os.unix.locate.plocate.PLocateFile method) HAVE_ASTOR (in module flow.record.selector) HCURSOR (in module acquire.acquire.gui.win32) HDD (class in dissect.hypervisor.disk.hdd) hdd_def (in module dissect.hypervisor.disk.c_hdd) HddContainer (class in dissect.target.containers.hdd) HDS (class in dissect.hypervisor.disk.hdd) HdsContainer (class in dissect.target.containers.hds) header (acquire.acquire.tools.decrypter.EncryptedFile property) Header (class in dissect.etl.headers.headers) header (dissect.etl.Buffer property) (dissect.etl.etl.Buffer property) (dissect.etl.etl.EventRecord property) (dissect.etl.headers.headers.Header property) (dissect.etl.headers.logfile.LogfileHeader property) (dissect.thumbcache.index.IndexEntry property) (dissect.thumbcache.index.ThumbnailIndex property) (dissect.thumbcache.IndexEntry property) (dissect.thumbcache.thumbcache_file.ThumbcacheFile property) (dissect.thumbcache.ThumbcacheFile property) (dissect.thumbcache.ThumbnailIndex property) HEADER (in module dissect.target.loaders.cyber) header() (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) header_dev (in module dissect.eventlog.wevt) header_extensions (dissect.etl.headers.event.EventHeader property) HEADER_FLAG (in module dissect.archive.c_wim) HEADER_FLAGS (dissect.etl.headers.headers.Marker attribute) HEADER_FOOTER_SIZE (in module dissect.util.compression.xz) HEADER_MAGIC (in module acquire.acquire.crypt) HEADER_MASK (dissect.etl.headers.headers.Marker attribute) HEADER_SIZE (dissect.target.plugins.os.unix.locate.plocate.PLocateFile attribute) header_size (dissect.volume.lvm.metadata.VdoPoolSegment attribute) header_type (dissect.etl.headers.headers.Marker property) HEADERS (in module dissect.etl.headers.utils) HeaderSection (class in dissect.evidence.ewf) HeapGuid (in module dissect.etl.utils) HEBREW (dissect.esedb.lcmapstring.SCRIPT attribute) HEXBIN_SUFFIX (in module dissect.cstruct.expression) hexdigest() (dissect.evidence.asdf.streams.HashedStream method) hexdigit() (dissect.cstruct.expression.ExpressionTokenizer method) hexdump() (in module dissect.cstruct) (in module dissect.cstruct.utils) HEXINT32 (dissect.eventlog.bxml.BxmlType attribute) HEXINT64 (dissect.eventlog.bxml.BxmlType attribute) HID (dissect.target.plugins.os.windows.regf.usb.UsbPlugin attribute) high_watermark (dissect.volume.lvm.metadata.WriteCacheSegment attribute) highest_vcn (dissect.ntfs.attr.AttributeHeader property) (dissect.ntfs.AttributeHeader property) HINT_NEEDLE (in module dissect.target.plugins.os.windows.catroot) historical_logical_volumes (dissect.volume.lvm.metadata.VolumeGroup attribute) HistoricalLogicalVolume (class in dissect.volume.lvm.metadata) History (class in acquire.acquire.acquire) history() (dissect.target.plugins.apps.browser.brave.BravePlugin method) (dissect.target.plugins.apps.browser.chrome.ChromePlugin method) (dissect.target.plugins.apps.browser.chromium.ChromiumMixin method) (dissect.target.plugins.apps.browser.chromium.ChromiumPlugin method) (dissect.target.plugins.apps.browser.edge.EdgePlugin method) (dissect.target.plugins.apps.browser.firefox.FirefoxPlugin method) (dissect.target.plugins.apps.browser.iexplore.InternetExplorerPlugin method) (dissect.target.plugins.apps.browser.iexplore.WebCache method) HitmanAlertRecord (in module dissect.target.plugins.apps.av.sophos) hitmanlogs() (dissect.target.plugins.apps.av.sophos.SophosPlugin method) hive (dissect.target.loaders.smb.SmbRegistryKey attribute) HiveCollection (class in dissect.target.helpers.regutil) HIVES (acquire.acquire.acquire.Registry attribute) HiveUnavailableError HIWORD() (in module acquire.acquire.gui.win32) HMAC_MAP (in module dissect.hypervisor.descriptor.vmx) Home (class in acquire.acquire.acquire) home() (dissect.target.helpers.compat.path_310.TargetPath class method) (dissect.target.helpers.compat.path_311.TargetPath class method) (dissect.target.helpers.compat.path_312.TargetPath class method) (dissect.target.helpers.compat.path_39.TargetPath class method) home_path (dissect.target.plugins.general.users.UserDetails attribute) hook_id (dissect.etl.headers.system.SystemSpecificHeader property) hostname (flow.record.fieldtypes.uri property) hostname() (dissect.target.loaders.profile.ProfileOSPlugin method) (dissect.target.loaders.res.ResOSPlugin method) (dissect.target.plugin.OSPlugin method) (dissect.target.plugins.general.default.DefaultPlugin method) (dissect.target.plugins.os.unix._os.UnixPlugin method) (dissect.target.plugins.os.unix.bsd._os.BsdPlugin method) (dissect.target.plugins.os.unix.bsd.citrix._os.CitrixPlugin method) (dissect.target.plugins.os.unix.bsd.ios._os.IOSPlugin method) (dissect.target.plugins.os.unix.bsd.openbsd._os.OpenBsdPlugin method) (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin method) (dissect.target.plugins.os.unix.esxi._os.ESXiPlugin method) (dissect.target.plugins.os.unix.linux.android._os.AndroidPlugin method) (dissect.target.plugins.os.unix.linux.fortios._os.FortiOSPlugin method) (dissect.target.plugins.os.windows._os.WindowsPlugin method) HOUR (in module dissect.target.plugins.os.windows.datetime) human_readable_size() (in module flow.record.fieldtypes) hwnd (acquire.acquire.gui.win32.Win32 attribute) hyperv_def (in module dissect.hypervisor.descriptor.c_hyperv) HyperVChildTargetPlugin (class in dissect.target.plugins.child.hyperv) HyperVFile (class in dissect.hypervisor.descriptor.hyperv) HypervisorTraceGuid (in module dissect.etl.utils) HypervisorXTraceGuid (in module dissect.etl.utils) HyperVLoader (class in dissect.target.loaders.hyperv) HyperVStorageFileObject (class in dissect.hypervisor.descriptor.hyperv) HyperVStorageKeyTable (class in dissect.hypervisor.descriptor.hyperv) HyperVStorageKeyTableEntry (class in dissect.hypervisor.descriptor.hyperv) HyperVStorageObjectTable (class in dissect.hypervisor.descriptor.hyperv) HyperVStorageReplayLog (class in dissect.hypervisor.descriptor.hyperv) I I (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) icat() (dissect.target.plugins.filesystem.icat.ICatPlugin method) ICatPlugin (class in dissect.target.plugins.filesystem.icat) ICON_ENVIRONMENT_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) iconcache() (dissect.target.plugins.os.windows.thumbcache.ThumbcachePlugin method) IconcacheRecord (in module dissect.target.plugins.os.windows.thumbcache) id (dissect.etl.headers.headers.MessageTraceHeader property) (dissect.hypervisor.util.envelope.KeyStore property) (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm attribute) (dissect.target.plugins.os.windows.dpapi.crypto.HashAlgorithm attribute) (dissect.volume.lvm.metadata.HistoricalLogicalVolume attribute) (dissect.volume.lvm.metadata.LogicalVolume attribute) (dissect.volume.lvm.metadata.PhysicalVolume attribute) (dissect.volume.lvm.metadata.VolumeGroup attribute) IDC_ARROW (in module acquire.acquire.gui.win32) identifier (dissect.target.helpers.keychain.Key attribute) (dissect.target.loaders.itunes.ITunesBackup property) (dissect.thumbcache.index.IndexEntry property) (dissect.thumbcache.IndexEntry property) (flow.record.base.RecordDescriptor property) (flow.record.RecordDescriptor property) IDENTIFIER_BYTES (in module dissect.thumbcache.index) identifier_to_str() (in module flow.record.packer) identify() (dissect.target.plugins.os.windows.prefetch.Prefetch method) (dissect.target.plugins.os.windows.regf.shimcache.ShimCache method) IDENTITY_DB_FILENAME (dissect.target.plugins.os.windows.ual.UalPlugin attribute) IDENTITY_DB_PATH (dissect.target.plugins.os.windows.ual.UalPlugin attribute) IDI_APPLICATION (in module acquire.acquire.gui.win32) IdleTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) IDX_MEMORY (in module dissect.evidence.asdf.asdf) IDX_METADATA (in module dissect.evidence.asdf.asdf) iface (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) IGNORE_CACHE (in module dissect.target.helpers.cache) IGNORED_IPS (in module dissect.target.helpers.network_managers) IIS (class in acquire.acquire.acquire) IISLogsPlugin (class in dissect.target.plugins.apps.webserver.iis) image (acquire.acquire.gui.win32.Win32 attribute) Image (class in dissect.archive.wim) (class in dissect.hypervisor.disk.hdd) ImageLoadGuid (in module dissect.etl.utils) images (dissect.hypervisor.disk.hdd.Storage attribute) images() (dissect.archive.wim.WIM method) (dissect.target.plugins.apps.container.docker.DockerPlugin method) import_lazy() (in module dissect.target.helpers.lazy) in_use (dissect.target.plugins.filesystem.ntfs.mft_timeline.Extras attribute) in_use() (dissect.thumbcache.index.IndexEntry method) (dissect.thumbcache.IndexEntry method) (dissect.volume.vss.StoreBitmap method) INCOMPATIBLE_PLUGIN (dissect.target.target.Event attribute) incompatible_plugins (dissect.target.report.TargetExecutionReport attribute) INDENT_STEP (in module dissect.target.helpers.docs) Indentation (class in dissect.target.helpers.configutil) Index (class in dissect.cim.index) (class in dissect.esedb.index) (class in dissect.ntfs) (class in dissect.ntfs.index) (class in dissect.sql.sqlite3) index (dissect.cim.cim.Property property) (dissect.cim.classes.ClassInstanceProperty property) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTable property) (dissect.util.compression.lzxpress_huffman.BitString property) index() (dissect.esedb.table.Table method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.sql.SQLite3 method) (dissect.sql.sqlite3.SQLite3 method) index_buffer() (dissect.ntfs.Index method) (dissect.ntfs.index.Index method) INDEX_ENTRIES (in module dissect.thumbcache.index) index_entries() (dissect.thumbcache.Thumbcache method) (dissect.thumbcache.thumbcache.Thumbcache method) INDEX_ENTRY_END (in module dissect.ntfs.c_ntfs) INDEX_ENTRY_NODE (in module dissect.ntfs.c_ntfs) index_memory_size_mb (dissect.volume.lvm.metadata.VdoPoolSegment attribute) INDEX_NODE (in module dissect.ntfs.c_ntfs) INDEX_PAGE_INVALID (in module dissect.cim.c_cim) INDEX_PAGE_INVALID2 (in module dissect.cim.c_cim) INDEX_PAGE_SIZE (in module dissect.cim.c_cim) IndexBuffer (class in dissect.ntfs.index) IndexEntry (class in dissect.ntfs) (class in dissect.ntfs.index) (class in dissect.thumbcache) (class in dissect.thumbcache.index) IndexLeaf (class in dissect.regf.regf) IndexPage (class in dissect.cim.index) IndexRecord (in module dissect.target.plugins.os.windows.thumbcache) IndexRoot (class in dissect.ntfs.index) (class in dissect.regf.regf) indices() (dissect.sql.SQLite3 method) (dissect.sql.sqlite3.SQLite3 method) infer() (dissect.target.plugins.os.unix.packagemanager.OperationTypes class method) infer_access_log_format() (dissect.target.plugins.apps.webserver.apache.ApachePlugin static method) (dissect.target.plugins.apps.webserver.citrix.CitrixWebserverPlugin static method) info (acquire.acquire.gui.win32.Win32 attribute) info() (dissect.target.loaders.remote.RemoteStreamConnection method) InfoRecord (in module dissect.target.tools.info) InformationType (class in dissect.target.plugins.filesystem.ntfs.utils) Ini (class in dissect.target.helpers.configutil) init() (acquire.acquire.outputs.base.Output method) (dissect.target.helpers.mount.DissectMount method) (dissect.util.compression.lzxpress_huffman.BitString method) init_from_dict() (flow.record.base.RecordDescriptor method) (flow.record.RecordDescriptor method) init_from_record() (flow.record.base.RecordDescriptor method) (flow.record.RecordDescriptor method) INITCOMMONCONTROLSEX (class in acquire.acquire.gui.win32) initd() (dissect.target.plugins.os.unix.linux.services.ServicesPlugin method) INITD_PATHS (dissect.target.plugins.os.unix.linux.services.ServicesPlugin attribute) initialize() (in module dissect.squashfs.compression) initialize_object_attributes() (in module acquire.acquire.dynamic.windows.ntdll) ino_to_cg() (in module dissect.ffs.ffs) ino_to_fsba() (in module dissect.ffs.ffs) ino_to_fsbo() (in module dissect.ffs.ffs) INode (class in dissect.btrfs) (class in dissect.btrfs.btrfs) (class in dissect.extfs) (class in dissect.extfs.extfs) (class in dissect.ffs.ffs) (class in dissect.jffs.jffs2) (class in dissect.squashfs) (class in dissect.squashfs.squashfs) (class in dissect.xfs.xfs) inode (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) (dissect.xfs.xfs.INode property) inode() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.btrfs.Subvolume method) (dissect.btrfs.INode method) (dissect.btrfs.Subvolume method) (dissect.ffs.FFS method) (dissect.ffs.ffs.FFS method) (dissect.ffs.ffs.INode method) (dissect.jffs.JFFS2 method) (dissect.jffs.jffs2.INode method) (dissect.jffs.jffs2.JFFS2 method) (dissect.squashfs.SquashFS method) (dissect.squashfs.squashfs.SquashFS method) inode_allocated() (dissect.ffs.ffs.CylinderGroup method) inode_map() (dissect.target.plugins.os.unix.linux.proc.ProcPlugin method) inode_number (dissect.squashfs.INode property) (dissect.squashfs.squashfs.INode property) INODE_STRUCT_MAP (in module dissect.squashfs.c_squashfs) inode_to_pids() (dissect.target.plugins.os.unix.linux.proc.ProcPlugin method) inodes() (dissect.jffs.jffs2.INode method) input_field (acquire.acquire.gui.win32.Win32 attribute) Install (dissect.target.plugins.os.unix.packagemanager.OperationTypes attribute) install_date() (dissect.target.plugins.os.unix.generic.GenericPlugin method) (dissect.target.plugins.os.unix.linux.fortios.generic.GenericPlugin method) (dissect.target.plugins.os.windows.generic.GenericPlugin method) install_paths() (dissect.target.plugins.os.windows.exchange.exchange.ExchangePlugin method) Instance (class in dissect.cim.cim) (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.instance) instance (dissect.target.loaders.targetd.TargetdLoader attribute) instance() (dissect.cim.cim.Class method) INSTANCE_INFO (dissect.etl.headers.event.ExtType attribute) InstanceKey (class in dissect.cim.classes) instances (dissect.cim.cim.Class property) INT16 (dissect.eventlog.bxml.BxmlType attribute) INT32 (dissect.eventlog.bxml.BxmlType attribute) INT64 (dissect.eventlog.bxml.BxmlType attribute) INT8 (dissect.eventlog.bxml.BxmlType attribute) IntegritySegment (class in dissect.volume.lvm.metadata) interface (dissect.target.helpers.network_managers.NetworkManager property) interface() (dissect.target.plugins.os.unix.linux._os.LinuxPlugin method) interleave_sectors (dissect.volume.lvm.metadata.IntegritySegment attribute) internal() (in module dissect.target.plugin) internal_hash (dissect.volume.lvm.metadata.IntegritySegment attribute) InternalPlugin (class in dissect.target.plugin) InternetExplorerPlugin (class in dissect.target.plugins.apps.browser.iexplore) InvalidBLFError InvalidBlock InvalidBPB, [1] InvalidBufferError, [1] InvalidContextError InvalidDatabase, [1], [2], [3] InvalidDatabaseError, [1] InvalidDirectoryError, [1] InvalidFileError, [1] InvalidHeader, [1] (class in dissect.etl.headers.headers) InvalidHeaderError, [1], [2], [3] InvalidHeaderMagic, [1] InvalidHookIdException, [1] InvalidMarkerError, [1] InvalidOperation InvalidPageNumber, [1] InvalidPageType, [1] InvalidRecordBlockError InvalidRecordError, [1] InvalidSelectorError InvalidSignature InvalidSignatureError, [1] InvalidSnapshot InvalidSQL, [1] InvalidSymbolTableError InvalidTaskError InvalidVirtualDisk IO_COMPLETION (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) io_open() (in module dissect.target.helpers.compat.path_common) IO_REPARSE_TAG (in module dissect.archive.c_wim) (in module dissect.ntfs.c_ntfs) IO_STATUS_BLOCK (class in acquire.acquire.dynamic.windows.types) IO_STATUS_BLOCK_DUMMYUNIONNAME (class in acquire.acquire.dynamic.windows.types) IOS (dissect.target.plugin.OperatingSystem attribute) IOSPlugin (class in dissect.target.plugins.os.unix.bsd.ios._os) ip_records_from_text_files() (in module flow.record.tools.geoip) ipaddress (class in flow.record.fieldtypes.net) (class in flow.record.fieldtypes.net.ip) IPAddress (in module flow.record.fieldtypes.net) (in module flow.record.fieldtypes.net.ip) ipnetwork (class in flow.record.fieldtypes.net) (class in flow.record.fieldtypes.net.ip) IPNetwork (in module flow.record.fieldtypes.net) (in module flow.record.fieldtypes.net.ip) ips (dissect.target.helpers.network_managers.NetworkManager property) ips() (dissect.target.loaders.profile.ProfileOSPlugin method) (dissect.target.loaders.res.ResOSPlugin method) (dissect.target.plugin.OSPlugin method) (dissect.target.plugins.general.default.DefaultPlugin method) (dissect.target.plugins.os.unix.bsd._os.BsdPlugin method) (dissect.target.plugins.os.unix.bsd.citrix._os.CitrixPlugin method) (dissect.target.plugins.os.unix.bsd.ios._os.IOSPlugin method) (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin method) (dissect.target.plugins.os.unix.esxi._os.ESXiPlugin method) (dissect.target.plugins.os.unix.linux._os.LinuxPlugin method) (dissect.target.plugins.os.unix.linux.android._os.AndroidPlugin method) (dissect.target.plugins.os.unix.linux.debian.vyos._os.VyosPlugin method) (dissect.target.plugins.os.unix.linux.fortios._os.FortiOSPlugin method) (dissect.target.plugins.os.windows._os.WindowsPlugin method) iptables() (dissect.target.plugins.os.unix.linux.iptables.IptablesSavePlugin method) IptablesSavePlugin (class in dissect.target.plugins.os.unix.linux.iptables) IptablesSaveRecord (in module dissect.target.plugins.os.unix.linux.iptables) IPv4Record (in module flow.record.tools.geoip) IR_TIMER (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) is_64bit (dissect.etl.headers.headers.Header property) (dissect.etl.headers.logfile.LogfileHeader property) is_archive() (dissect.fat.fat.DirectoryEntry method) (dissect.fat.fat.RootDirectory method) is_binary() (dissect.esedb.table.Column method) is_black (dissect.ole.ole.DirectoryEntry property) is_block_device() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) is_branch() (dissect.esedb.page.Page method) is_builtin_key (dissect.cim.classes.QualifierReference property) is_builtin_property (dissect.cim.classes.PropertyReference property) is_char_device() (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) is_character_device() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) is_compatible() (dissect.target.plugin.Plugin method) is_compound_ace (dissect.ntfs.ACE property) (dissect.ntfs.secure.ACE property) is_compressed (dissect.archive.wim.Resource property) is_compressed() (dissect.target.loaders.tar.TarLoader method) is_connected() (dissect.target.loaders.remote.RemoteStreamConnection method) is_data_reference (dissect.cim.index.Key property) is_default_value (dissect.cim.classes.ClassInstanceProperty property) is_derived (dissect.esedb.record.TagField property) is_device() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) is_dir() (dissect.archive.wim.DirectoryEntry method) (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.evidence.ad1.FileEntry method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry method) (dissect.target.filesystems.cb.CbFilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.exfat.ExfatFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.fat.FatFilesystemEntry method) (dissect.target.filesystems.ffs.FfsFilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemEntry method) (dissect.target.filesystems.jffs.JFFSFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.smb.SmbFilesystemEntry method) (dissect.target.filesystems.squashfs.SquashFSFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystemEntry method) (dissect.target.filesystems.vmfs.VmfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) (dissect.vmfs.vmfs.FileDescriptor method) is_directory() (dissect.fat.fat.DirectoryEntry method) (dissect.fat.fat.RootDirectory method) is_dirty (dissect.target.tools.dump.state.Sink attribute) is_drive_letter_path() (in module dissect.target.loaders.dir) is_dst() (dissect.target.plugins.os.windows.datetime.WindowsTimezone method) is_empty() (dissect.esedb.page.Page method) is_encrypted() (in module dissect.target.volume) is_end (dissect.ntfs.index.IndexEntry property) (dissect.ntfs.IndexEntry property) is_eof_record() (in module dissect.eventlog.evt) is_fifo() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) is_file() (dissect.archive.wim.DirectoryEntry method) (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.evidence.ad1.FileEntry method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry method) (dissect.target.filesystems.cb.CbFilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.exfat.ExfatFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.fat.FatFilesystemEntry method) (dissect.target.filesystems.ffs.FfsFilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemEntry method) (dissect.target.filesystems.jffs.JFFSFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.smb.SmbFilesystemEntry method) (dissect.target.filesystems.squashfs.SquashFSFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystemEntry method) (dissect.target.filesystems.vmfs.VmfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) (dissect.vmfs.vmfs.FileDescriptor method) is_file_object_pointer (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) is_fixed() (dissect.esedb.table.Column method) is_header_record() (in module dissect.eventlog.evt) is_hidden() (dissect.fat.fat.DirectoryEntry method) (dissect.fat.fat.RootDirectory method) is_hyperv_xml() (in module dissect.target.loaders.hyperv) is_index() (dissect.esedb.page.Page method) is_inherited (dissect.cim.cim.Property property) (dissect.cim.classes.ClassInstanceProperty property) is_initialized (dissect.cim.classes.ClassInstanceProperty property) is_internal (dissect.volume.dm.btree.Node property) is_ipc() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) is_junction() (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) is_leaf (dissect.volume.dm.btree.Node property) is_leaf() (dissect.esedb.page.Page method) is_long_value() (dissect.esedb.page.Page method) is_lvm_volume() (in module dissect.target.volume) is_mapped (dissect.cim.mappings.MappingEntry property) is_metadata (dissect.archive.wim.Resource property) is_minifat (dissect.ole.ole.DirectoryEntry property) is_mount() (dissect.target.helpers.compat.path_311.TargetPath method) is_mount_point() (dissect.archive.wim.DirectoryEntry method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) is_multi_volume_filesystem() (in module dissect.target.filesystem) is_node (dissect.ntfs.index.IndexEntry property) (dissect.ntfs.IndexEntry property) is_null (dissect.esedb.record.TagField property) is_number() (dissect.cstruct.Expression method) (dissect.cstruct.expression.Expression method) is_object_ace (dissect.ntfs.ACE property) (dissect.ntfs.secure.ACE property) is_parent() (dissect.esedb.page.Page method) is_pem() (in module dissect.target.helpers.ssh) is_pkcs8() (in module dissect.target.helpers.ssh) is_rdm() (dissect.vmfs.vmfs.FileDescriptor method) is_readonly() (dissect.fat.fat.DirectoryEntry method) (dissect.fat.fat.RootDirectory method) is_red (dissect.ole.ole.DirectoryEntry property) is_related() (dissect.executable.elf.elf.Section method) (dissect.executable.elf.elf.Segment method) (dissect.executable.elf.Section method) (dissect.executable.elf.Segment method) is_reparse_point() (dissect.archive.wim.DirectoryEntry method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) is_reserved() (dissect.target.helpers.compat.path_312.PureDissectPath method) is_rfc4716() (in module dissect.target.helpers.ssh) is_root() (dissect.esedb.page.Page method) (dissect.target.helpers.configutil.ScopeManager method) is_set() (dissect.volume.vss.StoreBitmap method) is_small_page() (dissect.esedb.page.Page method) is_socket() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) is_space_tree() (dissect.esedb.page.Page method) is_spanned (dissect.archive.wim.Resource property) is_standard_ace (dissect.ntfs.ACE property) (dissect.ntfs.secure.ACE property) is_stdout() (in module flow.record.utils) is_storage (dissect.ole.ole.DirectoryEntry property) is_stream (dissect.ole.ole.DirectoryEntry property) is_symlink() (dissect.archive.wim.DirectoryEntry method) (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry method) (dissect.target.filesystems.cb.CbFilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.exfat.ExfatFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.fat.FatFilesystemEntry method) (dissect.target.filesystems.ffs.FfsFilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemEntry method) (dissect.target.filesystems.jffs.JFFSFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.smb.SmbFilesystemEntry method) (dissect.target.filesystems.squashfs.SquashFSFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystemEntry method) (dissect.target.filesystems.vmfs.VmfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) (dissect.vmfs.vmfs.FileDescriptor method) is_system() (dissect.fat.fat.DirectoryEntry method) (dissect.fat.fat.RootDirectory method) (dissect.vmfs.vmfs.FileDescriptor method) is_tagged() (dissect.esedb.table.Column method) is_text() (dissect.esedb.table.Column method) is_user_admin() (in module acquire.acquire.utils) is_valid (dissect.ole.ole.DirectoryEntry property) is_valid_field_name() (in module flow.record.base) is_variable() (dissect.esedb.table.Column method) is_visible (dissect.volume.lvm.metadata.LogicalVolume property) is_vmfs5 (dissect.vmfs.VMFS property) (dissect.vmfs.vmfs.VMFS property) is_vmfs6 (dissect.vmfs.VMFS property) (dissect.vmfs.vmfs.VMFS property) is_volume_id() (dissect.fat.fat.DirectoryEntry method) (dissect.fat.fat.RootDirectory method) is_wildcard (dissect.target.helpers.keychain.Key attribute) is_xp_mapping() (in module dissect.cim.utils) isabs() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) IsADirectoryError isascii() (in module dissect.regf.regf) isjunction() (in module dissect.target.helpers.compat.path_common) issocket() (dissect.util.cpio.CpioInfo method) item() (dissect.btrfs.tree.Cursor method) ITEMIDLIST (class in acquire.acquire.gui.win32) items() (acquire.acquire.uploaders.plugin_registry.PluginRegistry method) (dissect.btrfs.tree.Cursor method) (dissect.hypervisor.descriptor.hyperv.HyperVFile method) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry method) (dissect.target.helpers.configutil.ConfigurationParser method) iter() (dissect.btrfs.tree.Cursor method) iter_bitmap() (dissect.target.plugins.os.windows.regf.cit.CIT method) iter_esxi_filesystems() (in module acquire.acquire.acquire) iter_fd() (dissect.vmfs.VMFS method) (dissect.vmfs.vmfs.VMFS method) iter_fileobj() (in module dissect.evidence.tools.asdf.verify) iter_inodes() (dissect.ffs.FFS method) (dissect.ffs.ffs.FFS method) (dissect.squashfs.SquashFS method) (dissect.squashfs.squashfs.SquashFS method) iter_leaf_nodes() (dissect.esedb.page.Page method) iter_log_format_path_pairs() (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin method) iter_nt() (dissect.target.plugins.os.windows.regf.shimcache.ShimCache method) iter_ntfs_filesystems() (in module acquire.acquire.acquire) iter_proc() (dissect.target.plugins.os.unix.linux.proc.ProcPlugin method) iter_resource_locations() (dissect.vmfs.resource.ResourceFile method) iter_subfs() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystems.btrfs.BtrfsFilesystem method) iter_timestamped_records() (in module flow.record) (in module flow.record.base) iter_win_8_plus() (dissect.target.plugins.os.windows.regf.shimcache.ShimCache method) iterdir() (dissect.archive.wim.DirectoryEntry method) (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.extfs.extfs.INode method) (dissect.extfs.INode method) (dissect.fat.fat.DirectoryEntry method) (dissect.fat.fat.RootDirectory method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry method) (dissect.target.filesystems.cb.CbFilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.exfat.ExfatFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.fat.FatFilesystemEntry method) (dissect.target.filesystems.ffs.FfsFilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemEntry method) (dissect.target.filesystems.jffs.JFFSFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.smb.SmbFilesystemEntry method) (dissect.target.filesystems.squashfs.SquashFSFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystemEntry method) (dissect.target.filesystems.vmfs.VmfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) (dissect.vmfs.vmfs.FileDescriptor method) (dissect.xfs.xfs.INode method) iterfileobj() (in module dissect.evidence.tools.asdf.meta) iterhives() (dissect.target.helpers.regutil.HiveCollection method) (dissect.target.plugins.os.windows.registry.RegistryPlugin method) iterkeys() (dissect.target.plugins.os.windows.registry.RegistryPlugin method) ITunesBackup (class in dissect.target.loaders.itunes) ITunesFilesystem (class in dissect.target.filesystems.itunes) ITunesFilesystemDirectoryEntry (class in dissect.target.filesystems.itunes) ITunesFilesystemEntry (class in dissect.target.filesystems.itunes) ITunesLoader (class in dissect.target.loaders.itunes) iv_length (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm attribute) J JAMO_SPECIAL (dissect.esedb.lcmapstring.SCRIPT attribute) jbc (dissect.vmfs.resource.ResourceManager property) JDB2 (class in dissect.extfs) (class in dissect.extfs.journal) jdb2_def (in module dissect.extfs.c_jdb2) JET_bitIndex (in module dissect.esedb.c_esedb) JET_cbKeyMost_OLD (in module dissect.esedb.index) JET_coltyp (in module dissect.esedb.c_esedb) JFFS2 (class in dissect.jffs) (class in dissect.jffs.jffs2) jffs2_def (in module dissect.jffs.c_jffs2) JFFS2_MAGIC_NUMBERS (in module dissect.jffs.c_jffs2) JFFSFilesystem (class in dissect.target.filesystems.jffs) JFFSFilesystemEntry (class in dissect.target.filesystems.jffs) JOB (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) job (dissect.target.plugins.os.windows.log.schedlgu.SchedLgU attribute) JOB_REGEX_PATTERN (in module dissect.target.plugins.os.windows.log.schedlgu) JobGuid (in module dissect.etl.utils) join() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) journal (dissect.extfs.ExtFS property) (dissect.extfs.extfs.ExtFS property) journal() (dissect.target.plugins.os.unix.log.journal.JournalPlugin method) journal_def (in module dissect.target.plugins.os.unix.log.journal) JOURNAL_GLOB (dissect.target.plugins.os.unix.log.journal.JournalPlugin attribute) JOURNAL_PATHS (dissect.target.plugins.os.unix.log.journal.JournalPlugin attribute) journal_sectors (dissect.volume.lvm.metadata.IntegritySegment attribute) JOURNAL_SIGNATURE (dissect.target.plugins.os.unix.log.journal.JournalPlugin attribute) journal_watermark (dissect.volume.lvm.metadata.IntegritySegment attribute) JournalBlockResource (class in dissect.vmfs.resource) JournalFile (class in dissect.target.plugins.os.unix.log.journal) JournalPlugin (class in dissect.target.plugins.os.unix.log.journal) JournalRecord (in module dissect.target.plugins.os.unix.log.journal) Json (class in dissect.target.helpers.configutil) JsonfileReader (class in flow.record.adapter.jsonfile) JsonfileWriter (class in flow.record.adapter.jsonfile) JSONLINES (dissect.target.tools.dump.utils.Serialization attribute) JsonLinesWriter (class in dissect.target.tools.dump.utils) JsonRecordPacker (class in flow.record) (class in flow.record.jsonpacker) JUMPLIST_FOOTER (in module dissect.shellitem.lnk.c_lnk) JUMPLIST_HEADER_SIZE (in module dissect.shellitem.lnk.c_lnk) K K (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) KANA (dissect.esedb.lcmapstring.SCRIPT attribute) KapeLoader (class in dissect.target.loaders.kape) KATAKANA (dissect.esedb.lcmapstring.CASE attribute) kernel32 (in module acquire.acquire.dynamic.windows.handles) (in module acquire.acquire.gui.win32) KERNEL_KEY_MAP (in module dissect.target.plugins.os.unix.linux.fortios._keys) KEY (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) Key (class in dissect.cim.index) (class in dissect.target.helpers.keychain) key (dissect.cim.classes.ClassInstance property) (dissect.cim.classes.QualifierReference property) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) (dissect.hypervisor.util.envelope.KeyStore property) (dissect.target.plugins.os.windows.dpapi.master_key.MasterKeyFile property) KEY (dissect.target.plugins.os.windows.regf.7zip.SevenZipPlugin attribute) (dissect.target.plugins.os.windows.regf.auditpol.AuditpolPlugin attribute) (dissect.target.plugins.os.windows.regf.cit.CITPlugin attribute) (dissect.target.plugins.os.windows.regf.firewall.FirewallPlugin attribute) (dissect.target.plugins.os.windows.regf.nethist.NethistPlugin attribute) (dissect.target.plugins.os.windows.regf.trusteddocs.TrustedDocumentsPlugin attribute) (dissect.target.plugins.os.windows.regf.userassist.UserAssistPlugin attribute) (dissect.target.plugins.os.windows.services.ServicesPlugin attribute) key() (dissect.cim.CIM method) (dissect.cim.cim.CIM method) (dissect.cim.index.IndexPage method) (dissect.ntfs.index.IndexEntry method) (dissect.ntfs.IndexEntry method) (dissect.target.helpers.regutil.HiveCollection method) (dissect.target.helpers.regutil.RegfHive method) (dissect.target.helpers.regutil.RegistryHive method) (dissect.target.helpers.regutil.VirtualHive method) (dissect.target.loaders.cb.CbRegistryHive method) (dissect.target.loaders.smb.SmbRegistryHive method) (dissect.target.plugins.os.windows.registry.RegistryPlugin method) (dissect.volume.dm.btree.Node method) key_fingerprint() (in module acquire.acquire.crypt) key_from_record() (dissect.esedb.index.Index method) key_iv_for_kernel_hash() (in module dissect.target.plugins.os.unix.linux.fortios._os) key_length (dissect.ntfs.index.IndexEntry property) (dissect.ntfs.IndexEntry property) (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm attribute) key_prefix() (dissect.esedb.page.Page method) key_type (dissect.target.helpers.keychain.Key attribute) KeyBag (class in dissect.target.loaders.itunes) keyboard() (dissect.target.plugins.os.unix.locale.LocalePlugin method) (dissect.target.plugins.os.windows.locale.LocalePlugin method) KEYCHAIN (in module dissect.target.helpers.keychain) KeyCollection (class in dissect.target.helpers.regutil) KeyDataFlag (in module dissect.hypervisor.descriptor.c_hyperv) KeyDataType (in module dissect.hypervisor.descriptor.c_hyperv) KEYED_EVENT (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) KeyNotFoundError, [1] keys (dissect.cim.classes.ClassDefinition property) KEYS (dissect.target.plugins.os.windows.regf.bam.BamDamPlugin attribute) (dissect.target.plugins.os.windows.regf.clsid.CLSIDPlugin attribute) (dissect.target.plugins.os.windows.regf.muicache.MuiCachePlugin attribute) (dissect.target.plugins.os.windows.regf.runkeys.RunKeysPlugin attribute) (dissect.target.plugins.os.windows.regf.shellbags.ShellBagsPlugin attribute) (dissect.target.plugins.os.windows.regf.shimcache.ShimcachePlugin attribute) keys() (dissect.cim.index.IndexPage method) (dissect.hypervisor.descriptor.hyperv.HyperVFile method) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry method) (dissect.target.helpers.configutil.ConfigurationParser method) (dissect.target.helpers.regutil.HiveCollection method) (dissect.target.helpers.regutil.RegistryHive method) (dissect.target.plugins.os.windows.registry.RegistryPlugin method) (dissect.util.plist.NSObject method) KeySafe (class in dissect.hypervisor.descriptor.vmx) KeyStore (class in dissect.hypervisor.util.envelope) KeyType (class in dissect.target.helpers.keychain) (in module dissect.target.helpers.regutil) KeyValue (class in dissect.regf.regf) KeyValueCollection (class in dissect.eventlog.utils) KEYW (class in dissect.eventlog.wevt_object) KNOWN_FILES (in module dissect.target.helpers.configutil) KNOWN_FOLDER_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) known_hosts() (dissect.target.plugins.apps.ssh.openssh.OpenSSHPlugin method) (dissect.target.plugins.apps.ssh.putty.PuTTYPlugin method) KNOWN_SKIP_TYPES (in module dissect.target.volumes.lvm) KnownDllRecord (in module dissect.target.plugins.os.windows.generic) knowndlls() (dissect.target.plugins.os.windows.generic.GenericPlugin method) KnownHostRecord (in module dissect.target.plugins.apps.ssh.ssh) L l1_table() (dissect.hypervisor.disk.qcow2.QCow2 method) (dissect.hypervisor.disk.qcow2.QCow2Snapshot method) l2_table() (dissect.hypervisor.disk.qcow2.QCow2 method) L2Table (class in dissect.hypervisor.disk.qcow2) label (acquire.acquire.gui.win32.Win32 attribute) LABEL_SCAN_SECTORS (in module dissect.volume.lvm.c_lvm2) language() (dissect.target.plugins.os.unix.linux.fortios.locale.LocalePlugin method) (dissect.target.plugins.os.unix.locale.LocalePlugin method) (dissect.target.plugins.os.windows.locale.LocalePlugin method) LargeFileBlockResource (class in dissect.vmfs.resource) last() (dissect.btrfs.tree.Cursor method) last_access_time (dissect.ntfs.attr.FileName property) (dissect.ntfs.attr.StandardInformation property) last_access_time() (dissect.archive.wim.DirectoryEntry method) last_access_time_ns (dissect.ntfs.attr.FileName property) (dissect.ntfs.attr.StandardInformation property) last_access_time_ns() (dissect.archive.wim.DirectoryEntry method) LAST_ACK (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) last_change_time (dissect.ntfs.attr.FileName property) (dissect.ntfs.attr.StandardInformation property) last_change_time_ns (dissect.ntfs.attr.FileName property) (dissect.ntfs.attr.StandardInformation property) last_modification_time (dissect.ntfs.attr.FileName property) (dissect.ntfs.attr.StandardInformation property) last_modification_time_ns (dissect.ntfs.attr.FileName property) (dissect.ntfs.attr.StandardInformation property) last_modified (dissect.thumbcache.index.IndexEntry property) (dissect.thumbcache.IndexEntry property) last_update_time (dissect.target.tools.dump.state.DumpState attribute) last_write_time() (dissect.archive.wim.DirectoryEntry method) last_write_time_ns (dissect.archive.wim.DirectoryEntry property) LastEmptyDirectoryError, [1] lastlog() (dissect.target.plugins.os.unix.log.lastlog.LastLogPlugin method) lastlog_def (in module dissect.target.plugins.os.unix.log.lastlog) LastLogFile (class in dissect.target.plugins.os.unix.log.lastlog) lastlogin() (dissect.target.plugins.apps.webhosting.cpanel.CPanelPlugin method) LastLogPlugin (class in dissect.target.plugins.os.unix.log.lastlog) LastLogRecord (in module dissect.target.plugins.os.unix.log.lastlog) lastvisited() (dissect.target.plugins.os.windows.regf.mru.MRUPlugin method) LastVisitedMRURecord (in module dissect.target.plugins.os.windows.regf.mru) LATEST (dissect.util.feature.Feature attribute) latest_timestamp (dissect.target.plugins.os.windows.prefetch.Prefetch property) LATIN (dissect.esedb.lcmapstring.SCRIPT attribute) lattr() (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.MappedFile method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) Layout (class in dissect.volume.raid.stream) LazyAttr (class in dissect.target.helpers.lazy) LazyImport (class in dissect.target.helpers.lazy) lchmod() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) LCMAP_BYTEREV (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_FULLWIDTH (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_HALFWIDTH (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_HASH (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_HIRAGANA (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_KATAKANA (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_LINGUISTIC_CASING (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_LOWERCASE (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_SIMPLIFIED_CHINESE (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_SORTHANDLE (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_SORTKEY (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_TITLECASE (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_TRADITIONAL_CHINESE (dissect.esedb.lcmapstring.MapFlags attribute) LCMAP_UPPERCASE (dissect.esedb.lcmapstring.MapFlags attribute) ldm_def (in module dissect.volume.ldm) LeafNode (class in dissect.esedb.page) LEFT_ASYMMETRIC (dissect.volume.raid.stream.Layout attribute) LEFT_ASYMMETRIC_6 (dissect.volume.raid.stream.Layout attribute) left_sibling (dissect.ole.ole.DirectoryEntry property) LEFT_SYMMETRIC (dissect.volume.raid.stream.Layout attribute) LEFT_SYMMETRIC_6 (dissect.volume.raid.stream.Layout attribute) len_types (dissect.eventlog.wevt.WEVT property) length (dissect.btrfs.stream.Chunk attribute) (dissect.btrfs.stream.Extent attribute) (dissect.ntfs.index.IndexEntry property) (dissect.ntfs.IndexEntry property) Less (dissect.ntfs.index.Match attribute) Level (class in dissect.volume.raid.stream) level (dissect.cim.cim.Property property) (dissect.cim.classes.ClassInstanceProperty property) LEVL (class in dissect.eventlog.wevt_object) lexists() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) lfb (dissect.vmfs.resource.ResourceManager property) line_reader() (dissect.target.helpers.configutil.Default method) LINEAR (dissect.volume.raid.stream.Level attribute) LinearStream (class in dissect.volume.raid.stream) LineReader (class in dissect.target.helpers.cache) LineWriter (class in dissect.target.helpers.cache) (class in flow.record.adapter.line) LINGUISTIC_IGNORECASE (dissect.esedb.lcmapstring.MapFlags attribute) LINGUISTIC_IGNOREDIACRITIC (dissect.esedb.lcmapstring.MapFlags attribute) link (dissect.executable.elf.elf.Section property) (dissect.executable.elf.Section property) (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.xfs.xfs.INode property) link() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.filesystem.RootFilesystem method) (dissect.target.filesystem.VirtualFilesystem method) (dissect.vmfs.vmfs.FileDescriptor method) LINK_EXTRA_DATA_HEADER_SIZE (in module dissect.shellitem.lnk.c_lnk) LINK_HEADER_SIZE (in module dissect.shellitem.lnk.c_lnk) LINK_INFO_BODY_SIZE (in module dissect.shellitem.lnk.c_lnk) LINK_INFO_HEADER_SIZE (in module dissect.shellitem.lnk.c_lnk) link_inode (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.xfs.xfs.INode property) link_inode() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) link_to() (dissect.target.helpers.compat.path_311.TargetPath method) LINUX (dissect.target.filesystems.cb.OS attribute) (dissect.target.plugin.OperatingSystem attribute) LINUX_DEV_DIR (in module dissect.target.loaders.local) LINUX_DRIVE_REGEX (in module dissect.target.loaders.local) LinuxNetworkManager (class in dissect.target.helpers.network_managers) LinuxPlugin (class in dissect.target.plugins.os.unix.linux._os) LinuxProfile (class in acquire.acquire.acquire) LinuxServiceRecord (in module dissect.target.plugins.os.unix.linux.services) list_adapters() (in module flow.record.tools.rdump) list_children() (dissect.target.plugin.ChildTargetPlugin method) (dissect.target.plugins.child.esxi.ESXiChildTargetPlugin method) (dissect.target.plugins.child.hyperv.HyperVChildTargetPlugin method) (dissect.target.plugins.child.virtuozzo.VirtuozzoChildTargetPlugin method) (dissect.target.plugins.child.vmware_workstation.WorkstationChildTargetPlugin method) (dissect.target.plugins.child.wsl.WSLChildTargetPlugin method) (dissect.target.Target method) (dissect.target.target.Target method) list_to_frozen_set() (in module dissect.target.helpers.utils) listdir() (dissect.archive.wim.DirectoryEntry method) (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.evidence.ad1.AD1 method) (dissect.extfs.extfs.INode method) (dissect.extfs.INode method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.ole.OLE method) (dissect.ole.ole.OLE method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.vmfs.vmfs.FileDescriptor method) (dissect.xfs.xfs.INode method) listdir_ext() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) LISTEN (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) (dissect.target.plugins.os.unix.linux.proc.Sockets.UDPStates attribute) LISTENING (dissect.target.plugins.os.unix.linux.proc.Sockets.SocketStateType attribute) ListUnwrapper (class in dissect.target.helpers.configutil) listxattr (dissect.target.helpers.mount.DissectMount attribute) Lnk (class in dissect.shellitem.lnk) (class in dissect.shellitem.lnk.lnk) lnk() (dissect.target.plugins.os.windows.lnk.LnkPlugin method) lnk_entries() (dissect.target.plugins.os.windows.lnk.LnkPlugin method) LnkExtraData (class in dissect.shellitem.lnk.lnk) LnkInfo (class in dissect.shellitem.lnk.lnk) LnkPlugin (class in dissect.target.plugins.os.windows.lnk) LnkRecord (in module dissect.target.plugins.os.windows.lnk) LnkStringData (class in dissect.shellitem.lnk.lnk) LnkTargetIdList (class in dissect.shellitem.lnk.lnk) load() (dissect.cstruct.cstruct method) (dissect.cstruct.cstruct.cstruct method) (flow.record.fieldtypes.net.ipv4.SubnetList method) (in module dissect.target.helpers.config) (in module dissect.target.plugin) load_child() (in module acquire.acquire.acquire) load_entrypoint_plugins() (acquire.acquire.uploaders.plugin_registry.PluginRegistry method) load_module_from_file() (in module dissect.target.plugin) load_module_from_name() (in module dissect.target.plugin) load_modules_from_paths() (in module dissect.target.plugin) load_state() (in module dissect.target.tools.dump.state) load_user_hives() (dissect.target.plugins.os.windows.registry.RegistryPlugin method) Loader (class in dissect.target.loader) LoaderError LoaderListPlugin (class in dissect.target.plugins.general.loaders) loaders() (dissect.target.plugins.general.loaders.LoaderListPlugin method) loadfile() (dissect.cstruct.cstruct method) (dissect.cstruct.cstruct.cstruct method) local() (dissect.target.plugins.os.unix.datetime.DateTimePlugin method) (dissect.target.plugins.os.windows.datetime.DateTimePlugin method) local_address (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) local_def (in module dissect.target.plugins.apps.container.docker) local_groups_to_users() (in module dissect.target.plugins.os.unix.linux.fortios._os) local_ip (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) local_module() (in module acquire.acquire.acquire) local_port (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) local_wintimestamp() (in module dissect.target.plugins.os.windows.regf.cit) LocalePlugin (class in dissect.target.plugins.os.unix.linux.fortios.locale) (class in dissect.target.plugins.os.unix.locale) (class in dissect.target.plugins.os.windows.locale) LocalLoader (class in dissect.target.loaders.local) locate() (dissect.target.plugins.os.unix.locate.gnulocate.GNULocatePlugin method) (dissect.target.plugins.os.unix.locate.mlocate.MLocatePlugin method) (dissect.target.plugins.os.unix.locate.plocate.PLocatePlugin method) lock_args (dissect.volume.lvm.metadata.LogicalVolume attribute) (dissect.volume.lvm.metadata.VolumeGroup attribute) lock_info() (dissect.vmfs.vmfs.FileDescriptor method) lock_type (dissect.volume.lvm.metadata.VolumeGroup attribute) log (in module acquire.acquire.acquire) (in module acquire.acquire.collector) (in module acquire.acquire.dynamic.windows.collect) (in module acquire.acquire.dynamic.windows.handles) (in module acquire.acquire.hashes) (in module acquire.acquire.log) (in module acquire.acquire.tools.decrypter) (in module acquire.acquire.uploaders.plugin_registry) (in module dissect.eventlog.evtx) (in module dissect.evidence.ewf) (in module dissect.extfs.extfs) (in module dissect.ffs.ffs) (in module dissect.hypervisor.disk.vhdx) (in module dissect.hypervisor.disk.vmdk) (in module dissect.hypervisor.tools.vma) (in module dissect.jffs.jffs2) (in module dissect.regf.regf) (in module dissect.shellitem.lnk.lnk) (in module dissect.shellitem.tools.lnk) (in module dissect.target.container) (in module dissect.target.filesystem) (in module dissect.target.filesystems.config) (in module dissect.target.filesystems.smb) (in module dissect.target.filesystems.tar) (in module dissect.target.filesystems.xfs) (in module dissect.target.filesystems.zip) (in module dissect.target.helpers.config) (in module dissect.target.helpers.keychain) (in module dissect.target.helpers.loaderutil) (in module dissect.target.helpers.mount) (in module dissect.target.helpers.utils) (in module dissect.target.loaders.hyperv) (in module dissect.target.loaders.remote) (in module dissect.target.loaders.tar) (in module dissect.target.loaders.velociraptor) (in module dissect.target.plugin) (in module dissect.target.plugins.apps.container.docker) (in module dissect.target.plugins.apps.ssh.putty) (in module dissect.target.plugins.filesystem.ntfs.mft) (in module dissect.target.plugins.os.unix._os) (in module dissect.target.plugins.os.unix.linux._os) (in module dissect.target.plugins.os.windows.log.schedlgu) (in module dissect.target.plugins.os.windows.regf.shellbags) (in module dissect.target.plugins.os.windows.tasks) (in module dissect.target.target) (in module dissect.target.tools.dd) (in module dissect.target.tools.dump.run) (in module dissect.target.tools.dump.state) (in module dissect.target.tools.dump.utils) (in module dissect.target.tools.fs) (in module dissect.target.tools.info) (in module dissect.target.tools.mount) (in module dissect.target.tools.query) (in module dissect.target.tools.reg) (in module dissect.target.tools.shell) (in module dissect.target.volume) (in module dissect.target.volumes.bde) (in module dissect.target.volumes.luks) (in module dissect.target.volumes.lvm) (in module dissect.target.volumes.vmfs) (in module dissect.volume.ldm) (in module dissect.volume.lvm.lvm2) (in module dissect.volume.vss) (in module dissect.xfs.xfs) (in module flow.record.adapter.elastic) (in module flow.record.adapter.splunk) (in module flow.record.base) (in module flow.record.jsonpacker) (in module flow.record.stream) (in module flow.record.tools.rdump) log() (dissect.target.plugins.os.unix.linux.debian.dpkg.DpkgPlugin method) LOG_DB_GLOB (dissect.target.plugins.os.windows.ual.UalPlugin attribute) LOG_DIR_PATH (dissect.target.plugins.os.unix.linux.debian.apt.AptPlugin attribute) (dissect.target.plugins.os.unix.linux.redhat.yum.YumPlugin attribute) (dissect.target.plugins.os.unix.linux.suse.zypper.ZypperPlugin attribute) LOG_FILE_FIREWALL (dissect.target.plugins.apps.av.trendmicro.TrendMicroPlugin attribute) log_file_handler (in module acquire.acquire.acquire) LOG_FILE_INFECTIONS (dissect.target.plugins.apps.av.trendmicro.TrendMicroPlugin attribute) LOG_FILE_PATTERN (dissect.target.plugins.apps.av.mcafee.McAfeePlugin attribute) LOG_FILE_REGEX (in module dissect.target.plugins.apps.webserver.caddy) LOG_FILES_GLOB (dissect.target.plugins.os.unix.linux.debian.apt.AptPlugin attribute) (dissect.target.plugins.os.unix.linux.redhat.yum.YumPlugin attribute) (dissect.target.plugins.os.unix.linux.suse.zypper.ZypperPlugin attribute) (in module dissect.target.plugins.os.unix.linux.debian.dpkg) LOG_FOLDER (dissect.target.plugins.apps.av.trendmicro.TrendMicroPlugin attribute) LOG_FORMAT_ACCESS_COMBINED (in module dissect.target.plugins.apps.webserver.apache) LOG_FORMAT_ACCESS_COMMON (in module dissect.target.plugins.apps.webserver.apache) LOG_FORMAT_ACCESS_VHOST_COMBINED (in module dissect.target.plugins.apps.webserver.apache) LOG_FORMAT_CITRIX_NETSCALER_ACCESS_COMBINED_RESPONSE_TIME (in module dissect.target.plugins.apps.webserver.citrix) LOG_FORMAT_CITRIX_NETSCALER_ACCESS_COMBINED_RESPONSE_TIME_WITH_HEADERS (in module dissect.target.plugins.apps.webserver.citrix) LOG_FORMAT_ERROR_COMMON (in module dissect.target.plugins.apps.webserver.apache) log_func_error() (dissect.target.report.ExecutionReport method) log_func_execution() (dissect.target.report.ExecutionReport method) log_incompatible_plugin() (dissect.target.report.ExecutionReport method) log_progress() (in module dissect.target.tools.dump.run) LOG_RECORD_NAME (in module dissect.target.plugins.apps.webserver.iis) LOG_REGEX (in module dissect.target.plugins.apps.webserver.caddy) (in module dissect.target.plugins.apps.webserver.nginx) log_registered_plugin() (dissect.target.report.ExecutionReport method) LOG_SEP_AV (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) LOG_SEP_NET (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) LOG_SOPHOS_HITMAN (dissect.target.plugins.apps.av.sophos.SophosPlugin attribute) LOG_SOPHOS_HOME (dissect.target.plugins.apps.av.sophos.SophosPlugin attribute) LOG_TIME_FORMAT (dissect.target.plugins.os.unix.linux.iptables.IptablesSavePlugin attribute) logfile_def (in module dissect.etl.headers.logfile) LogfileHeader (class in dissect.etl.headers.logfile) LogFormat (class in dissect.target.plugins.apps.webserver.apache) logger (in module flow.record.adapter.sqlite) (in module flow.record.tools.geoip) logical_page() (dissect.cim.objects.Store method) LOGICAL_SECTOR_SIZE_GUID (in module dissect.hypervisor.disk.c_vhdx) logical_threads (dissect.volume.lvm.metadata.VdoPoolSegment attribute) logical_volume (dissect.volume.lvm.metadata.Segment property) LOGICAL_VOLUME_MANAGERS (in module dissect.target.volume) logical_volumes (dissect.volume.lvm.metadata.VolumeGroup attribute) LogicalImage (class in dissect.evidence.ad1) LogicalVolume (class in dissect.volume.lvm.metadata) LogicalVolumeSystem (class in dissect.target.volume) LogLoader (class in dissect.target.loaders.log) LogonTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) LOGS (dissect.target.plugins.apps.av.sophos.SophosPlugin attribute) (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) logs() (dissect.target.plugins.apps.av.symantec.SymantecPlugin method) (dissect.target.plugins.apps.container.docker.DockerPlugin method) (dissect.target.plugins.apps.remoteaccess.anydesk.AnydeskPlugin method) (dissect.target.plugins.apps.remoteaccess.teamviewer.TeamviewerPlugin method) (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin method) (dissect.target.plugins.apps.webserver.webserver.WebserverPlugin method) (dissect.target.plugins.os.unix.linux.debian.apt.AptPlugin method) (dissect.target.plugins.os.unix.linux.redhat.yum.YumPlugin method) (dissect.target.plugins.os.unix.linux.suse.zypper.ZypperPlugin method) (dissect.target.plugins.os.unix.packagemanager.PackageManagerPlugin method) LOGS_DIR_PATH (dissect.target.plugins.os.windows.log.evt.EvtPlugin attribute) (dissect.target.plugins.os.windows.log.evt.WindowsEventlogsMixin attribute) (dissect.target.plugins.os.windows.log.evtx.EvtxPlugin attribute) LOGS_DIRS (dissect.target.loaders.log.LogLoader attribute) lookup() (dissect.cim.index.Index method) (dissect.ntfs.Secure method) (dissect.ntfs.secure.Secure method) (dissect.util.compression.lzxpress_huffman.BitString method) (dissect.volume.dm.btree.BTree method) (in module dissect.etl.manifest) (in module dissect.target.plugin) lookup_guid() (in module dissect.etl.utils) low_watermark (dissect.volume.lvm.metadata.WriteCacheSegment attribute) lower() (in module flow.record.selector) lowest_vcn (dissect.ntfs.attr.AttributeHeader property) (dissect.ntfs.AttributeHeader property) LOWORD() (in module acquire.acquire.gui.win32) LRESULT (in module acquire.acquire.gui.win32) ls() (in module dissect.target.tools.fs) LS_COLORS (in module dissect.target.tools.shell) lsakey() (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin method) lsmod() (dissect.target.plugins.os.unix.linux.modules.ModulePlugin method) lstat() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.MappedFile method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry method) (dissect.target.filesystems.cb.CbFilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.exfat.ExfatFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.fat.FatFilesystemEntry method) (dissect.target.filesystems.ffs.FfsFilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemDirectoryEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemEntry method) (dissect.target.filesystems.jffs.JFFSFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.smb.SmbFilesystemEntry method) (dissect.target.filesystems.squashfs.SquashFSFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystemDirectoryEntry method) (dissect.target.filesystems.tar.TarFilesystemEntry method) (dissect.target.filesystems.vmfs.VmfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) (dissect.target.filesystems.zip.ZipFilesystemDirectoryEntry method) (dissect.target.filesystems.zip.ZipFilesystemEntry method) (dissect.target.loaders.res.ResFile method) LUID (class in acquire.acquire.dynamic.windows.types) LUID_AND_ATTRIBUTES (class in acquire.acquire.dynamic.windows.types) luks (in module dissect.target.volume) LUKSVolumeSystem (class in dissect.target.volumes.luks) LUKSVolumeSystemError lv (dissect.volume.lvm.metadata.Segment property) (dissect.volume.lvm.metadata.VolumeGroup property) lv_page() (dissect.esedb.table.Table method) LVM (class in dissect.vmfs) (class in dissect.vmfs.lvm) lvm (in module dissect.target.volume) LVM2 (class in dissect.volume.lvm) (class in dissect.volume.lvm.lvm2) LVM2Device (class in dissect.volume.lvm) (class in dissect.volume.lvm.physical) LVM2Error lvm_def (in module dissect.volume.lvm.c_lvm2) LvmVolumeSystem (class in dissect.target.volumes.lvm) LZ4 (dissect.target.tools.dump.utils.Compression attribute) LZ4_MAGIC (in module flow.record.base) M MAC (dissect.target.filesystems.cb.OS attribute) machine() (dissect.target.plugins.os.windows.regf.clsid.CLSIDPlugin method) MACHINE_NAME (dissect.target.loaders.smb.SmbLoader attribute) MacPlugin (class in dissect.target.plugins.os.unix.bsd.osx._os) MAGENTA (dissect.target.helpers.cyber.Color attribute) MAGIC_NT52 (in module dissect.target.plugins.os.windows.regf.shimcache) MAGIC_NT61 (in module dissect.target.plugins.os.windows.regf.shimcache) MAGIC_WIN10 (in module dissect.target.plugins.os.windows.regf.shimcache) MAGIC_WIN81 (in module dissect.target.plugins.os.windows.regf.shimcache) main() (in module acquire.acquire.acquire) (in module acquire.acquire.tools.decrypter) (in module dissect.esedb.tools.sru) (in module dissect.esedb.tools.ual) (in module dissect.evidence.tools.asdf.dd) (in module dissect.evidence.tools.asdf.meta) (in module dissect.evidence.tools.asdf.repair) (in module dissect.evidence.tools.asdf.verify) (in module dissect.hypervisor.tools.envelope) (in module dissect.hypervisor.tools.vma) (in module dissect.shellitem.tools.lnk) (in module dissect.target.tools.build_pluginlist) (in module dissect.target.tools.dd) (in module dissect.target.tools.dump.run) (in module dissect.target.tools.fs) (in module dissect.target.tools.info) (in module dissect.target.tools.mount) (in module dissect.target.tools.query) (in module dissect.target.tools.reg) (in module dissect.target.tools.shell) (in module dissect.thumbcache.tools.extract_images) (in module dissect.thumbcache.tools.extract_with_index) (in module dissect.util.tools.dump_nskeyedarchiver) (in module flow.record.tools.geoip) (in module flow.record.tools.rdump) main_globals (in module dissect.esedb.tools.impacket) make_cli_args_overview() (in module dissect.target.report) make_key() (dissect.esedb.index.Index method) make_keys() (dissect.target.helpers.regutil.VirtualHive method) make_plugin_import_errors_overview() (in module dissect.target.report) make_selector() (in module flow.record.selector) makedirs() (dissect.target.filesystem.VirtualFilesystem method) MalformedElfChnkException, [1] MANAGERS (in module dissect.target.helpers.network_managers) ManifestNotFoundError, [1] map() (dissect.target.loader.Loader method) (dissect.target.loaders.ad1.AD1Loader method) (dissect.target.loaders.asdf.AsdfLoader method) (dissect.target.loaders.cb.CbLoader method) (dissect.target.loaders.cyber.CyberLoader method) (dissect.target.loaders.dir.DirLoader method) (dissect.target.loaders.hyperv.HyperVLoader method) (dissect.target.loaders.itunes.ITunesLoader method) (dissect.target.loaders.kape.KapeLoader method) (dissect.target.loaders.local.LocalLoader method) (dissect.target.loaders.log.LogLoader method) (dissect.target.loaders.multiraw.MultiRawLoader method) (dissect.target.loaders.ovf.OvfLoader method) (dissect.target.loaders.phobos.PhobosLoader method) (dissect.target.loaders.profile.ProfileLoader method) (dissect.target.loaders.pvs.PvsLoader method) (dissect.target.loaders.raw.RawLoader method) (dissect.target.loaders.remote.RemoteLoader method) (dissect.target.loaders.res.ResLoader method) (dissect.target.loaders.smb.SmbLoader method) (dissect.target.loaders.tanium.TaniumLoader method) (dissect.target.loaders.tar.TarLoader method) (dissect.target.loaders.target.TargetLoader method) (dissect.target.loaders.targetd.TargetdLoader method) (dissect.target.loaders.utm.UtmLoader method) (dissect.target.loaders.vb.VBLoader method) (dissect.target.loaders.vbox.VBoxLoader method) (dissect.target.loaders.velociraptor.VelociraptorLoader method) (dissect.target.loaders.vma.VmaLoader method) (dissect.target.loaders.vmx.VmxLoader method) (dissect.target.loaders.xva.XvaLoader method) map_definition() (dissect.target.helpers.regutil.RegFlex method) map_dir() (dissect.target.filesystem.VirtualFilesystem method) map_dir_from_tar() (dissect.target.filesystem.VirtualFilesystem method) map_dirs() (in module dissect.target.loaders.dir) map_esxi_drives() (in module dissect.target.loaders.local) map_file() (dissect.target.filesystem.VirtualFilesystem method) map_file_entry() (dissect.target.filesystem.VirtualFilesystem method) map_file_fh() (dissect.target.filesystem.VirtualFilesystem method) map_file_from_tar() (dissect.target.filesystem.VirtualFilesystem method) map_fs() (dissect.target.filesystem.VirtualFilesystem method) map_hive() (dissect.target.helpers.regutil.VirtualHive method) map_key() (dissect.target.helpers.regutil.VirtualHive method) map_linux_drives() (in module dissect.target.loaders.local) map_solaris_drives() (in module dissect.target.loaders.local) map_string() (in module dissect.esedb.lcmapstring) map_value() (dissect.target.helpers.regutil.VirtualHive method) map_windows_drives() (in module dissect.target.loaders.local) map_windows_mounted_drives() (in module dissect.target.loaders.local) MapFlags (class in dissect.esedb.lcmapstring) MapNetworkDriveMRURecord (in module dissect.target.plugins.os.windows.regf.mru) MappedCompressedFile (class in dissect.target.filesystem) MappedFile (class in dissect.target.filesystem) Mapping (class in dissect.cim.mappings) mapping (dissect.thumbcache.Thumbcache property) (dissect.thumbcache.thumbcache.Thumbcache property) MAPPING_FILE_CLEAN (in module dissect.cim.c_cim) MAPPING_PAGE_ID_MASK (in module dissect.cim.c_cim) MAPPING_PAGE_UNAVAIL (in module dissect.cim.c_cim) MappingEntry (class in dissect.cim.mappings) MAPPINGS (dissect.target.plugins.os.windows.registry.RegistryPlugin attribute) mappings() (dissect.target.plugins.os.windows.registry.RegistryPlugin method) MappingStream (class in dissect.util.stream) MAPS_WEVT_TYPE (class in dissect.eventlog.wevt) mark_as_finished() (dissect.target.tools.dump.state.DumpState method) Marker (class in dissect.etl.headers.headers) marker (dissect.etl.headers.headers.Header property) MARKER_INFECTION (dissect.target.plugins.apps.av.mcafee.McAfeePlugin attribute) (dissect.target.plugins.apps.av.sophos.SophosPlugin attribute) (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) MARKER_MASK (dissect.etl.headers.headers.Marker attribute) MARKER_SUSPICIOUS_TCP_CONNECTION (dissect.target.plugins.apps.av.mcafee.McAfeePlugin attribute) MARKER_SUSPICIOUS_UDP_CONNECTION (dissect.target.plugins.apps.av.mcafee.McAfeePlugin attribute) mask (flow.record.fieldtypes.net.ipv4.subnet attribute) mask() (in module dissect.fat.fat) master_key_def (in module dissect.target.plugins.os.windows.dpapi.master_key) MASTER_KEY_REGEX (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin attribute) master_keys() (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin method) MasterKey (class in dissect.target.plugins.os.windows.dpapi.master_key) MasterKeyFile (class in dissect.target.plugins.os.windows.dpapi.master_key) Match (class in dissect.ntfs.index) match() (dissect.cstruct.expression.ExpressionTokenizer method) (flow.record.selector.CompiledSelector method) (flow.record.selector.Selector method) MATCH_MAP (in module dissect.target.helpers.configutil) matches() (flow.record.selector.RecordContextMatcher method) matrix() (in module dissect.target.helpers.cyber) MATRIX_CHARS (in module dissect.target.helpers.cyber) MATRIX_FRAME_DELAY (in module dissect.target.helpers.cyber) MATRIX_MAX_CASCADES (in module dissect.target.helpers.cyber) MATRIX_MAX_COLS (in module dissect.target.helpers.cyber) MATRIX_MAX_SPEED (in module dissect.target.helpers.cyber) MATRIX_REVEAL_SECONDS (in module dissect.target.helpers.cyber) max_age (dissect.volume.lvm.metadata.WriteCacheSegment attribute) MAX_BLOCK_TABLE_SIZE (in module dissect.evidence.asdf.asdf) max_discard (dissect.volume.lvm.metadata.VdoPoolSegment attribute) MAX_FILE_SIZE_BYTES (acquire.acquire.acquire.FileHashes attribute) MAX_IDX (in module dissect.evidence.asdf.asdf) MAX_IMM_OFFSET (in module dissect.thumbcache.index) max_lv (dissect.volume.lvm.metadata.VolumeGroup attribute) MAX_OPEN_SEGMENTS (in module dissect.evidence.ewf) max_pv (dissect.volume.lvm.metadata.VolumeGroup attribute) MAX_READ_LENGTH (in module dissect.util.compression.lzo) MAX_RECONNECTS (dissect.target.loaders.remote.RemoteStreamConnection attribute) max_recovery_rate (dissect.volume.lvm.metadata.RAIDSegment attribute) MAX_SHORT_READS (dissect.target.loaders.remote.RemoteStreamConnection attribute) MAX_STATES (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) MB (in module dissect.hypervisor.disk.c_vhdx) MBR (class in dissect.volume.disk.schemes) (class in dissect.volume.disk.schemes.mbr) mbr_def (in module dissect.volume.disk.schemes.mbr) McAfeeMscFirewallRecord (in module dissect.target.plugins.apps.av.mcafee) McAfeeMscLogRecord (in module dissect.target.plugins.apps.av.mcafee) McAfeePlugin (class in dissect.target.plugins.apps.av.mcafee) MD (class in dissect.volume.md) (class in dissect.volume.md.md) md (in module dissect.target.volume) MD5 (acquire.acquire.hashes.HashFunc attribute) md5 (flow.record.fieldtypes.digest property) md5() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (in module dissect.target.helpers.hashutil) MD5_NEEDLE (in module dissect.target.plugins.os.windows.catroot) md_def (in module dissect.volume.md.c_md) MDConfiguration (class in dissect.volume.md.md) MDDisk (class in dissect.volume.md.md) MDError MdVolumeSystem (class in dissect.target.volumes.md) members() (dissect.evidence.asdf.asdf.Metadata method) merge (dissect.volume.lvm.metadata.ThinSegment attribute) merge_record_descriptors() (in module flow.record.base) merging_store (dissect.volume.lvm.metadata.SnapshotSegment attribute) message() (acquire.acquire.gui.base.GUI method) (acquire.acquire.gui.base.Stub method) (acquire.acquire.gui.win32.Win32 method) MESSAGE_FLAGS (dissect.etl.headers.headers.Marker attribute) messages() (dissect.target.plugins.os.unix.log.messages.MessagesPlugin method) MessagesPlugin (class in dissect.target.plugins.os.unix.log.messages) MessagesRecord (in module dissect.target.plugins.os.unix.log.messages) MessageTraceHeader (class in dissect.etl.headers.headers) meta_dev (dissect.volume.lvm.metadata.IntegritySegment attribute) MetaBase (class in dissect.volume.lvm.metadata) Metadata (class in dissect.evidence.asdf.asdf) (class in dissect.volume.dm.thin) metadata (dissect.volume.lvm.metadata.CachePoolSegment attribute) (dissect.volume.lvm.metadata.ThinPoolSegment attribute) metadata() (dissect.volume.lvm.LVM2Device method) (dissect.volume.lvm.physical.LVM2Device method) METADATA_BASE (acquire.acquire.collector.Collector attribute) metadata_copies (dissect.volume.lvm.metadata.VolumeGroup attribute) metadata_format (dissect.volume.lvm.metadata.CachePoolSegment attribute) (dissect.volume.lvm.metadata.CacheSegment attribute) metadata_id (dissect.volume.lvm.metadata.CacheSegment attribute) metadata_len (dissect.volume.lvm.metadata.CacheSegment attribute) METADATA_MAP (dissect.hypervisor.disk.vhdx.MetadataTable attribute) metadata_only (dissect.volume.lvm.metadata.WriteCacheSegment attribute) METADATA_PREFIX (dissect.target.loaders.asdf.AsdfLoader attribute) METADATA_REGION_GUID (in module dissect.hypervisor.disk.c_vhdx) metadata_start (dissect.volume.lvm.metadata.CacheSegment attribute) MetadataTable (class in dissect.hypervisor.disk.vhdx) MetaType (in module dissect.evidence.ad1) method_name (dissect.target.plugin.PluginFunction attribute) Mft (class in dissect.ntfs) (class in dissect.ntfs.mft) mft() (dissect.target.plugins.filesystem.ntfs.mft.MftPlugin method) mft_records() (dissect.target.plugins.filesystem.ntfs.mft.MftPlugin method) mft_timeline() (dissect.target.plugins.filesystem.ntfs.mft_timeline.MftTimelinePlugin method) MftNotAvailableError MftPlugin (class in dissect.target.plugins.filesystem.ntfs.mft) MftRecord (class in dissect.ntfs) (class in dissect.ntfs.mft) MftTimelinePlugin (class in dissect.target.plugins.filesystem.ntfs.mft_timeline) MicrosoftDefenderPlugin (class in dissect.target.plugins.os.windows.defender) MIN_BITMAPS_SIZE (dissect.target.plugins.os.windows.regf.cit.BaseUseData attribute) (dissect.target.plugins.os.windows.regf.cit.SystemData attribute) min_recovery_rate (dissect.volume.lvm.metadata.RAIDSegment attribute) MIN_SPAN_STATS_SIZE (dissect.target.plugins.os.windows.regf.cit.BaseUseData attribute) (dissect.target.plugins.os.windows.regf.cit.SystemData attribute) MIN_STATS_SIZE (dissect.target.plugins.os.windows.regf.cit.BaseUseData attribute) (dissect.target.plugins.os.windows.regf.cit.SystemData attribute) MiniChain (class in dissect.ole.ole) minichain() (dissect.ole.OLE method) (dissect.ole.ole.OLE method) minifat() (dissect.ole.OLE method) (dissect.ole.ole.OLE method) MINIMAL (acquire.acquire.acquire.BsdProfile attribute) (acquire.acquire.acquire.ESXiProfile attribute) (acquire.acquire.acquire.LinuxProfile attribute) (acquire.acquire.acquire.OSXProfile attribute) (acquire.acquire.acquire.WindowsProfile attribute) minimal_size (dissect.etl.headers.event.EventHeader property) (dissect.etl.headers.headers.ErrorHeader property) (dissect.etl.headers.headers.EventInstanceGUIDHeader property) (dissect.etl.headers.headers.EventInstanceHeader property) (dissect.etl.headers.headers.EventTraceHeader property) (dissect.etl.headers.headers.Header property) (dissect.etl.headers.headers.MessageTraceHeader property) (dissect.etl.headers.logfile.LogfileHeader property) (dissect.etl.headers.system.SystemSpecificHeader property) minimum_io_size (dissect.volume.lvm.metadata.VdoPoolSegment attribute) MinIO (class in acquire.acquire.uploaders.minio) minutes_duration_to_iso() (dissect.target.plugins.os.windows.task_helpers.tasks_job.AtTask method) mirror_count (dissect.volume.lvm.metadata.MirrorSegment attribute) mirror_log (dissect.volume.lvm.metadata.MirrorSegment attribute) mirrors (dissect.volume.lvm.metadata.MirrorSegment attribute) MirrorSegment (class in dissect.volume.lvm.metadata) Misc (class in acquire.acquire.acquire) MISC_MAPPING (in module acquire.acquire.acquire) misc_osx_user_homes() (in module acquire.acquire.acquire) misc_unix_user_homes() (in module acquire.acquire.acquire) misc_windows_user_homes() (in module acquire.acquire.acquire) MISSING (acquire.acquire.collector.Outcome attribute) mkdir() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) mkts() (in module dissect.target.plugins.os.windows.activitiescache) MLocate (class in dissect.target.plugins.os.unix.locate.mlocate) mlocate_def (in module dissect.target.plugins.os.unix.locate.mlocate) MLocateFile (class in dissect.target.plugins.os.unix.locate.mlocate) MLocatePlugin (class in dissect.target.plugins.os.unix.locate.mlocate) MLocateRecord (in module dissect.target.plugins.os.unix.locate.mlocate) modargs2json() (in module acquire.acquire.acquire) ModBoundGuid (in module dissect.etl.utils) mode (dissect.squashfs.INode property) (dissect.squashfs.squashfs.INode property) (dissect.target.loaders.itunes.FileInfo property) (dissect.vmfs.vmfs.FileDescriptor property) (dissect.volume.lvm.metadata.IntegritySegment attribute) mode() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) modification_time (dissect.target.plugins.os.windows.regf.shellbags.FILE_ENTRY property) (dissect.target.plugins.os.windows.regf.shellbags.MTP_FILE_ENTRY property) (dissect.target.plugins.os.windows.regf.shellbags.SHITEM property) (dissect.target.plugins.os.windows.regf.shellbags.UNKNOWN_0x74 property) Modifier (class in dissect.target.helpers.record_modifier) ModifierFunc (in module dissect.target.helpers.record_modifier) MODPATH (in module dissect.etl.manifest) module acquire.acquire acquire.acquire.acquire acquire.acquire.collector acquire.acquire.crypt acquire.acquire.dynamic acquire.acquire.dynamic.windows acquire.acquire.dynamic.windows.collect acquire.acquire.dynamic.windows.exceptions acquire.acquire.dynamic.windows.handles acquire.acquire.dynamic.windows.named_objects acquire.acquire.dynamic.windows.ntdll acquire.acquire.dynamic.windows.types acquire.acquire.esxi acquire.acquire.gui acquire.acquire.gui.base acquire.acquire.gui.win32 acquire.acquire.hashes acquire.acquire.log acquire.acquire.outputs acquire.acquire.outputs.base acquire.acquire.outputs.dir acquire.acquire.outputs.tar acquire.acquire.outputs.zip acquire.acquire.tools acquire.acquire.tools.decrypter acquire.acquire.uploaders acquire.acquire.uploaders.minio acquire.acquire.uploaders.plugin acquire.acquire.uploaders.plugin_registry acquire.acquire.utils acquire.acquire.volatilestream codestyle dissect.archive dissect.archive.c_wim dissect.archive.exceptions dissect.archive.wim dissect.btrfs dissect.btrfs.btrfs dissect.btrfs.c_btrfs dissect.btrfs.exceptions dissect.btrfs.stream dissect.btrfs.tree dissect.cim dissect.cim.c_cim dissect.cim.cim dissect.cim.classes dissect.cim.exceptions dissect.cim.index dissect.cim.mappings dissect.cim.objects dissect.cim.utils dissect.clfs dissect.clfs.blf dissect.clfs.c_clfs dissect.clfs.container dissect.clfs.exceptions dissect.cstruct dissect.cstruct.bitbuffer dissect.cstruct.compiler dissect.cstruct.cstruct dissect.cstruct.exceptions dissect.cstruct.expression dissect.cstruct.parser dissect.cstruct.types dissect.cstruct.types.base dissect.cstruct.types.bytesinteger dissect.cstruct.types.chartype dissect.cstruct.types.enum dissect.cstruct.types.flag dissect.cstruct.types.instance dissect.cstruct.types.packedtype dissect.cstruct.types.pointer dissect.cstruct.types.structure dissect.cstruct.types.voidtype dissect.cstruct.types.wchartype dissect.cstruct.utils dissect.esedb dissect.esedb.c_esedb dissect.esedb.compression dissect.esedb.cursor dissect.esedb.esedb dissect.esedb.exceptions dissect.esedb.index dissect.esedb.lcmapstring dissect.esedb.page dissect.esedb.record dissect.esedb.sorting_table dissect.esedb.table dissect.esedb.tools dissect.esedb.tools.impacket dissect.esedb.tools.sru dissect.esedb.tools.ual dissect.etl dissect.etl.etl dissect.etl.exceptions dissect.etl.headers dissect.etl.headers.event dissect.etl.headers.headers dissect.etl.headers.logfile dissect.etl.headers.system dissect.etl.headers.utils dissect.etl.manifest dissect.etl.manifests dissect.etl.utils dissect.eventlog dissect.eventlog.bxml dissect.eventlog.evt dissect.eventlog.evtx dissect.eventlog.exceptions dissect.eventlog.utils dissect.eventlog.wevt dissect.eventlog.wevt_object dissect.eventlog.wevtutil dissect.evidence dissect.evidence.ad1 dissect.evidence.asdf dissect.evidence.asdf.asdf dissect.evidence.asdf.streams dissect.evidence.ewf dissect.evidence.exceptions dissect.evidence.tools dissect.evidence.tools.asdf dissect.evidence.tools.asdf.dd dissect.evidence.tools.asdf.meta dissect.evidence.tools.asdf.repair dissect.evidence.tools.asdf.verify dissect.executable dissect.executable.elf dissect.executable.elf.c_elf dissect.executable.elf.elf dissect.executable.exception dissect.executable.macho dissect.executable.pe dissect.extfs dissect.extfs.c_ext dissect.extfs.c_jdb2 dissect.extfs.exceptions dissect.extfs.extfs dissect.extfs.journal dissect.fat dissect.fat.c_exfat dissect.fat.c_fat dissect.fat.exceptions dissect.fat.exfat dissect.fat.fat dissect.ffs dissect.ffs.c_ffs dissect.ffs.exceptions dissect.ffs.ffs dissect.hypervisor dissect.hypervisor.backup dissect.hypervisor.backup.c_vma dissect.hypervisor.backup.vma dissect.hypervisor.backup.xva dissect.hypervisor.descriptor dissect.hypervisor.descriptor.c_hyperv dissect.hypervisor.descriptor.hyperv dissect.hypervisor.descriptor.ovf dissect.hypervisor.descriptor.pvs dissect.hypervisor.descriptor.vbox dissect.hypervisor.descriptor.vmx dissect.hypervisor.disk dissect.hypervisor.disk.c_hdd dissect.hypervisor.disk.c_qcow2 dissect.hypervisor.disk.c_vdi dissect.hypervisor.disk.c_vhd dissect.hypervisor.disk.c_vhdx dissect.hypervisor.disk.c_vmdk dissect.hypervisor.disk.hdd dissect.hypervisor.disk.qcow2 dissect.hypervisor.disk.vdi dissect.hypervisor.disk.vhd dissect.hypervisor.disk.vhdx dissect.hypervisor.disk.vmdk dissect.hypervisor.exceptions dissect.hypervisor.tools dissect.hypervisor.tools.envelope dissect.hypervisor.tools.vma dissect.hypervisor.util dissect.hypervisor.util.envelope dissect.hypervisor.util.vmtar dissect.jffs dissect.jffs.c_jffs2 dissect.jffs.exceptions dissect.jffs.jffs2 dissect.ntfs dissect.ntfs.attr dissect.ntfs.c_ntfs dissect.ntfs.exceptions dissect.ntfs.index dissect.ntfs.mft dissect.ntfs.ntfs dissect.ntfs.secure dissect.ntfs.stream dissect.ntfs.usnjrnl dissect.ntfs.util dissect.ole dissect.ole.c_ole dissect.ole.exceptions dissect.ole.ole dissect.regf dissect.regf.c_regf dissect.regf.exceptions dissect.regf.regf dissect.shellitem dissect.shellitem.lnk dissect.shellitem.lnk.c_lnk dissect.shellitem.lnk.lnk dissect.shellitem.tools dissect.shellitem.tools.lnk dissect.sql dissect.sql.c_sqlite3 dissect.sql.exceptions dissect.sql.sqlite3 dissect.sql.utils dissect.squashfs dissect.squashfs.c_squashfs dissect.squashfs.compression dissect.squashfs.exceptions dissect.squashfs.squashfs dissect.target dissect.target.container dissect.target.containers dissect.target.containers.asdf dissect.target.containers.ewf dissect.target.containers.hdd dissect.target.containers.hds dissect.target.containers.qcow2 dissect.target.containers.raw dissect.target.containers.split dissect.target.containers.vdi dissect.target.containers.vhd dissect.target.containers.vhdx dissect.target.containers.vmdk dissect.target.exceptions dissect.target.filesystem dissect.target.filesystems dissect.target.filesystems.ad1 dissect.target.filesystems.btrfs dissect.target.filesystems.cb dissect.target.filesystems.config dissect.target.filesystems.cpio dissect.target.filesystems.dir dissect.target.filesystems.exfat dissect.target.filesystems.extfs dissect.target.filesystems.fat dissect.target.filesystems.ffs dissect.target.filesystems.itunes dissect.target.filesystems.jffs dissect.target.filesystems.ntfs dissect.target.filesystems.smb dissect.target.filesystems.squashfs dissect.target.filesystems.tar dissect.target.filesystems.vmfs dissect.target.filesystems.vmtar dissect.target.filesystems.xfs dissect.target.filesystems.zip dissect.target.helpers dissect.target.helpers.cache dissect.target.helpers.compat dissect.target.helpers.compat.path_310 dissect.target.helpers.compat.path_311 dissect.target.helpers.compat.path_312 dissect.target.helpers.compat.path_39 dissect.target.helpers.compat.path_common dissect.target.helpers.config dissect.target.helpers.configutil dissect.target.helpers.cyber dissect.target.helpers.descriptor_extensions dissect.target.helpers.docs dissect.target.helpers.fsutil dissect.target.helpers.hashutil dissect.target.helpers.keychain dissect.target.helpers.lazy dissect.target.helpers.loaderutil dissect.target.helpers.localeutil dissect.target.helpers.mount dissect.target.helpers.mui dissect.target.helpers.network_managers dissect.target.helpers.polypath dissect.target.helpers.protobuf dissect.target.helpers.record dissect.target.helpers.record_modifier dissect.target.helpers.regutil dissect.target.helpers.shell_folder_ids dissect.target.helpers.ssh dissect.target.helpers.targetd dissect.target.helpers.utils dissect.target.loader dissect.target.loaders dissect.target.loaders.ad1 dissect.target.loaders.asdf dissect.target.loaders.cb dissect.target.loaders.cyber dissect.target.loaders.dir dissect.target.loaders.hyperv dissect.target.loaders.itunes dissect.target.loaders.kape dissect.target.loaders.local dissect.target.loaders.log dissect.target.loaders.multiraw dissect.target.loaders.ova dissect.target.loaders.ovf dissect.target.loaders.phobos dissect.target.loaders.profile dissect.target.loaders.pvm dissect.target.loaders.pvs dissect.target.loaders.raw dissect.target.loaders.remote dissect.target.loaders.res dissect.target.loaders.smb dissect.target.loaders.tanium dissect.target.loaders.tar dissect.target.loaders.target dissect.target.loaders.targetd dissect.target.loaders.utm dissect.target.loaders.vb dissect.target.loaders.vbox dissect.target.loaders.velociraptor dissect.target.loaders.vma dissect.target.loaders.vmwarevm dissect.target.loaders.vmx dissect.target.loaders.xva dissect.target.plugin dissect.target.plugins dissect.target.plugins.apps dissect.target.plugins.apps.av dissect.target.plugins.apps.av.mcafee dissect.target.plugins.apps.av.sophos dissect.target.plugins.apps.av.symantec dissect.target.plugins.apps.av.trendmicro dissect.target.plugins.apps.browser dissect.target.plugins.apps.browser.brave dissect.target.plugins.apps.browser.browser dissect.target.plugins.apps.browser.chrome dissect.target.plugins.apps.browser.chromium dissect.target.plugins.apps.browser.edge dissect.target.plugins.apps.browser.firefox dissect.target.plugins.apps.browser.iexplore dissect.target.plugins.apps.container dissect.target.plugins.apps.container.docker dissect.target.plugins.apps.remoteaccess dissect.target.plugins.apps.remoteaccess.anydesk dissect.target.plugins.apps.remoteaccess.remoteaccess dissect.target.plugins.apps.remoteaccess.teamviewer dissect.target.plugins.apps.shell dissect.target.plugins.apps.shell.powershell dissect.target.plugins.apps.ssh dissect.target.plugins.apps.ssh.openssh dissect.target.plugins.apps.ssh.opensshd dissect.target.plugins.apps.ssh.putty dissect.target.plugins.apps.ssh.ssh dissect.target.plugins.apps.vpn dissect.target.plugins.apps.vpn.openvpn dissect.target.plugins.apps.vpn.wireguard dissect.target.plugins.apps.webhosting dissect.target.plugins.apps.webhosting.cpanel dissect.target.plugins.apps.webserver dissect.target.plugins.apps.webserver.apache dissect.target.plugins.apps.webserver.caddy dissect.target.plugins.apps.webserver.citrix dissect.target.plugins.apps.webserver.iis dissect.target.plugins.apps.webserver.nginx dissect.target.plugins.apps.webserver.webserver dissect.target.plugins.child dissect.target.plugins.child.esxi dissect.target.plugins.child.hyperv dissect.target.plugins.child.virtuozzo dissect.target.plugins.child.vmware_workstation dissect.target.plugins.child.wsl dissect.target.plugins.filesystem dissect.target.plugins.filesystem.acquire_handles dissect.target.plugins.filesystem.acquire_hash dissect.target.plugins.filesystem.icat dissect.target.plugins.filesystem.ntfs dissect.target.plugins.filesystem.ntfs.mft dissect.target.plugins.filesystem.ntfs.mft_timeline dissect.target.plugins.filesystem.ntfs.usnjrnl dissect.target.plugins.filesystem.ntfs.utils dissect.target.plugins.filesystem.resolver dissect.target.plugins.filesystem.unix dissect.target.plugins.filesystem.unix.capability dissect.target.plugins.filesystem.unix.suid dissect.target.plugins.filesystem.walkfs dissect.target.plugins.filesystem.yara dissect.target.plugins.general dissect.target.plugins.general.config dissect.target.plugins.general.default dissect.target.plugins.general.example dissect.target.plugins.general.loaders dissect.target.plugins.general.osinfo dissect.target.plugins.general.plugins dissect.target.plugins.general.scrape dissect.target.plugins.general.users dissect.target.plugins.os dissect.target.plugins.os.unix dissect.target.plugins.os.unix._os dissect.target.plugins.os.unix.bsd._os dissect.target.plugins.os.unix.bsd.citrix dissect.target.plugins.os.unix.bsd.citrix._os dissect.target.plugins.os.unix.bsd.citrix.history dissect.target.plugins.os.unix.bsd.freebsd dissect.target.plugins.os.unix.bsd.freebsd._os dissect.target.plugins.os.unix.bsd.ios dissect.target.plugins.os.unix.bsd.ios._os dissect.target.plugins.os.unix.bsd.openbsd dissect.target.plugins.os.unix.bsd.openbsd._os dissect.target.plugins.os.unix.bsd.osx dissect.target.plugins.os.unix.bsd.osx._os dissect.target.plugins.os.unix.bsd.osx.user dissect.target.plugins.os.unix.cronjobs dissect.target.plugins.os.unix.datetime dissect.target.plugins.os.unix.esxi dissect.target.plugins.os.unix.esxi._os dissect.target.plugins.os.unix.etc dissect.target.plugins.os.unix.generic dissect.target.plugins.os.unix.history dissect.target.plugins.os.unix.linux dissect.target.plugins.os.unix.linux._os dissect.target.plugins.os.unix.linux.android dissect.target.plugins.os.unix.linux.android._os dissect.target.plugins.os.unix.linux.cmdline dissect.target.plugins.os.unix.linux.debian dissect.target.plugins.os.unix.linux.debian._os dissect.target.plugins.os.unix.linux.debian.apt dissect.target.plugins.os.unix.linux.debian.dpkg dissect.target.plugins.os.unix.linux.debian.vyos dissect.target.plugins.os.unix.linux.debian.vyos._os dissect.target.plugins.os.unix.linux.environ dissect.target.plugins.os.unix.linux.fortios dissect.target.plugins.os.unix.linux.fortios._keys dissect.target.plugins.os.unix.linux.fortios._os dissect.target.plugins.os.unix.linux.fortios.generic dissect.target.plugins.os.unix.linux.fortios.locale dissect.target.plugins.os.unix.linux.iptables dissect.target.plugins.os.unix.linux.modules dissect.target.plugins.os.unix.linux.netstat dissect.target.plugins.os.unix.linux.proc dissect.target.plugins.os.unix.linux.processes dissect.target.plugins.os.unix.linux.redhat dissect.target.plugins.os.unix.linux.redhat._os dissect.target.plugins.os.unix.linux.redhat.yum dissect.target.plugins.os.unix.linux.services dissect.target.plugins.os.unix.linux.sockets dissect.target.plugins.os.unix.linux.suse dissect.target.plugins.os.unix.linux.suse._os dissect.target.plugins.os.unix.linux.suse.zypper dissect.target.plugins.os.unix.locale dissect.target.plugins.os.unix.locate dissect.target.plugins.os.unix.locate.gnulocate dissect.target.plugins.os.unix.locate.locate dissect.target.plugins.os.unix.locate.mlocate dissect.target.plugins.os.unix.locate.plocate dissect.target.plugins.os.unix.log dissect.target.plugins.os.unix.log.atop dissect.target.plugins.os.unix.log.audit dissect.target.plugins.os.unix.log.auth dissect.target.plugins.os.unix.log.journal dissect.target.plugins.os.unix.log.lastlog dissect.target.plugins.os.unix.log.messages dissect.target.plugins.os.unix.log.utmp dissect.target.plugins.os.unix.packagemanager dissect.target.plugins.os.unix.shadow dissect.target.plugins.os.windows dissect.target.plugins.os.windows._os dissect.target.plugins.os.windows.activitiescache dissect.target.plugins.os.windows.adpolicy dissect.target.plugins.os.windows.amcache dissect.target.plugins.os.windows.catroot dissect.target.plugins.os.windows.cim dissect.target.plugins.os.windows.clfs dissect.target.plugins.os.windows.datetime dissect.target.plugins.os.windows.defender dissect.target.plugins.os.windows.dpapi dissect.target.plugins.os.windows.dpapi.blob dissect.target.plugins.os.windows.dpapi.crypto dissect.target.plugins.os.windows.dpapi.dpapi dissect.target.plugins.os.windows.dpapi.master_key dissect.target.plugins.os.windows.env dissect.target.plugins.os.windows.exchange dissect.target.plugins.os.windows.exchange.exchange dissect.target.plugins.os.windows.generic dissect.target.plugins.os.windows.lnk dissect.target.plugins.os.windows.locale dissect.target.plugins.os.windows.log dissect.target.plugins.os.windows.log.amcache dissect.target.plugins.os.windows.log.etl dissect.target.plugins.os.windows.log.evt dissect.target.plugins.os.windows.log.evtx dissect.target.plugins.os.windows.log.pfro dissect.target.plugins.os.windows.log.schedlgu dissect.target.plugins.os.windows.notifications dissect.target.plugins.os.windows.prefetch dissect.target.plugins.os.windows.recyclebin dissect.target.plugins.os.windows.regf dissect.target.plugins.os.windows.regf.7zip dissect.target.plugins.os.windows.regf.appxdebugkeys dissect.target.plugins.os.windows.regf.auditpol dissect.target.plugins.os.windows.regf.bam dissect.target.plugins.os.windows.regf.cit dissect.target.plugins.os.windows.regf.clsid dissect.target.plugins.os.windows.regf.firewall dissect.target.plugins.os.windows.regf.mru dissect.target.plugins.os.windows.regf.muicache dissect.target.plugins.os.windows.regf.nethist dissect.target.plugins.os.windows.regf.recentfilecache dissect.target.plugins.os.windows.regf.regf dissect.target.plugins.os.windows.regf.runkeys dissect.target.plugins.os.windows.regf.shellbags dissect.target.plugins.os.windows.regf.shimcache dissect.target.plugins.os.windows.regf.trusteddocs dissect.target.plugins.os.windows.regf.usb dissect.target.plugins.os.windows.regf.userassist dissect.target.plugins.os.windows.registry dissect.target.plugins.os.windows.sam dissect.target.plugins.os.windows.services dissect.target.plugins.os.windows.sru dissect.target.plugins.os.windows.startupinfo dissect.target.plugins.os.windows.syscache dissect.target.plugins.os.windows.task_helpers dissect.target.plugins.os.windows.task_helpers.tasks_job dissect.target.plugins.os.windows.task_helpers.tasks_records dissect.target.plugins.os.windows.task_helpers.tasks_xml dissect.target.plugins.os.windows.tasks dissect.target.plugins.os.windows.thumbcache dissect.target.plugins.os.windows.ual dissect.target.plugins.os.windows.wer dissect.target.report dissect.target.target dissect.target.tools dissect.target.tools.build_pluginlist dissect.target.tools.dd dissect.target.tools.dump dissect.target.tools.dump.run dissect.target.tools.dump.state dissect.target.tools.dump.utils dissect.target.tools.fs dissect.target.tools.info dissect.target.tools.logging dissect.target.tools.mount dissect.target.tools.query dissect.target.tools.reg dissect.target.tools.shell dissect.target.tools.utils dissect.target.volume dissect.target.volumes dissect.target.volumes.bde dissect.target.volumes.ddf dissect.target.volumes.disk dissect.target.volumes.luks dissect.target.volumes.lvm dissect.target.volumes.md dissect.target.volumes.vmfs dissect.thumbcache dissect.thumbcache.c_thumbcache dissect.thumbcache.exceptions dissect.thumbcache.index dissect.thumbcache.thumbcache dissect.thumbcache.thumbcache_file dissect.thumbcache.tools dissect.thumbcache.tools.extract_images dissect.thumbcache.tools.extract_with_index dissect.thumbcache.tools.utils dissect.thumbcache.util dissect.util dissect.util.compression dissect.util.compression.lz4 dissect.util.compression.lznt1 dissect.util.compression.lzo dissect.util.compression.lzxpress dissect.util.compression.lzxpress_huffman dissect.util.compression.sevenbit dissect.util.compression.xz dissect.util.cpio dissect.util.crc32c dissect.util.encoding dissect.util.encoding.surrogateescape dissect.util.exceptions dissect.util.feature dissect.util.plist dissect.util.sid dissect.util.stream dissect.util.tools dissect.util.tools.dump_nskeyedarchiver dissect.util.ts dissect.util.xmemoryview dissect.vmfs dissect.vmfs.c_vmfs dissect.vmfs.exceptions dissect.vmfs.lvm dissect.vmfs.resource dissect.vmfs.vmfs dissect.volume dissect.volume.ddf dissect.volume.ddf.c_ddf dissect.volume.ddf.ddf dissect.volume.disk dissect.volume.disk.disk dissect.volume.disk.partition dissect.volume.disk.schemes dissect.volume.disk.schemes.apm dissect.volume.disk.schemes.bsd dissect.volume.disk.schemes.gpt dissect.volume.disk.schemes.mbr dissect.volume.dm dissect.volume.dm.btree dissect.volume.dm.c_dm dissect.volume.dm.thin dissect.volume.exceptions dissect.volume.ldm dissect.volume.lvm dissect.volume.lvm.c_lvm2 dissect.volume.lvm.lvm2 dissect.volume.lvm.metadata dissect.volume.lvm.physical dissect.volume.md dissect.volume.md.c_md dissect.volume.md.md dissect.volume.raid dissect.volume.raid.raid dissect.volume.raid.stream dissect.volume.vss dissect.xfs dissect.xfs.c_xfs dissect.xfs.exceptions dissect.xfs.xfs flow.record flow.record.adapter flow.record.adapter.archive flow.record.adapter.avro flow.record.adapter.broker flow.record.adapter.csvfile flow.record.adapter.elastic flow.record.adapter.jsonfile flow.record.adapter.line flow.record.adapter.mongo flow.record.adapter.split flow.record.adapter.splunk flow.record.adapter.sqlite flow.record.adapter.stream flow.record.adapter.text flow.record.adapter.xlsx flow.record.base flow.record.exceptions flow.record.fieldtypes flow.record.fieldtypes.credential flow.record.fieldtypes.net flow.record.fieldtypes.net.ip flow.record.fieldtypes.net.ipv4 flow.record.fieldtypes.net.tcp flow.record.fieldtypes.net.udp flow.record.jsonpacker flow.record.packer flow.record.selector flow.record.stream flow.record.tools flow.record.tools.geoip flow.record.tools.rdump flow.record.utils flow.record.whitelist Module (class in acquire.acquire.acquire) (class in dissect.target.plugins.os.unix.linux.modules) module (dissect.squashfs.compression.Compression attribute) (dissect.squashfs.compression.NativeLZ4 attribute) (dissect.squashfs.compression.NativeLZMA attribute) (dissect.squashfs.compression.NativeLZO attribute) (dissect.squashfs.compression.NativeXZ attribute) (dissect.squashfs.compression.NativeZlib attribute) (dissect.squashfs.compression.NativeZSTD attribute) (dissect.squashfs.compression.PythonLZ4 attribute) (dissect.squashfs.compression.PythonLZO attribute) module_arg() (in module acquire.acquire.acquire) MODULE_LOOKUP (in module acquire.acquire.acquire) module_name (acquire.acquire.collector.Record attribute) MODULE_PATH (in module dissect.target.container) (in module dissect.target.filesystem) (in module dissect.target.plugin) ModulePlugin (class in dissect.target.plugins.os.unix.linux.modules) ModuleRecord (in module dissect.target.plugins.os.unix.linux.modules) MODULES (in module acquire.acquire.acquire) modules() (dissect.target.plugins.os.windows.regf.cit.CITPlugin method) MongoReader (class in flow.record.adapter.mongo) MongoWriter (class in flow.record.adapter.mongo) MonthlyDateTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) MonthlyDowTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) MORE_MASK (dissect.eventlog.bxml.Token attribute) mount (dissect.target.filesystem.VirtualFilesystem attribute) mount() (dissect.target.filesystem.RootFilesystem method) MRUPlugin (class in dissect.target.plugins.os.windows.regf.mru) msc() (dissect.target.plugins.apps.av.mcafee.McAfeePlugin method) MSGPACK (dissect.target.tools.dump.utils.Serialization attribute) msoffice() (dissect.target.plugins.os.windows.regf.mru.MRUPlugin method) MSOfficeMRURecord (in module dissect.target.plugins.os.windows.regf.mru) mstsc() (dissect.target.plugins.os.windows.regf.mru.MRUPlugin method) mtime (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.fat.fat.DirectoryEntry property) (dissect.fat.fat.RootDirectory property) (dissect.squashfs.INode property) (dissect.squashfs.squashfs.INode property) (dissect.xfs.xfs.INode property) mtime() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.vmfs.vmfs.FileDescriptor method) mtime_ns (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.xfs.xfs.INode property) mtime_ns() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) MTP_FILE_ENTRY (class in dissect.target.plugins.os.windows.regf.shellbags) MTP_VOLUME (class in dissect.target.plugins.os.windows.regf.shellbags) MUI_TZ_MAP (in module dissect.target.helpers.mui) muicache() (dissect.target.plugins.os.windows.regf.muicache.MuiCachePlugin method) MuiCachePlugin (class in dissect.target.plugins.os.windows.regf.muicache) MuiCacheRecord (in module dissect.target.plugins.os.windows.regf.muicache) MultiDict (class in dissect.target.plugins.apps.vpn.wireguard) MultiRawLoader (class in dissect.target.loaders.multiraw) MUTANT (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) MUTEX (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) N N (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) name (acquire.acquire.dynamic.windows.types.OBJECT_DIRECTORY_INFORMATION property) (acquire.acquire.dynamic.windows.types.PUBLIC_OBJECT_TYPE_INFORMATION property) (dissect.cim.cim.Class property) (dissect.cim.cim.Instance property) (dissect.cim.cim.Property property) (dissect.cim.classes.ClassInstanceProperty property) (dissect.cstruct.EnumInstance property) (dissect.cstruct.FlagInstance property) (dissect.cstruct.types.enum.EnumInstance property) (dissect.cstruct.types.EnumInstance property) (dissect.cstruct.types.flag.FlagInstance property) (dissect.cstruct.types.FlagInstance property) (dissect.executable.elf.elf.Section property) (dissect.executable.elf.elf.Symbol property) (dissect.executable.elf.Section property) (dissect.executable.elf.Symbol property) (dissect.ntfs.attr.Attribute property) (dissect.ntfs.attr.AttributeHeader property) (dissect.ntfs.Attribute property) (dissect.ntfs.AttributeHeader property) (dissect.target.helpers.regutil.KeyCollection property) (dissect.target.helpers.regutil.RegfKey property) (dissect.target.helpers.regutil.RegfValue property) (dissect.target.helpers.regutil.RegistryKey property) (dissect.target.helpers.regutil.RegistryValue property) (dissect.target.helpers.regutil.ValueCollection property) (dissect.target.helpers.regutil.VirtualKey property) (dissect.target.helpers.regutil.VirtualValue property) (dissect.target.loaders.cb.CbRegistryKey property) (dissect.target.loaders.cb.CbRegistryValue property) (dissect.target.loaders.smb.SmbRegistryKey property) (dissect.target.loaders.smb.SmbRegistryValue property) (dissect.target.plugin.PluginFunction attribute) (dissect.target.plugins.apps.webserver.apache.LogFormat attribute) (dissect.target.plugins.os.unix.linux.modules.Module attribute) (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) (dissect.target.plugins.os.windows.dpapi.crypto.CipherAlgorithm attribute) (dissect.target.plugins.os.windows.dpapi.crypto.HashAlgorithm attribute) (dissect.target.plugins.os.windows.regf.shellbags.CDBURN property) (dissect.target.plugins.os.windows.regf.shellbags.COMPRESSED_FOLDER property) (dissect.target.plugins.os.windows.regf.shellbags.CONTROL_PANEL property) (dissect.target.plugins.os.windows.regf.shellbags.CONTROL_PANEL_CATEGORY property) (dissect.target.plugins.os.windows.regf.shellbags.CONTROL_PANEL_CPL_FILE property) (dissect.target.plugins.os.windows.regf.shellbags.DELEGATE property) (dissect.target.plugins.os.windows.regf.shellbags.FILE_ENTRY property) (dissect.target.plugins.os.windows.regf.shellbags.GAME_FOLDER property) (dissect.target.plugins.os.windows.regf.shellbags.MTP_FILE_ENTRY property) (dissect.target.plugins.os.windows.regf.shellbags.MTP_VOLUME property) (dissect.target.plugins.os.windows.regf.shellbags.NETWORK property) (dissect.target.plugins.os.windows.regf.shellbags.ROOT_FOLDER property) (dissect.target.plugins.os.windows.regf.shellbags.SHITEM property) (dissect.target.plugins.os.windows.regf.shellbags.UNKNOWN property) (dissect.target.plugins.os.windows.regf.shellbags.UNKNOWN0 property) (dissect.target.plugins.os.windows.regf.shellbags.UNKNOWN1 property) (dissect.target.plugins.os.windows.regf.shellbags.UNKNOWN_0x74 property) (dissect.target.plugins.os.windows.regf.shellbags.URI property) (dissect.target.plugins.os.windows.regf.shellbags.USERS_PROPERTY_VIEW property) (dissect.target.plugins.os.windows.regf.shellbags.VOLUME property) (dissect.target.Target property) (dissect.target.target.Target property) (dissect.volume.lvm.metadata.HistoricalLogicalVolume attribute) (dissect.volume.lvm.metadata.LogicalVolume property) (dissect.volume.lvm.metadata.PhysicalVolume property) (dissect.volume.lvm.metadata.Segment property) (dissect.volume.lvm.metadata.VolumeGroup property) (flow.record.base.RecordDescriptor attribute) (flow.record.base.RecordField attribute) (flow.record.RecordDescriptor attribute) (flow.record.RecordField attribute) name() (dissect.jffs.jffs2.DirEntry method) (in module flow.record.selector) NAME_TO_GUID_MAP (in module dissect.esedb.tools.sru) NamedKey (class in dissect.regf.regf) NamedObject (class in acquire.acquire.dynamic.windows.named_objects) NamedObjectType (class in acquire.acquire.dynamic.windows.named_objects) names() (dissect.evidence.asdf.asdf.Metadata method) (in module flow.record.selector) Namespace (class in dissect.cim.cim) namespace() (dissect.cim.CIM method) (dissect.cim.cim.CIM method) (dissect.cim.cim.Namespace method) NAMESPACE_CLASS_NAME (in module dissect.cim.c_cim) NamespacePlugin (class in dissect.target.plugin) namespaces (dissect.cim.cim.Namespace property) NATIVE_TYPE_MAP (in module dissect.esedb.tools.sru) NATIVE_UNICODE (in module flow.record.fieldtypes) NativeLZ4 (class in dissect.squashfs.compression) NativeLZMA (class in dissect.squashfs.compression) NativeLZO (class in dissect.squashfs.compression) NativeXZ (class in dissect.squashfs.compression) NativeZlib (class in dissect.squashfs.compression) NativeZSTD (class in dissect.squashfs.compression) ndis() (dissect.target.plugins.os.windows.generic.GenericPlugin method) NdisRecord (in module dissect.target.plugins.os.windows.generic) NEEDLE (dissect.target.plugins.os.windows.log.evt.EvtPlugin attribute) (dissect.target.plugins.os.windows.log.evtx.EvtxPlugin attribute) net (flow.record.fieldtypes.net.ipv4.subnet attribute) (in module flow.record.base) NethistPlugin (class in dissect.target.plugins.os.windows.regf.nethist) netloc (flow.record.fieldtypes.uri property) netmask (dissect.target.helpers.network_managers.NetworkManager property) netmask() (dissect.target.plugins.os.unix.linux._os.LinuxPlugin method) NetSocket (class in dissect.target.plugins.os.unix.linux.proc) NetSocketPlugin (class in dissect.target.plugins.os.unix.linux.sockets) NetSocketRecord (in module dissect.target.plugins.os.unix.linux.sockets) Netstat (class in acquire.acquire.acquire) netstat() (dissect.target.plugins.os.unix.linux.netstat.NetstatPlugin method) NETSTAT_HEADER (in module dissect.target.plugins.os.unix.linux.netstat) NETSTAT_TEMPLATE (in module dissect.target.plugins.os.unix.linux.netstat) NetstatPlugin (class in dissect.target.plugins.os.unix.linux.netstat) NETWORK (class in dissect.target.plugins.os.windows.regf.shellbags) network_connectivity() (dissect.target.plugins.os.windows.sru.SRUPlugin method) network_data() (dissect.target.plugins.os.windows.sru.SRUPlugin method) network_history() (dissect.target.plugins.os.windows.regf.nethist.NethistPlugin method) NetworkConnectivityRecord (in module dissect.target.plugins.os.windows.sru) NetworkDataRecord (in module dissect.target.plugins.os.windows.sru) networkdrive() (dissect.target.plugins.os.windows.regf.mru.MRUPlugin method) NetworkHistoryRecord (in module dissect.target.plugins.os.windows.regf.nethist) NetworkManager (class in dissect.target.helpers.network_managers) new_file_handler() (in module acquire.acquire.log) NEW_SYN_RECV (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) next (dissect.cstruct.parser.TokenConsumer property) next() (dissect.btrfs.tree.Cursor method) (dissect.esedb.cursor.Cursor method) next_buffer (dissect.etl.Buffer property) (dissect.etl.etl.Buffer property) next_node() (dissect.btrfs.tree.Cursor method) next_page() (dissect.esedb.cursor.Cursor method) NginxPlugin (class in dissect.target.plugins.apps.webserver.nginx) nms() (in module dissect.target.helpers.cyber) NMS_JUMBLE_LOOP_SPEED (in module dissect.target.helpers.cyber) NMS_JUMBLE_SECONDS (in module dissect.target.helpers.cyber) NMS_MASK_TABLE (in module dissect.target.helpers.cyber) NMS_REVEAL_LOOP_SPEED (in module dissect.target.helpers.cyber) NMS_REVEAL_SECONDS (in module dissect.target.helpers.cyber) NMS_TYPE_EFFECT_SPEED (in module dissect.target.helpers.cyber) NO_DOCS (in module dissect.target.helpers.docs) NO_VOLUME_LABEL_ENTRY (in module dissect.fat.c_exfat) NoCellData, [1] Node (class in dissect.esedb.page) (class in dissect.util.compression.lzxpress_huffman) (class in dissect.volume.dm.btree) node() (dissect.esedb.cursor.Cursor method) (dissect.esedb.page.Page method) node_vcn (dissect.ntfs.index.IndexEntry property) (dissect.ntfs.IndexEntry property) nodes() (dissect.esedb.page.Page method) nofua (dissect.volume.lvm.metadata.WriteCacheSegment attribute) NoMoreEntriesError NoMoreEventsError NONE (dissect.target.tools.dump.utils.Compression attribute) NONE_OBJECT (in module flow.record.selector) NoNeighbourPageError, [1] NoneObject (class in flow.record.selector) NONSPACE_MARK (dissect.esedb.lcmapstring.SCRIPT attribute) noop() (in module dissect.esedb.record) NORM_IGNORECASE (dissect.esedb.lcmapstring.MapFlags attribute) NORM_IGNOREKANATYPE (dissect.esedb.lcmapstring.MapFlags attribute) NORM_IGNORENONSPACE (dissect.esedb.lcmapstring.MapFlags attribute) NORM_IGNORESYMBOLS (dissect.esedb.lcmapstring.MapFlags attribute) NORM_IGNOREWIDTH (dissect.esedb.lcmapstring.MapFlags attribute) NORM_LINGUISTIC_CASING (dissect.esedb.lcmapstring.MapFlags attribute) NORMAL_SUBCLUSTER_TYPES (in module dissect.hypervisor.disk.c_qcow2) normalise_field_name() (in module dissect.target.plugins.apps.webserver.iis) normalize() (flow.record.fieldtypes.uri static method) (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) normalize_fieldname() (in module flow.record.base) normalize_language() (in module dissect.target.helpers.localeutil) normalize_path() (in module acquire.acquire.utils) normalize_sysvol() (in module acquire.acquire.utils) normalize_timezone() (in module dissect.target.helpers.localeutil) normpath() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) NotADirectoryError, [1], [2], [3], [4], [5], [6], [7], [8], [9], [10], [11], [12], [13], [14], [15], [16], [17], [18] NotAFileError, [1], [2], [3] NotAnIndexFileError NotAReparsePointError, [1] NotASymlinkError, [1], [2], [3], [4], [5], [6], [7], [8], [9], [10], [11], [12], [13], [14] NotFoundError, [1] NOTIFICATIONS_DIR (in module dissect.target.plugins.os.windows.notifications) NotificationsPlugin (class in dissect.target.plugins.os.windows.notifications) now (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) now() (in module dissect.util.ts) NoWriteAheadLog, [1] nr_of_items (dissect.eventlog.wevt.WEVT_TYPE property) ns (dissect.cim.cim.Class property) (dissect.cim.cim.Instance property) NS (dissect.hypervisor.descriptor.ovf.OVF attribute) NSDictionary (class in dissect.util.plist) NSKeyedArchiver (class in dissect.util.plist) NSObject (class in dissect.util.plist) nt52_entry_type() (in module dissect.target.plugins.os.windows.regf.shimcache) nt61_entry_type() (in module dissect.target.plugins.os.windows.regf.shimcache) ntdll (in module acquire.acquire.dynamic.windows.ntdll) NTDS (class in acquire.acquire.acquire) NTFS (class in acquire.acquire.acquire) (class in dissect.ntfs) (class in dissect.ntfs.ntfs) ntfs_def (in module dissect.ntfs.c_ntfs) NTFS_NEEDLE (in module dissect.target.loaders.phobos) NTFS_SIGNATURE (in module dissect.ntfs) (in module dissect.ntfs.c_ntfs) NtfsFilesystem (class in dissect.target.filesystems.ntfs) NtfsFilesystemEntry (class in dissect.target.filesystems.ntfs) NtOpenDirectoryObject (in module acquire.acquire.dynamic.windows.ntdll) NtQueryDirectoryObject (in module acquire.acquire.dynamic.windows.ntdll) NtQueryInformationFile (in module acquire.acquire.dynamic.windows.ntdll) NtQueryObject (in module acquire.acquire.dynamic.windows.ntdll) NtQuerySystemInformation (in module acquire.acquire.dynamic.windows.ntdll) NTSTATUS (in module acquire.acquire.dynamic.windows.types) NtStatusCode (class in acquire.acquire.dynamic.windows.ntdll) ntversion() (dissect.target.plugins.os.windows.generic.GenericPlugin method) NULL (dissect.eventlog.bxml.BxmlType attribute) (in module acquire.acquire.dynamic.windows.types) NULL_GUID (in module dissect.hypervisor.disk.hdd) NullGuid (in module dissect.etl.utils) NullPointerDereference, [1] NullSessionPipeRecord (in module dissect.target.plugins.os.windows.generic) nullsessionpipes() (dissect.target.plugins.os.windows.generic.GenericPlugin method) num (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) NUM_APPDB_CHUNKS (in module dissect.target.plugins.os.windows.notifications) num_elements (dissect.regf.regf.FastLeaf property) (dissect.regf.regf.HashLeaf property) (dissect.regf.regf.IndexLeaf property) (dissect.regf.regf.IndexRoot property) NUM_OVERFLOW_SLOTS (dissect.target.plugins.os.unix.locate.plocate.PLocateFile attribute) num_stripes (dissect.btrfs.stream.Chunk attribute) O oatimestamp() (in module dissect.util.ts) OBJ_ATTR (class in acquire.acquire.dynamic.windows.ntdll) OBJ_CASE_INSENSITIVE (acquire.acquire.dynamic.windows.ntdll.OBJ_ATTR attribute) OBJ_EXCLUSIVE (acquire.acquire.dynamic.windows.ntdll.OBJ_ATTR attribute) OBJ_FORCE_ACCESS_CHECK (acquire.acquire.dynamic.windows.ntdll.OBJ_ATTR attribute) OBJ_IGNORE_IMPERSONATED_DEVICEMAP (acquire.acquire.dynamic.windows.ntdll.OBJ_ATTR attribute) OBJ_INHERIT (acquire.acquire.dynamic.windows.ntdll.OBJ_ATTR attribute) OBJ_KERNEL_HANDLE (acquire.acquire.dynamic.windows.ntdll.OBJ_ATTR attribute) OBJ_OPENIF (acquire.acquire.dynamic.windows.ntdll.OBJ_ATTR attribute) OBJ_OPENLINK (acquire.acquire.dynamic.windows.ntdll.OBJ_ATTR attribute) OBJ_PERMANENT (acquire.acquire.dynamic.windows.ntdll.OBJ_ATTR attribute) OBJ_VALID_ATTRIBUTES (acquire.acquire.dynamic.windows.ntdll.OBJ_ATTR attribute) object (acquire.acquire.dynamic.windows.types.SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX property) object() (dissect.cim.index.Key method) OBJECT_ATTRIBUTES (class in acquire.acquire.dynamic.windows.ntdll) OBJECT_DIRECTORY_INFORMATION (class in acquire.acquire.dynamic.windows.types) OBJECT_INFORMATION_CLASS (class in acquire.acquire.dynamic.windows.types) object_type_index (acquire.acquire.dynamic.windows.types.SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX property) ObjectBasicInformation (acquire.acquire.dynamic.windows.types.OBJECT_INFORMATION_CLASS attribute) ObjectEntryType (in module dissect.hypervisor.descriptor.c_hyperv) ObjectGuid (in module dissect.etl.utils) ObjectNameInformation (acquire.acquire.dynamic.windows.types.OBJECT_INFORMATION_CLASS attribute) ObjectPath (in module dissect.cim.utils) Objects (class in dissect.cim.objects) objects() (dissect.cim.index.Key method) (dissect.cim.objects.DataPage method) ObjectTypeInformation (acquire.acquire.dynamic.windows.types.OBJECT_INFORMATION_CLASS attribute) offset (dissect.btrfs.stream.Chunk attribute) (dissect.btrfs.stream.Extent attribute) (dissect.btrfs.stream.Stripe attribute) (dissect.cim.cim.Property property) (dissect.cim.classes.ClassInstanceProperty property) (dissect.esedb.table.Column property) offset_into_cluster() (in module dissect.hypervisor.disk.qcow2) offset_into_subcluster() (in module dissect.hypervisor.disk.qcow2) offset_to_l1_index() (in module dissect.hypervisor.disk.qcow2) offset_to_l2_index() (in module dissect.hypervisor.disk.qcow2) offset_to_sc_index() (in module dissect.hypervisor.disk.qcow2) OLE (class in dissect.ole) (class in dissect.ole.ole) ole32 (in module acquire.acquire.gui.win32) ole_def (in module dissect.ole.c_ole) on_new_descriptor() (flow.record.stream.RecordStreamWriter method) ONLY_READ_CACHE (in module dissect.target.helpers.cache) OPCO (class in dissect.eventlog.wevt_object) opcode (dissect.etl.headers.event.EventHeader property) (dissect.etl.headers.system.SystemSpecificHeader property) open() (dissect.archive.wim.DirectoryEntry method) (dissect.archive.wim.Resource method) (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.cim.classes.DataRegion method) (dissect.clfs.c_clfs.BlockHeader method) (dissect.etl.Buffer method) (dissect.etl.etl.Buffer method) (dissect.evidence.ad1.AD1 method) (dissect.evidence.ad1.FileEntry method) (dissect.evidence.asdf.asdf.AsdfSnapshot method) (dissect.evidence.asdf.asdf.Metadata method) (dissect.evidence.asdf.AsdfSnapshot method) (dissect.evidence.AsdfSnapshot method) (dissect.evidence.EWF method) (dissect.evidence.ewf.EWF method) (dissect.extfs.extfs.INode method) (dissect.extfs.INode method) (dissect.extfs.journal.DescriptorBlockTag method) (dissect.fat.fat.DirectoryEntry method) (dissect.fat.fat.RootDirectory method) (dissect.ffs.ffs.INode method) (dissect.hypervisor.backup.vma.Device method) (dissect.hypervisor.backup.xva.XVA method) (dissect.hypervisor.descriptor.hyperv.HyperVStorageFileObject method) (dissect.hypervisor.disk.hdd.HDD method) (dissect.hypervisor.disk.qcow2.QCow2Snapshot method) (dissect.jffs.jffs2.INode method) (dissect.ntfs.attr.Attribute method) (dissect.ntfs.attr.AttributeHeader method) (dissect.ntfs.Attribute method) (dissect.ntfs.AttributeHeader method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.ntfs.util.AttributeCollection method) (dissect.ole.ole.Chain method) (dissect.ole.ole.DirectoryEntry method) (dissect.ole.ole.MiniChain method) (dissect.regf.regf.RegistryHive method) (dissect.regf.RegistryHive method) (dissect.sql.sqlite3.Page method) (dissect.squashfs.INode method) (dissect.squashfs.squashfs.INode method) (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.MappedCompressedFile method) (dissect.target.filesystem.MappedFile method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry method) (dissect.target.filesystems.cb.CbFilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.exfat.ExfatFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.fat.FatFilesystemEntry method) (dissect.target.filesystems.ffs.FfsFilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemEntry method) (dissect.target.filesystems.jffs.JFFSFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.smb.SmbFilesystemEntry method) (dissect.target.filesystems.squashfs.SquashFSFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystemEntry method) (dissect.target.filesystems.vmfs.VmfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) (dissect.target.filesystems.zip.ZipFilesystemEntry method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) (dissect.target.helpers.mount.DissectMount method) (dissect.target.loaders.ad1.AD1File method) (dissect.target.loaders.itunes.ITunesBackup method) (dissect.target.loaders.res.File method) (dissect.target.loaders.res.ResFile method) (dissect.target.loaders.res.UPR method) (dissect.target.loaders.target.TargetLoader method) (dissect.target.loaders.vbox.VBoxLoader method) (dissect.target.Target class method) (dissect.target.target.Target class method) (dissect.vmfs.resource.ResourceManager method) (dissect.vmfs.vmfs.FileDescriptor method) (dissect.volume.disk.Partition method) (dissect.volume.disk.partition.Partition method) (dissect.volume.dm.thin.ThinPool method) (dissect.volume.lvm.LVM2Device method) (dissect.volume.lvm.metadata.LogicalVolume method) (dissect.volume.lvm.metadata.MirrorSegment method) (dissect.volume.lvm.metadata.Segment method) (dissect.volume.lvm.metadata.StripedSegment method) (dissect.volume.lvm.metadata.ThinPoolSegment method) (dissect.volume.lvm.metadata.ThinSegment method) (dissect.volume.lvm.physical.LVM2Device method) (dissect.volume.raid.raid.PhysicalDisk method) (dissect.volume.raid.raid.VirtualDisk method) (dissect.volume.vss.Store method) (dissect.xfs.xfs.INode method) (in module dissect.hypervisor.util.vmtar) (in module dissect.target.container) (in module dissect.target.filesystem) (in module dissect.target.loader) (in module dissect.target.volume) (in module dissect.util.cpio) open_all() (dissect.target.Target class method) (dissect.target.target.Target class method) (dissect.target.volume.LogicalVolumeSystem class method) (dissect.target.volumes.ddf.DdfVolumeSystem class method) (dissect.target.volumes.lvm.LvmVolumeSystem class method) (dissect.target.volumes.md.MdVolumeSystem class method) (dissect.target.volumes.vmfs.VmfsVolumeSystem class method) open_child() (dissect.target.Target method) (dissect.target.target.Target method) open_children() (dissect.target.Target method) (dissect.target.target.Target method) open_decompress() (in module dissect.target.helpers.fsutil) open_directory_object() (in module acquire.acquire.dynamic.windows.ntdll) open_encrypted() (in module dissect.target.volume) open_lvm() (in module dissect.target.volume) open_multi_volume() (in module dissect.target.filesystem) open_parent() (in module dissect.hypervisor.disk.vhdx) (in module dissect.hypervisor.disk.vmdk) open_path() (in module dissect.target.tools.dump.utils) (in module flow.record) (in module flow.record.base) open_path_or_stream() (in module flow.record) (in module flow.record.base) open_pool() (dissect.volume.lvm.metadata.ThinPoolSegment method) open_process() (in module acquire.acquire.dynamic.windows.handles) open_raw() (dissect.target.Target class method) (dissect.target.target.Target class method) open_reader() (dissect.target.helpers.cache.Cache method) open_segment() (dissect.evidence.EWF method) (dissect.evidence.ewf.EWF method) open_shell() (in module dissect.target.tools.shell) open_stream() (in module flow.record) (in module flow.record.base) open_subvolume() (dissect.btrfs.Btrfs method) (dissect.btrfs.btrfs.Btrfs method) (dissect.target.filesystems.btrfs.BtrfsFilesystem method) OPEN_TYPES (in module dissect.target.volumes.lvm) open_wal() (dissect.sql.SQLite3 method) (dissect.sql.sqlite3.SQLite3 method) open_writer() (dissect.target.helpers.cache.Cache method) OPEN_WRITERS_LIMIT (in module dissect.target.tools.dump.utils) OpenBsdPlugin (class in dissect.target.plugins.os.unix.bsd.openbsd._os) opendir() (dissect.target.helpers.mount.DissectMount method) OpenHandles (class in acquire.acquire.acquire) OpenHandlesPlugin (class in dissect.target.plugins.filesystem.acquire_handles) OpenProcess (in module acquire.acquire.dynamic.windows.handles) OpenProcessError OpenProcessToken (in module acquire.acquire.dynamic.windows.handles) opensave() (dissect.target.plugins.os.windows.regf.mru.MRUPlugin method) OpenSaveMRURecord (in module dissect.target.plugins.os.windows.regf.mru) OpenSSHPlugin (class in dissect.target.plugins.apps.ssh.openssh) OpenSSHUserRecordDescriptor (in module dissect.target.plugins.apps.ssh.ssh) openTable() (dissect.esedb.tools.impacket.ESENT_DB method) OpenVPNClient (in module dissect.target.plugins.apps.vpn.openvpn) OpenVPNPlugin (class in dissect.target.plugins.apps.vpn.openvpn) OpenVPNServer (in module dissect.target.plugins.apps.vpn.openvpn) OperatingSystem (class in dissect.target.plugin) OperationTypes (class in dissect.target.plugins.os.unix.packagemanager) operator() (dissect.cstruct.expression.ExpressionTokenizer method) operators (dissect.cstruct.Expression attribute) (dissect.cstruct.expression.Expression attribute) origin (dissect.volume.lvm.metadata.CacheSegment attribute) (dissect.volume.lvm.metadata.HistoricalLogicalVolume attribute) (dissect.volume.lvm.metadata.IntegritySegment attribute) (dissect.volume.lvm.metadata.SnapshotSegment attribute) (dissect.volume.lvm.metadata.ThinSegment attribute) (dissect.volume.lvm.metadata.WriteCacheSegment attribute) OS (class in dissect.target.filesystems.cb) os() (dissect.target.loaders.profile.ProfileOSPlugin method) (dissect.target.loaders.res.ResOSPlugin method) (dissect.target.plugin.OSPlugin method) (dissect.target.plugins.general.default.DefaultPlugin method) (dissect.target.plugins.os.unix._os.UnixPlugin method) (dissect.target.plugins.os.unix.bsd._os.BsdPlugin method) (dissect.target.plugins.os.unix.bsd.citrix._os.CitrixPlugin method) (dissect.target.plugins.os.unix.bsd.ios._os.IOSPlugin method) (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin method) (dissect.target.plugins.os.unix.esxi._os.ESXiPlugin method) (dissect.target.plugins.os.unix.linux._os.LinuxPlugin method) (dissect.target.plugins.os.unix.linux.android._os.AndroidPlugin method) (dissect.target.plugins.os.unix.linux.debian.vyos._os.VyosPlugin method) (dissect.target.plugins.os.unix.linux.fortios._os.FortiOSPlugin method) (dissect.target.plugins.os.windows._os.WindowsPlugin method) os_plugins() (in module dissect.target.plugin) os_type_from_path() (in module dissect.target.loaders.dir) osinfo() (dissect.target.plugins.general.osinfo.OSInfoPlugin method) OSInfoPlugin (class in dissect.target.plugins.general.osinfo) OSInfoRecord (in module dissect.target.plugins.general.osinfo) OSPlugin (class in dissect.target.plugin) OSX (class in acquire.acquire.acquire) (dissect.target.plugin.OperatingSystem attribute) OSXApplicationsInfo (class in acquire.acquire.acquire) OSXProfile (class in acquire.acquire.acquire) Other (dissect.target.plugins.os.unix.packagemanager.OperationTypes attribute) otime() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) otime_ns() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) OUTBOUND (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) outcome (acquire.acquire.collector.Record attribute) Outcome (class in acquire.acquire.collector) Output (class in acquire.acquire.outputs.base) output_dir (dissect.target.tools.dump.state.DumpState attribute) output_plugin_description_recursive() (in module dissect.target.plugins.general.plugins) output_type (dissect.target.plugin.PluginFunction attribute) OUTPUTS (in module dissect.target.plugin) ova (dissect.hypervisor.backup.xva.XVA property) OvaLoader (class in dissect.target.loaders.ova) OverlayStream (class in dissect.util.stream) OVF (class in dissect.hypervisor.descriptor.ovf) OvfLoader (class in dissect.target.loaders.ovf) owner (dissect.target.plugins.filesystem.ntfs.mft_timeline.Extras attribute) (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) owner() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) owner_id (dissect.ntfs.attr.StandardInformation property) P P (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) p16() (in module dissect.cstruct) (in module dissect.cstruct.utils) p32() (in module dissect.cstruct) (in module dissect.cstruct.utils) p64() (in module dissect.cstruct) (in module dissect.cstruct.utils) p8() (in module dissect.cstruct) (in module dissect.cstruct.utils) pack() (dissect.cstruct.BytesInteger static method) (dissect.cstruct.types.BytesInteger static method) (dissect.cstruct.types.bytesinteger.BytesInteger static method) (dissect.target.tools.dump.utils.SortedKeysJsonRecordPacker method) (flow.record.jsonpacker.JsonRecordPacker method) (flow.record.JsonRecordPacker method) (flow.record.packer.RecordPacker method) (in module dissect.cstruct) (in module dissect.cstruct.utils) pack_obj() (flow.record.jsonpacker.JsonRecordPacker method) (flow.record.JsonRecordPacker method) (flow.record.packer.RecordPacker method) PackageManagerLogRecord (in module dissect.target.plugins.os.unix.packagemanager) PackageManagerPlugin (class in dissect.target.plugins.os.unix.packagemanager) packb (in module flow.record.packer) PackedType (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.packedtype) packer (flow.record.stream.RecordStreamReader attribute) (flow.record.stream.RecordStreamWriter attribute) packer_on_new_descriptor() (flow.record.adapter.jsonfile.JsonfileWriter method) packet() (dissect.target.plugins.os.unix.linux.proc.Sockets method) (dissect.target.plugins.os.unix.linux.sockets.NetSocketPlugin method) PacketSocket (class in dissect.target.plugins.os.unix.linux.proc) PacketSocketRecord (in module dissect.target.plugins.os.unix.linux.sockets) PaddingTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) Page (class in dissect.esedb.page) (class in dissect.sql.sqlite3) page() (dissect.cim.index.Store method) (dissect.cim.objects.Store method) (dissect.esedb.EseDB method) (dissect.esedb.esedb.EseDB method) (dissect.sql.SQLite3 method) (dissect.sql.sqlite3.SQLite3 method) page_count (dissect.sql.sqlite3.WALFrame property) PAGE_FLAG (in module dissect.esedb.c_esedb) page_map (dissect.sql.sqlite3.WALCheckpoint property) page_number (dissect.sql.sqlite3.WALFrame property) PAGE_TYPES (in module dissect.sql.c_sqlite3) PageFaultGuid (in module dissect.etl.utils) pages() (dissect.esedb.EseDB method) (dissect.esedb.esedb.EseDB method) (dissect.sql.SQLite3 method) (dissect.sql.sqlite3.SQLite3 method) PAINTSTRUCT (class in acquire.acquire.gui.win32) Pair (class in dissect.hypervisor.descriptor.vmx) Palette (in module dissect.cstruct.utils) PanelPathRecord (in module dissect.target.plugins.os.windows.regf.7zip) params (flow.record.fieldtypes.uri property) parent (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) (dissect.hypervisor.disk.hdd.Shot attribute) (dissect.target.helpers.compat.path_310.PureDissectPath property) (dissect.target.helpers.compat.path_311.PureDissectPath property) (dissect.target.helpers.compat.path_39.PureDissectPath property) (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) (dissect.target.plugins.os.unix.locate.mlocate.MLocate attribute) (dissect.vmfs.vmfs.FileDescriptor property) (in module flow.record.whitelist) parent() (dissect.cim.cim.Namespace method) (dissect.ntfs.usnjrnl.UsnRecord method) (dissect.ntfs.UsnRecord method) parent_guid (dissect.etl.headers.headers.EventInstanceGUIDHeader property) PARENT_LOCATOR_GUID (in module dissect.hypervisor.disk.c_vhdx) parent_name (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) ParentLocator (class in dissect.hypervisor.disk.vhdx) parents (dissect.btrfs.btrfs.INode property) (dissect.btrfs.INode property) (dissect.target.helpers.compat.path_310.PureDissectPath property) (dissect.target.helpers.compat.path_311.PureDissectPath property) (dissect.target.helpers.compat.path_39.PureDissectPath property) PARITY_0 (dissect.volume.raid.stream.Layout attribute) PARITY_0_6 (dissect.volume.raid.stream.Layout attribute) PARITY_N (dissect.volume.raid.stream.Layout attribute) PARITY_N_6 (dissect.volume.raid.stream.Layout attribute) parse() (dissect.cstruct.BytesInteger static method) (dissect.cstruct.parser.CStyleParser method) (dissect.cstruct.parser.Parser method) (dissect.cstruct.parser.TokenParser method) (dissect.cstruct.types.BytesInteger static method) (dissect.cstruct.types.bytesinteger.BytesInteger static method) (dissect.hypervisor.descriptor.vmx.VMX class method) (dissect.hypervisor.disk.vmdk.DiskDescriptor class method) (dissect.target.helpers.network_managers.NetworkManager method) (dissect.target.helpers.network_managers.Parser method) (dissect.target.plugins.os.windows.prefetch.Prefetch method) (in module dissect.shellitem.tools.lnk) (in module dissect.target.helpers.configutil) parse_acquire_args() (in module acquire.acquire.utils) parse_address() (dissect.vmfs.resource.FileDescriptorResource method) (dissect.vmfs.resource.JournalBlockResource method) (dissect.vmfs.resource.LargeFileBlockResource method) (dissect.vmfs.resource.PointerBlockResource method) (dissect.vmfs.resource.ResourceFile method) (dissect.vmfs.resource.ResourceManager method) (dissect.vmfs.resource.SmallFileBlockResource method) (dissect.vmfs.resource.SubBlockResource method) parse_arguments() (in module dissect.target.tools.dump.run) parse_autodetect_format_log() (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin method) parse_boot_cfg() (in module dissect.target.plugins.os.unix.esxi._os) parse_bxml() (in module dissect.eventlog.bxml) parse_cell_data() (dissect.regf.regf.RegistryHive method) (dissect.regf.RegistryHive method) parse_chunk() (in module dissect.eventlog.evt) parse_config() (in module dissect.target.helpers.configutil) parse_config_store() (in module dissect.target.plugins.os.unix.esxi._os) parse_crontab() (dissect.target.plugins.os.unix.cronjobs.CronjobPlugin method) parse_datetime_iso() (in module dissect.target.tools.dump.utils) parse_def() (in module flow.record.base) parse_device_name() (dissect.target.plugins.os.windows.regf.usb.UsbPlugin method) parse_dynamic_dst() (in module dissect.target.plugins.os.windows.datetime) parse_esx_conf() (in module dissect.target.plugins.os.unix.esxi._os) parse_fb_address() (in module dissect.vmfs.resource) parse_fd_address() (in module dissect.vmfs.resource) parse_file() (dissect.target.helpers.configutil.ConfigurationParser method) (dissect.target.helpers.configutil.Default method) (dissect.target.helpers.configutil.Indentation method) (dissect.target.helpers.configutil.Ini method) (dissect.target.helpers.configutil.Json method) (dissect.target.helpers.configutil.SystemD method) (dissect.target.helpers.configutil.Txt method) (dissect.target.helpers.configutil.Xml method) (dissect.target.helpers.configutil.Yaml method) (dissect.target.plugins.os.windows.amcache.AmcachePluginOldMixin method) parse_fish_history() (dissect.target.plugins.os.unix.history.CommandHistoryPlugin method) parse_flex_value() (in module dissect.target.helpers.regutil) parse_fsblock() (in module dissect.xfs.xfs) parse_fstab() (in module dissect.target.plugins.os.unix._os) parse_generic_history() (dissect.target.plugins.os.unix.history.CommandHistoryPlugin method) parse_host_user() (in module dissect.target.plugins.apps.ssh.putty) parse_iis_format_log() (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin method) parse_inventory_application() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) parse_inventory_application_file() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) parse_inventory_application_shortcut() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) parse_inventory_device_container() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) parse_inventory_driver_binary() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) parse_ip() (in module dissect.target.plugins.os.unix.linux.proc) parse_iso_datetime() (in module dissect.target.plugins.os.windows.defender) parse_jb_address() (in module dissect.vmfs.resource) parse_key() (dissect.target.plugins.os.windows.regf.7zip.SevenZipPlugin method) parse_key_bag() (in module dissect.target.loaders.itunes) parse_key_type() (in module dissect.target.helpers.keychain) parse_known_host() (in module dissect.target.plugins.apps.ssh.openssh) parse_lfb_address() (in module dissect.vmfs.resource) parse_log_date_time() (in module dissect.target.plugins.os.unix.linux.debian.dpkg) parse_log_line() (in module dissect.target.plugins.os.unix.linux.debian.dpkg) parse_metadata() (in module dissect.volume.lvm.physical) parse_metrics() (dissect.target.plugins.os.windows.prefetch.Prefetch method) parse_mru_ex_key() (in module dissect.target.plugins.os.windows.regf.mru) parse_mru_key() (in module dissect.target.plugins.os.windows.regf.mru) parse_netscaler_bash_history() (dissect.target.plugins.os.unix.bsd.citrix.history.CitrixCommandHistoryPlugin method) parse_netscaler_cli_history() (dissect.target.plugins.os.unix.bsd.citrix.history.CitrixCommandHistoryPlugin method) parse_nsarray() (in module dissect.util.plist) parse_nsdata() (in module dissect.util.plist) parse_nsdate() (in module dissect.util.plist) parse_nsset() (in module dissect.util.plist) parse_nsurl() (in module dissect.util.plist) parse_nsuuid() (in module dissect.util.plist) parse_object_path() (in module dissect.cim.utils) parse_office_mru() (in module dissect.target.plugins.os.windows.regf.mru) parse_office_mru_key() (in module dissect.target.plugins.os.windows.regf.mru) parse_options_string() (in module dissect.target.helpers.utils) parse_path() (in module flow.record.adapter.mongo) parse_path_uri() (in module dissect.target.helpers.utils) parse_payload() (in module dissect.etl.etl) parse_pb_address() (in module dissect.vmfs.resource) parse_programs() (dissect.target.plugins.os.windows.amcache.AmcachePluginOldMixin method) parse_record() (in module dissect.eventlog.evt) parse_sb_address() (in module dissect.vmfs.resource) parse_sfb_address() (in module dissect.vmfs.resource) parse_shell_item_list() (in module dissect.target.plugins.os.windows.regf.shellbags) parse_ssh_key() (in module dissect.target.plugins.apps.ssh.openssh) parse_ssh_public_key_file() (in module dissect.target.plugins.apps.ssh.openssh) parse_start_element() (dissect.eventlog.bxml.Bxml method) parse_status_block() (in module dissect.target.plugins.os.unix.linux.debian.dpkg) parse_systemtime_transition() (in module dissect.target.plugins.os.windows.datetime) parse_table_columns_constraints() (in module dissect.sql.utils) parse_ts() (in module dissect.target.plugins.os.windows.regf.nethist) (in module dissect.target.plugins.os.windows.startupinfo) parse_tzi() (in module dissect.target.plugins.os.windows.datetime) parse_unix_dhcp_log_messages() (in module dissect.target.helpers.network_managers) parse_value() (in module dissect.regf.regf) parse_version() (in module dissect.target.plugins.os.unix.linux.fortios._os) parse_w3c_format_log() (dissect.target.plugins.apps.webserver.iis.IISLogsPlugin method) parse_win_datetime() (in module dissect.target.plugins.os.windows.amcache) parse_win_timestamp() (in module dissect.target.plugins.os.windows.amcache) parse_zsh_history() (dissect.target.plugins.os.unix.history.CommandHistoryPlugin method) parsed_data (dissect.target.helpers.configutil.ConfigurationParser attribute) Parser (class in dissect.cstruct.parser) (class in dissect.target.helpers.network_managers) parser (dissect.target.helpers.configutil.ParserConfig attribute) parser_items (dissect.target.filesystems.config.ConfigurationEntry attribute) ParserConfig (class in dissect.target.helpers.configutil) ParserError, [1] ParserOptions (class in dissect.target.helpers.configutil) PARTITION (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) Partition (class in dissect.volume.disk) (class in dissect.volume.disk.partition) PARTITION_TYPES (in module dissect.volume.disk.partition) parts() (dissect.cim.index.Key method) PASS2KEY_MAP (in module dissect.hypervisor.descriptor.vmx) pass_shown (acquire.acquire.gui.win32.Win32 attribute) PASSPHRASE (dissect.target.helpers.keychain.KeyType attribute) password (class in flow.record.fieldtypes.credential) (flow.record.fieldtypes.uri property) passwords() (dissect.target.plugins.os.unix.shadow.ShadowPlugin method) patch() (dissect.executable.elf.elf.Segment method) (dissect.executable.elf.Segment method) PATH (acquire.acquire.collector.ArtifactType attribute) path (class in flow.record.fieldtypes) (dissect.btrfs.btrfs.INode property) (dissect.btrfs.INode property) (dissect.eventlog.wevtutil.WevtutilWrapper attribute) (dissect.fat.fat.DirectoryEntry property) (dissect.fat.fat.RootDirectory property) (dissect.regf.regf.NamedKey property) (dissect.target.helpers.regutil.KeyCollection property) (dissect.target.helpers.regutil.RegfKey property) (dissect.target.helpers.regutil.RegistryKey property) (dissect.target.helpers.regutil.VirtualKey property) (dissect.target.loaders.cb.CbRegistryKey property) (dissect.target.loaders.res.File property) (dissect.target.loaders.res.Folder property) (dissect.target.loaders.smb.SmbRegistryKey property) (dissect.target.plugin.PluginFunction attribute) PATH (dissect.target.plugins.child.hyperv.HyperVChildTargetPlugin attribute) (dissect.target.plugins.child.virtuozzo.VirtuozzoChildTargetPlugin attribute) path (dissect.target.plugins.os.unix.linux.modules.Module attribute) (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) (dissect.target.plugins.os.unix.locate.gnulocate.GNULocatePlugin attribute) (dissect.target.plugins.os.unix.locate.mlocate.MLocate attribute) (dissect.target.plugins.os.unix.locate.mlocate.MLocatePlugin attribute) (dissect.target.plugins.os.unix.locate.plocate.PLocatePlugin attribute) (dissect.target.tools.dump.state.DumpState property) (dissect.target.tools.dump.state.Sink attribute) (flow.record.fieldtypes.uri property) path() (dissect.btrfs.btrfs.Subvolume method) (dissect.btrfs.Subvolume method) (dissect.target.filesystem.Filesystem method) path_extensions() (dissect.target.plugins.os.windows.env.EnvironmentVariablePlugin method) PATH_POSIX (in module flow.record.fieldtypes) PATH_REPLACEMENTS (in module dissect.target.loaders.res) path_type (in module flow.record.fieldtypes) PATH_WINDOWS (in module flow.record.fieldtypes) pathenvironment() (dissect.target.plugins.os.windows.generic.GenericPlugin method) pathext (dissect.target.plugins.os.windows.env.EnvironmentVariablePlugin property) PathextRecord (in module dissect.target.plugins.os.windows.env) PathHistoryRecord (in module dissect.target.plugins.os.windows.regf.7zip) PATHS (dissect.target.plugins.apps.shell.powershell.PowerShellHistoryPlugin attribute) (dissect.target.plugins.os.windows.log.etl.EtlPlugin attribute) (dissect.target.plugins.os.windows.log.schedlgu.SchedLgUPlugin attribute) (dissect.target.plugins.os.windows.tasks.TasksPlugin attribute) paths() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) PathTemplateWriter (class in flow.record.stream) pattern (dissect.target.plugins.apps.webserver.apache.LogFormat attribute) PATTERN_IPTABLES_SAVE_GENERATED (in module dissect.target.plugins.os.unix.linux.iptables) PATTERN_IPTABLES_SAVE_POLICY (in module dissect.target.plugins.os.unix.linux.iptables) PATTERN_IPTABLES_SAVE_RULE (in module dissect.target.plugins.os.unix.linux.iptables) pause_writeback (dissect.volume.lvm.metadata.WriteCacheSegment attribute) payload (dissect.etl.headers.headers.Header property) (dissect.etl.headers.logfile.LogfileHeader property) payload_types (dissect.eventlog.wevt.WEVT property) pb() (dissect.hypervisor.disk.vhdx.BlockAllocationTable method) pb2 (dissect.vmfs.resource.ResourceManager property) pbc (dissect.vmfs.resource.ResourceManager property) pbkdf2() (in module dissect.target.plugins.os.windows.dpapi.crypto) PBKDF2_SALT (in module dissect.hypervisor.util.envelope) PBM_DELTAPOS (in module acquire.acquire.gui.win32) PBM_SETPOS (in module acquire.acquire.gui.win32) PBM_SETRANGE (in module acquire.acquire.gui.win32) PBM_SETRANGE32 (in module acquire.acquire.gui.win32) PBM_SETSTEP (in module acquire.acquire.gui.win32) PBM_STEPIT (in module acquire.acquire.gui.win32) PBS_SMOOTH (in module acquire.acquire.gui.win32) PCA (class in acquire.acquire.acquire) pe_count (dissect.volume.lvm.metadata.PhysicalVolume attribute) pe_start (dissect.volume.lvm.metadata.PhysicalVolume attribute) PEBS_INDEX (dissect.etl.headers.event.ExtType attribute) peek() (dissect.target.helpers.configutil.PeekableIterator method) PeekableIterator (class in dissect.target.helpers.configutil) PEM_ENCRYPTED (in module dissect.target.helpers.ssh) PEM_MARKER_END_DSA (in module dissect.target.helpers.ssh) PEM_MARKER_END_EC (in module dissect.target.helpers.ssh) PEM_MARKER_END_RSA (in module dissect.target.helpers.ssh) PEM_MARKER_START_DSA (in module dissect.target.helpers.ssh) PEM_MARKER_START_EC (in module dissect.target.helpers.ssh) PEM_MARKER_START_RSA (in module dissect.target.helpers.ssh) pending_updates_count (dissect.target.tools.dump.state.DumpState attribute) PENDING_UPDATES_LIMIT (in module dissect.target.tools.dump.state) perf_freq (dissect.etl.headers.logfile.LogfileHeader property) PerfinfoGuid (in module dissect.etl.utils) PerfinfoTraceHeader (class in dissect.etl.headers.system) PERFORMANCE_FREQ (dissect.etl.headers.logfile.ReservedFlags attribute) PERFORMANCE_TIMESTAMP (dissect.etl.headers.headers.EventProperty attribute) persist() (dissect.target.tools.dump.state.DumpState method) persist_execution_report() (in module acquire.acquire.utils) (in module dissect.target.tools.utils) persist_processing_state() (in module dissect.target.tools.dump.run) persisted_state() (in module dissect.target.tools.dump.state) PF (in module dissect.executable.elf.c_elf) pfro() (dissect.target.plugins.os.windows.log.pfro.PfroPlugin method) PfroPlugin (class in dissect.target.plugins.os.windows.log.pfro) PfroRecord (in module dissect.target.plugins.os.windows.log.pfro) pfwlog_def (in module dissect.target.plugins.apps.av.trendmicro) pgnoFDPMSO (in module dissect.esedb.c_esedb) pgnoFDPMSO_NameIndex (in module dissect.esedb.c_esedb) pgnoFDPMSO_RootObjectIndex (in module dissect.esedb.c_esedb) pgnoFDPMSOShadow (in module dissect.esedb.c_esedb) PhobosLoader (class in dissect.target.loaders.phobos) Phrase (class in dissect.hypervisor.descriptor.vmx) physical_page() (dissect.cim.objects.Store method) PHYSICAL_SECTOR_SIZE_GUID (in module dissect.hypervisor.disk.c_vhdx) physical_threads (dissect.volume.lvm.metadata.VdoPoolSegment attribute) physical_volumes (dissect.volume.lvm.metadata.VolumeGroup attribute) PhysicalDisk (class in dissect.volume.raid.raid) PhysicalDiskData (class in dissect.volume.ddf.ddf) PhysicalDiskRecord (class in dissect.volume.ddf.ddf) PhysicalVolume (class in dissect.volume.lvm.metadata) pid (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) PKCS8_MARKER_END (in module dissect.target.helpers.ssh) PKCS8_MARKER_END_ENCRYPTED (in module dissect.target.helpers.ssh) PKCS8_MARKER_START (in module dissect.target.helpers.ssh) PKCS8_MARKER_START_ENCRYPTED (in module dissect.target.helpers.ssh) plocate_def (in module dissect.target.plugins.os.unix.locate.plocate) PLocateFile (class in dissect.target.plugins.os.unix.locate.plocate) PLocatePlugin (class in dissect.target.plugins.os.unix.locate.plocate) PLocateRecord (in module dissect.target.plugins.os.unix.locate.plocate) Plugin (class in dissect.target.plugin) plugin_bridge() (dissect.target.loaders.targetd.TargetdLoader method) plugin_desc (dissect.target.plugin.PluginFunction attribute) plugin_factory() (in module dissect.target.tools.utils) plugin_function_index() (in module dissect.target.plugin) plugin_function_with_argparser() (in module dissect.target.tools.utils) plugin_import_errors (dissect.target.report.ExecutionReport attribute) PluginDescriptor (in module dissect.target.plugin) PluginError PluginFunction (class in dissect.target.plugin) PluginListPlugin (class in dissect.target.plugins.general.plugins) PluginNotFoundError PluginRegistry (class in acquire.acquire.uploaders.plugin_registry) plugins() (dissect.target.plugins.general.plugins.PluginListPlugin method) (in module dissect.target.plugin) PMC_COUNTERS (dissect.etl.headers.event.ExtType attribute) Pointer (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.pointer) pointer (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) POINTER32 (dissect.etl.headers.headers.EventProperty attribute) POINTER64 (dissect.etl.headers.headers.EventProperty attribute) pointer_size (dissect.etl.headers.logfile.LogfileHeader property) PointerBlockResource (class in dissect.vmfs.resource) PointerInstance (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.pointer) policy (dissect.volume.lvm.metadata.CachePoolSegment attribute) (dissect.volume.lvm.metadata.CacheSegment attribute) POLICY_CATEGORIES (in module dissect.target.plugins.os.windows.regf.auditpol) POLICY_MAP (in module dissect.target.plugins.os.windows.regf.auditpol) policy_settings (dissect.volume.lvm.metadata.CachePoolSegment attribute) (dissect.volume.lvm.metadata.CacheSegment attribute) POLICY_VALUES (in module dissect.target.plugins.os.windows.regf.auditpol) pool (dissect.volume.lvm.metadata.ThinPoolSegment attribute) PoolGuid (in module dissect.etl.utils) pop() (dissect.btrfs.tree.Cursor method) (dissect.target.helpers.configutil.ScopeManager method) populate_role_guid_map() (dissect.target.plugins.os.windows.ual.UalPlugin method) port (class in flow.record.fieldtypes.net.tcp) (class in flow.record.fieldtypes.net.udp) (flow.record.fieldtypes.uri property) Port (in module flow.record.fieldtypes.net.tcp) (in module flow.record.fieldtypes.net.udp) posix_path (class in flow.record.fieldtypes) PowerGuid (in module dissect.etl.utils) PowerShell (class in acquire.acquire.acquire) powershell_history() (dissect.target.plugins.apps.shell.powershell.PowerShellHistoryPlugin method) PowerShellHistoryPlugin (class in dissect.target.plugins.apps.shell.powershell) ppid (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) precedence() (dissect.cstruct.Expression method) (dissect.cstruct.expression.Expression method) precedence_levels (dissect.cstruct.Expression attribute) (dissect.cstruct.expression.Expression attribute) predicted_tick (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) Prefetch (class in acquire.acquire.acquire) (class in dissect.target.plugins.os.windows.prefetch) prefetch (in module dissect.target.plugins.os.windows.prefetch) prefetch() (dissect.target.plugins.os.windows.prefetch.PrefetchPlugin method) prefetch_version_structs (in module dissect.target.plugins.os.windows.prefetch) PrefetchPlugin (class in dissect.target.plugins.os.windows.prefetch) PrefetchRecord (in module dissect.target.plugins.os.windows.prefetch) PREFIXES (in module dissect.target.loaders.dir) prepare_client() (acquire.acquire.uploaders.minio.MinIO method) (acquire.acquire.uploaders.plugin.UploaderPlugin method) prepare_insert_sql() (in module flow.record.adapter.sqlite) prepare_ls_colors() (in module dissect.target.tools.shell) prev() (dissect.btrfs.tree.Cursor method) (dissect.esedb.cursor.Cursor method) prev_node() (dissect.btrfs.tree.Cursor method) prev_page() (dissect.esedb.cursor.Cursor method) previous_bitmap (dissect.volume.vss.Store property) previous_timestamps (dissect.target.plugins.os.windows.prefetch.Prefetch property) print_acquire_warning() (in module acquire.acquire.acquire) print_disks_overview() (in module acquire.acquire.acquire) print_extensive_file_stat() (dissect.target.tools.shell.TargetCli method) print_name (dissect.archive.wim.ReparsePoint property) (dissect.ntfs.attr.ReparsePoint property) print_object() (in module dissect.util.tools.dump_nskeyedarchiver) print_target_info() (in module dissect.target.tools.info) print_volumes_overview() (in module acquire.acquire.acquire) PRINTABLE (in module dissect.cstruct.utils) private_key_filter() (in module acquire.acquire.acquire) private_keys() (dissect.target.plugins.apps.ssh.openssh.OpenSSHPlugin method) PrivateKeyRecord (in module dissect.target.plugins.apps.ssh.ssh) Proc (class in acquire.acquire.acquire) PROC_STAT_NAMES (in module dissect.target.plugins.os.unix.linux.proc) PROCESS (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) process() (dissect.target.plugins.os.unix.linux.proc.ProcPlugin method) (dissect.target.target.TargetLogAdapter method) PROCESS_ALL_ACCESS (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) PROCESS_CREATE_PROCESS (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) PROCESS_CREATE_THREAD (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) PROCESS_DUP_HANDLE (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) process_generic_arguments() (in module dissect.target.tools.utils) process_id (dissect.etl.headers.event.EventHeader property) (dissect.etl.headers.headers.EventInstanceGUIDHeader property) (dissect.etl.headers.headers.EventTraceHeader property) (dissect.etl.headers.headers.MessageTraceHeader property) (dissect.etl.headers.system.CompactSystemHeader property) (dissect.etl.headers.system.SystemHeader property) PROCESS_QUERY_INFORMATION (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) PROCESS_SET_INFORMATION (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) PROCESS_SET_QUOTA (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) PROCESS_START_KEY (dissect.etl.headers.event.ExtType attribute) PROCESS_TERMINATE (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) PROCESS_VM_OPERATION (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) PROCESS_VM_READ (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) PROCESS_VM_WRITE (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) ProcessAccess (class in acquire.acquire.dynamic.windows.types) processes() (dissect.target.plugins.os.unix.linux.proc.ProcPlugin method) (dissect.target.plugins.os.unix.linux.processes.ProcProcesses method) ProcessGuid (in module dissect.etl.utils) processor_time (dissect.etl.headers.system.SystemHeader property) ProcessStateEnum (class in dissect.target.plugins.os.unix.linux.proc) ProcessToken (class in acquire.acquire.dynamic.windows.types) ProcPlugin (class in dissect.target.plugins.os.unix.linux.proc) ProcProcess (class in dissect.target.plugins.os.unix.linux.proc) ProcProcesses (class in dissect.target.plugins.os.unix.linux.processes) ProcProcessRecord (in module dissect.target.plugins.os.unix.linux.processes) produce_target_func_pairs() (in module dissect.target.tools.dump.run) profile (dissect.volume.lvm.metadata.LogicalVolume attribute) (dissect.volume.lvm.metadata.VolumeGroup attribute) PROFILE_KEY (dissect.target.plugins.os.windows.regf.nethist.NethistPlugin attribute) ProfileLoader (class in dissect.target.loaders.profile) ProfileOSPlugin (class in dissect.target.loaders.profile) PROFILES (in module acquire.acquire.acquire) ProgramDataBitmaps (class in dissect.target.plugins.os.windows.regf.cit) programs() (dissect.target.plugins.os.windows.amcache.AmcachePluginOldMixin method) ProgramsAppcompatRecord (in module dissect.target.plugins.os.windows.amcache) ProgramUseData (class in dissect.target.plugins.os.windows.regf.cit) progress (acquire.acquire.gui.win32.Win32 property) Progress (class in dissect.evidence.tools.asdf.dd) progress (in module acquire.acquire.tools.decrypter) (in module dissect.hypervisor.tools.vma) progress_bar (acquire.acquire.gui.win32.Win32 attribute) PROGRESS_LOG_STEP (in module acquire.acquire.hashes) prompt (dissect.target.tools.shell.RegistryCli property) (dissect.target.tools.shell.TargetCli property) (dissect.target.tools.shell.TargetHubCli attribute) (dissect.target.tools.shell.UnixConfigTreeCli property) properties (dissect.cim.cim.Class property) (dissect.cim.classes.ClassDefinition property) (dissect.cim.classes.ClassInstance property) properties_length (dissect.cim.cim.Class property) Property (class in dissect.cim.cim) property_default_values (dissect.cim.cim.Class property) PROPERTY_STORE_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) PropertyDefaultValues (class in dissect.cim.classes) PropertyReference (class in dissect.cim.classes) PropertyStates (class in dissect.cim.classes) ProtobufVarint (class in dissect.target.helpers.protobuf) PROTOCOL (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) protocol (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) (flow.record.fieldtypes.uri property) protocol_string (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) protocol_type (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) PROV_TRAITS (dissect.etl.headers.event.ExtType attribute) provider (dissect.target.helpers.keychain.Key attribute) provider_id (dissect.etl.headers.event.EventHeader property) (dissect.etl.headers.headers.Header property) (dissect.etl.headers.headers.MessageTraceHeader property) (dissect.etl.headers.system.SystemSpecificHeader property) (dissect.eventlog.wevt.WEVT property) provider_id() (dissect.etl.etl.Event method) provider_name() (dissect.etl.etl.Event method) ProxyLoader (class in dissect.target.helpers.targetd) PRVA (class in dissect.eventlog.wevt_object) PSM_KEY (dissect.etl.headers.event.ExtType attribute) PT (in module dissect.executable.elf.c_elf) PUA_FIRST (dissect.esedb.lcmapstring.SCRIPT attribute) PUA_LAST (dissect.esedb.lcmapstring.SCRIPT attribute) public_keys() (dissect.target.plugins.apps.ssh.openssh.OpenSSHPlugin method) PUBLIC_OBJECT_TYPE_INFORMATION (class in acquire.acquire.dynamic.windows.types) PublicKeyRecord (in module dissect.target.plugins.apps.ssh.ssh) publisher (flow.record.adapter.broker.BrokerWriter attribute) PUNCTUATION (dissect.esedb.lcmapstring.SCRIPT attribute) PUNICODE_STRING (in module acquire.acquire.dynamic.windows.types) PureDissectPath (class in dissect.target.helpers.compat.path_310) (class in dissect.target.helpers.compat.path_311) (class in dissect.target.helpers.compat.path_312) (class in dissect.target.helpers.compat.path_39) push() (dissect.btrfs.tree.Cursor method) (dissect.target.helpers.configutil.ScopeManager method) push_notification() (dissect.target.plugins.os.windows.sru.SRUPlugin method) PushNotificationRecord (in module dissect.target.plugins.os.windows.sru) PuTTYPlugin (class in dissect.target.plugins.apps.ssh.putty) PuTTYSessionRecord (in module dissect.target.plugins.apps.ssh.putty) PuTTYUserRecordDescriptor (in module dissect.target.plugins.apps.ssh.putty) puu() (dissect.target.plugins.os.windows.regf.cit.CITPlugin method) pv (dissect.volume.lvm.metadata.VolumeGroup property) PvmLoader (class in dissect.target.loaders.pvm) PVOID (in module acquire.acquire.dynamic.windows.types) PVS (class in dissect.hypervisor.descriptor.pvs) PvsLoader (class in dissect.target.loaders.pvs) PY37 (in module dissect.regf.regf) PY_311 (in module flow.record.fieldtypes) PY_312 (in module flow.record.fieldtypes) PY_YAML (in module dissect.target.helpers.configutil) (in module dissect.target.helpers.network_managers) python_shell() (in module dissect.target.tools.shell) PythonLZ4 (class in dissect.squashfs.compression) PythonLZO (class in dissect.squashfs.compression) Q QCow2 (class in dissect.hypervisor.disk.qcow2) qcow2_def (in module dissect.hypervisor.disk.c_qcow2) QCOW2_INCOMPAT_MASK (in module dissect.hypervisor.disk.c_qcow2) QCOW2_MAGIC (in module dissect.hypervisor.disk.c_qcow2) QCOW2_MAGIC_BYTES (in module dissect.hypervisor.disk.c_qcow2) QCow2ClusterType (in module dissect.hypervisor.disk.c_qcow2) QCow2Container (class in dissect.target.containers.qcow2) QCow2Snapshot (class in dissect.hypervisor.disk.qcow2) QCow2SubclusterType (in module dissect.hypervisor.disk.c_qcow2) Qualifier (class in dissect.cim.classes) QualifierReference (class in dissect.cim.classes) qualifiers (dissect.cim.cim.Property property) (dissect.cim.classes.ClassDefinition property) (dissect.cim.classes.ClassInstance property) (dissect.cim.classes.ClassInstanceProperty property) quarantine() (dissect.target.plugins.os.windows.defender.MicrosoftDefenderPlugin method) QUARANTINE_SUCCESS (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) QuarantinedFiles (class in acquire.acquire.acquire) QuarantineEntry (class in dissect.target.plugins.os.windows.defender) QuarantineEntryResource (class in dissect.target.plugins.os.windows.defender) query (flow.record.fieldtypes.uri property) query() (dissect.cim.CIM method) (dissect.cim.cim.CIM method) (dissect.cim.cim.Namespace method) query_directory_object() (in module acquire.acquire.dynamic.windows.ntdll) quit() (acquire.acquire.gui.win32.Win32 method) quitting (acquire.acquire.gui.win32.Win32 attribute) R r (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) R (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) RAID (class in dissect.volume.raid.raid) RAID0 (dissect.volume.raid.stream.Level attribute) raid0_lvs (dissect.volume.lvm.metadata.RAIDSegment attribute) RAID0Stream (class in dissect.volume.raid.stream) RAID1 (dissect.volume.raid.stream.Level attribute) RAID10 (dissect.volume.raid.stream.Level attribute) RAID10Stream (class in dissect.volume.raid.stream) RAID3 (dissect.volume.raid.stream.Level attribute) RAID4 (dissect.volume.raid.stream.Level attribute) RAID456Stream (class in dissect.volume.raid.stream) RAID5 (dissect.volume.raid.stream.Level attribute) RAID6 (dissect.volume.raid.stream.Level attribute) RAIDError raids (dissect.volume.lvm.metadata.RAIDSegment attribute) RAIDSegment (class in dissect.volume.lvm.metadata) range_list (dissect.volume.vss.Store property) RangeList (class in dissect.volume.vss) RangeStream (class in dissect.util.stream) raw (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) RAW (dissect.target.helpers.keychain.KeyType attribute) raw() (dissect.target.plugins.os.unix.linux.proc.Sockets method) (dissect.target.plugins.os.unix.linux.sockets.NetSocketPlugin method) (dissect.vmfs.vmfs.FileDescriptor method) raw6() (dissect.target.plugins.os.unix.linux.proc.Sockets method) raw_page() (dissect.sql.SQLite3 method) (dissect.sql.sqlite3.SQLite3 method) RawContainer (class in dissect.target.containers.raw) (in module dissect.target.container) RawDisk (class in dissect.hypervisor.disk.vmdk) RawLoader (class in dissect.target.loaders.raw) (in module dissect.target.loader) RawType (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.base) rc4_crypt() (in module dissect.target.plugins.os.windows.defender) RE_ACCESS_COMMON_PATTERN (in module dissect.target.plugins.apps.webserver.apache) RE_ANSI_ESCAPE (in module dissect.target.plugins.apps.container.docker) re_cdata (in module dissect.target.plugins.apps.av.mcafee) RE_CITRIX_NETSCALER_BASH_HISTORY_DATE (in module dissect.target.plugins.os.unix.bsd.citrix.history) RE_CONFIG_CUSTOM_LOG_DIRECTIVE (in module dissect.target.plugins.apps.webserver.apache) RE_CONFIG_ERRORLOG_DIRECTIVE (in module dissect.target.plugins.apps.webserver.apache) RE_CONFIG_HOSTNAME (in module dissect.target.plugins.os.unix.bsd.citrix._os) RE_CONFIG_IP (in module dissect.target.plugins.os.unix.bsd.citrix._os) RE_CONFIG_TIMEZONE (in module dissect.target.plugins.os.unix.bsd.citrix._os) RE_CONFIG_USER (in module dissect.target.plugins.os.unix.bsd.citrix._os) RE_DAEMON (in module dissect.target.plugins.os.unix.log.messages) RE_DOCKER_NS (in module dissect.target.plugins.apps.container.docker) RE_ERROR_COMMON_PATTERN (in module dissect.target.plugins.apps.webserver.apache) RE_EXTENDED_BASH (in module dissect.target.plugins.os.unix.history) RE_EXTENDED_ZSH (in module dissect.target.plugins.os.unix.history) re_field (in module dissect.target.plugins.os.windows.log.amcache) re_firewall (in module dissect.target.plugins.os.windows.regf.firewall) RE_FISH (in module dissect.target.plugins.os.unix.history) re_illegal_characters (in module dissect.target.plugins.os.windows.log.evt) (in module dissect.target.plugins.os.windows.log.evtx) RE_LOADER_CONFIG_KERNEL_VERSION (in module dissect.target.plugins.os.unix.bsd.citrix._os) RE_MSG (in module dissect.target.plugins.os.unix.log.messages) re_normalize_path (in module dissect.target.helpers.polypath) RE_NORMALIZE_PATH (in module flow.record.fieldtypes) re_normalize_sbs_path (in module dissect.target.helpers.polypath) RE_PATH_SPLIT (in module dissect.target.plugins.os.windows.services) RE_PATH_SPLIT_FALLBACK (in module dissect.target.plugins.os.windows.services) RE_PID (in module dissect.target.plugins.os.unix.log.messages) re_quoted (in module dissect.target.plugins.filesystem.resolver) RE_REFERER_USER_AGENT_PATTERN (in module dissect.target.plugins.apps.webserver.apache) RE_REMOTE_PATTERN (in module dissect.target.plugins.apps.webserver.apache) RE_RESPONSE_TIME_PATTERN (in module dissect.target.plugins.apps.webserver.apache) re_strip_tags (in module dissect.target.plugins.apps.av.mcafee) RE_TS (in module dissect.target.plugins.os.unix.linux.redhat.yum) (in module dissect.target.plugins.os.unix.log.auth) (in module dissect.target.plugins.os.unix.log.messages) RE_TS_AND_HOSTNAME (in module dissect.target.plugins.os.unix.log.auth) RE_VALID_FIELD_NAME (in module flow.record.base) RE_VALID_RECORD_TYPE_NAME (in module flow.record.base) read() (dissect.cstruct.BaseType method) (dissect.cstruct.BitBuffer method) (dissect.cstruct.bitbuffer.BitBuffer method) (dissect.cstruct.cstruct method) (dissect.cstruct.cstruct.cstruct method) (dissect.cstruct.types.base.BaseType method) (dissect.cstruct.types.BaseType method) (dissect.eventlog.bxml.BxmlNameReader method) (dissect.eventlog.bxml.EvtxNameReader method) (dissect.eventlog.bxml.WevtNameReader method) (dissect.eventlog.evtx.ElfChnk method) (dissect.hypervisor.descriptor.hyperv.HyperVStorageFileObject method) (dissect.target.container.Container method) (dissect.target.containers.asdf.AsdfContainer method) (dissect.target.containers.ewf.EwfContainer method) (dissect.target.containers.hdd.HddContainer method) (dissect.target.containers.hds.HdsContainer method) (dissect.target.containers.qcow2.QCow2Container method) (dissect.target.containers.split.SplitContainer method) (dissect.target.containers.vdi.VdiContainer method) (dissect.target.containers.vhd.VhdContainer method) (dissect.target.containers.vhdx.VhdxContainer method) (dissect.target.containers.vmdk.VmdkContainer method) (dissect.target.helpers.mount.DissectMount method) (dissect.target.loaders.remote.RemoteStreamConnection method) (dissect.target.volume.Volume method) (dissect.util.compression.lzxpress_huffman.BitString method) (dissect.util.stream.AlignedStream method) (flow.record.stream.RecordStreamReader method) read_ahead (dissect.volume.lvm.metadata.LogicalVolume attribute) read_attribute() (dissect.eventlog.bxml.Bxml method) read_bin_file() (dissect.target.plugins.os.windows.recyclebin.RecyclebinPlugin method) read_binxml_fragment() (in module dissect.eventlog.bxml) read_block() (dissect.extfs.JDB2 method) (dissect.extfs.journal.JDB2 method) (dissect.volume.vss.Store method) (in module dissect.volume.vss) read_block_data() (in module dissect.volume.vss) read_cell() (dissect.regf.regf.RegistryHive method) (dissect.regf.RegistryHive method) read_cell_data() (dissect.regf.regf.RegistryHive method) (dissect.regf.RegistryHive method) read_char_reference() (dissect.eventlog.bxml.Bxml method) read_chunk() (dissect.evidence.ewf.TableSection method) read_descriptor_array() (in module dissect.eventlog.bxml) read_descriptors_from_stream() (dissect.eventlog.bxml.BxmlTemplateDescriptor class method) read_entity_reference() (dissect.eventlog.bxml.Bxml method) read_etl_files() (dissect.target.plugins.os.windows.log.etl.EtlPlugin method) read_etl_records() (dissect.target.plugins.os.windows.log.etl.EtlRecordBuilder method) read_file() (dissect.target.helpers.configutil.ConfigurationParser method) read_filename() (dissect.target.plugins.os.windows.prefetch.Prefetch method) read_footer() (in module dissect.hypervisor.disk.vhd) read_fragment_header() (dissect.eventlog.bxml.Bxml method) read_guid() (in module dissect.eventlog.bxml) read_instance_info() (in module dissect.etl.headers.event) read_key_subkeys() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) read_list() (dissect.cim.classes.PropertyReference class method) (dissect.cim.classes.QualifierReference class method) read_name_from_stream() (dissect.eventlog.bxml.Bxml method) read_null_terminated_wstring() (in module dissect.regf.regf) read_page() (dissect.cim.index.Store method) (dissect.esedb.EseDB method) (dissect.esedb.esedb.EseDB method) read_plain_chunk() (in module dissect.target.plugins.general.scrape) read_provider_traits() (in module dissect.etl.headers.event) read_record() (dissect.etl.Buffer method) (dissect.etl.etl.Buffer method) (in module dissect.sql.sqlite3) read_records() (dissect.target.plugins.os.windows.sru.SRUPlugin method) read_recycle_bin() (dissect.target.plugins.os.windows.recyclebin.RecyclebinPlugin method) read_sb() (dissect.ffs.FFS static method) (dissect.ffs.ffs.FFS static method) read_sectors() (dissect.evidence.ewf.Segment method) (dissect.evidence.ewf.TableSection method) (dissect.hypervisor.disk.vhd.Disk method) (dissect.hypervisor.disk.vhd.DynamicDisk method) (dissect.hypervisor.disk.vhd.FixedDisk method) (dissect.hypervisor.disk.vhdx.VHDX method) (dissect.hypervisor.disk.vmdk.RawDisk method) (dissect.hypervisor.disk.vmdk.SparseDisk method) (dissect.hypervisor.disk.vmdk.VMDK method) (dissect.volume.lvm.LVM2Device method) (dissect.volume.lvm.physical.LVM2Device method) read_sid() (in module dissect.eventlog.bxml) (in module dissect.util.sid) read_stack_trace() (in module dissect.etl.headers.event) read_stack_trace64() (in module dissect.etl.headers.event) read_status_blocks() (in module dissect.target.plugins.os.unix.linux.debian.dpkg) read_systemtime() (in module dissect.eventlog.bxml) read_table() (flow.record.adapter.sqlite.SqliteReader method) read_table_records() (dissect.target.plugins.os.windows.ual.UalPlugin method) read_template_instance() (dissect.eventlog.bxml.Bxml method) read_token() (dissect.eventlog.bxml.Bxml method) read_uuid() (in module dissect.etl.headers.event) read_value() (dissect.eventlog.bxml.Bxml method) (in module dissect.eventlog.bxml) readable() (dissect.target.filesystem.VirtualFileHandle method) (dissect.util.stream.AlignedStream method) readall() (dissect.util.stream.AlignedStream method) (dissect.util.stream.ZlibStream method) readdir() (dissect.target.helpers.mount.DissectMount method) readheader() (flow.record.stream.RecordStreamReader method) readinto() (dissect.target.container.Container method) (dissect.target.filesystem.VirtualFileHandle method) (dissect.target.volume.Volume method) (dissect.util.stream.AlignedStream method) (in module dissect.target.helpers.utils) readlink() (dissect.archive.wim.DirectoryEntry method) (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.ffs.FfsFilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemEntry method) (dissect.target.filesystems.jffs.JFFSFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.smb.SmbFilesystemEntry method) (dissect.target.filesystems.squashfs.SquashFSFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystemEntry method) (dissect.target.filesystems.vmfs.VmfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) (dissect.target.filesystems.zip.ZipFilesystemEntry method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) (dissect.target.helpers.mount.DissectMount method) readlink_ext() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystemEntry method) (dissect.target.filesystems.zip.ZipFilesystemEntry method) readoffset() (dissect.util.stream.AlignedStream method) reads() (dissect.cstruct.BaseType method) (dissect.cstruct.types.base.BaseType method) (dissect.cstruct.types.BaseType method) ready (acquire.acquire.gui.base.GUI attribute) realattr (dissect.target.helpers.lazy.LazyAttr property) realpath() (in module dissect.target.helpers.compat.path_common) recalculate (dissect.volume.lvm.metadata.IntegritySegment attribute) recentdocs() (dissect.target.plugins.os.windows.regf.mru.MRUPlugin method) RecentDocsRecord (in module dissect.target.plugins.os.windows.regf.mru) recentfilecache() (dissect.target.plugins.os.windows.regf.recentfilecache.RecentFileCachePlugin method) RecentFileCachePlugin (class in dissect.target.plugins.os.windows.regf.recentfilecache) RecentFileCacheRecord (in module dissect.target.plugins.os.windows.regf.recentfilecache) Recents (class in acquire.acquire.acquire) reconfigure_log_file() (in module acquire.acquire.log) RECONNECT_WAIT (dissect.target.loaders.remote.RemoteStreamConnection attribute) Record (class in acquire.acquire.collector) (class in dissect.esedb.record) (class in flow.record) (class in flow.record.base) record (class in flow.record.fieldtypes) (dissect.target.tools.dump.run.RecordStreamElement attribute) Record (in module dissect.eventlog.evt) RECORD_CLASS_TEMPLATE (in module flow.record.base) record_count (dissect.target.tools.dump.state.DumpState property) (dissect.target.tools.dump.state.Sink attribute) record_descriptor_for_fields() (flow.record.stream.RecordFieldRewriter method) record_length (dissect.ntfs.attr.AttributeHeader property) (dissect.ntfs.AttributeHeader property) RECORD_NAME (dissect.target.plugins.os.windows.log.etl.EtlRecordBuilder attribute) (dissect.target.plugins.os.windows.log.evtx.EvtxPlugin attribute) (in module dissect.target.plugins.os.unix.linux.services) record_output() (in module dissect.target.tools.query) RECORD_PACK_EXT_TYPE (in module flow.record.packer) RECORD_PACK_TYPE_DATETIME (in module flow.record.packer) RECORD_PACK_TYPE_DESCRIPTOR (in module flow.record.packer) RECORD_PACK_TYPE_FIELDTYPE (in module flow.record.packer) RECORD_PACK_TYPE_GROUPEDRECORD (in module flow.record.packer) RECORD_PACK_TYPE_RECORD (in module flow.record.packer) RECORD_PACK_TYPE_VARINT (in module flow.record.packer) record_stream() (in module flow.record.stream) record_stream_for_path() (flow.record.stream.PathTemplateWriter method) record_to_document() (flow.record.adapter.elastic.ElasticWriter method) RECORD_TYPE (in module dissect.volume.vss) RECORD_TYPE_MAP (in module flow.record.adapter.avro) RECORD_TYPES (in module dissect.target.plugins.filesystem.ntfs.mft) RECORD_VERSION (in module flow.record) (in module flow.record.base) RecordAdapter() (in module flow.record) (in module flow.record.base) RecordAdapterNotFound RecordArchiver (class in flow.record.stream) RecordContextMatcher (class in flow.record.selector) RecordData (class in dissect.esedb.record) RecordDescriptor (class in flow.record) (class in flow.record.base) RecordDescriptorError, [1] RecordDescriptorExtensionBase (class in dissect.target.helpers.descriptor_extensions) RecordDescriptorNotFound RecordField (class in flow.record) (class in flow.record.base) RecordFieldRewriter (class in flow.record.stream) RecordFieldSet (class in flow.record.base) RecordOutput() (in module flow.record.stream) RecordPacker (class in flow.record.packer) RecordPrinter (class in flow.record.stream) RecordReader() (in module flow.record) (in module flow.record.base) records() (dissect.clfs.container.Container method) (dissect.esedb.table.Table method) (dissect.ntfs.UsnJrnl method) (dissect.ntfs.usnjrnl.UsnJrnl method) RECORDSTREAM_MAGIC (in module flow.record) (in module flow.record.base) RECORDSTREAM_MAGIC_DEPTH (in module flow.record.base) RecordStreamElement (class in dissect.target.tools.dump.run) RecordStreamReader (class in flow.record.stream) RecordStreamWriter (class in flow.record.stream) recordType (flow.record.base.RecordDescriptor attribute) (flow.record.RecordDescriptor attribute) recordtype (flow.record.stream.RecordStreamReader attribute) RecordValue (in module dissect.esedb.c_esedb) RecordWrapper (class in dissect.esedb.tools.impacket) RecordWriter() (in module flow.record) (in module flow.record.base) recover() (dissect.target.plugins.os.windows.defender.MicrosoftDefenderPlugin method) recover_quarantined_file_streams() (in module dissect.target.plugins.os.windows.defender) RECOVERY_KEY (dissect.target.helpers.keychain.KeyType attribute) recursor() (in module dissect.target.tools.reg) RecycleBin (class in acquire.acquire.acquire) recyclebin() (dissect.target.plugins.os.windows.recyclebin.RecyclebinPlugin method) recyclebin_filter() (in module acquire.acquire.acquire) RecyclebinPlugin (class in dissect.target.plugins.os.windows.recyclebin) RecycleBinRecord (in module dissect.target.plugins.os.windows.recyclebin) RED (dissect.target.helpers.cyber.Color attribute) RedHat (class in dissect.target.plugins.os.unix.linux.redhat._os) ref (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) refcnt (dissect.target.plugins.os.unix.linux.modules.Module attribute) reference() (dissect.cim.index.Key method) ReferenceNotFoundError, [1] references() (dissect.cim.index.Key method) REG_BINARY (in module dissect.regf.c_regf) REG_DWORD (in module dissect.regf.c_regf) REG_DWORD_BIG_ENDIAN (in module dissect.regf.c_regf) REG_EXPAND_SZ (in module dissect.regf.c_regf) REG_FULL_RESOURCE_DESCRIPTOR (in module dissect.regf.c_regf) REG_LINK (in module dissect.regf.c_regf) REG_MULTI_SZ (in module dissect.regf.c_regf) REG_NONE (in module dissect.regf.c_regf) REG_QWORD (in module dissect.regf.c_regf) REG_RESOURCE_LIST (in module dissect.regf.c_regf) REG_RESOURCE_REQUIREMENTS_LIST (in module dissect.regf.c_regf) REG_SZ (in module dissect.regf.c_regf) REGEX_IPV4 (in module flow.record.tools.geoip) REGEX_PACKAGE_NAMES (in module dissect.target.plugins.os.unix.linux.debian.apt) regf() (dissect.target.plugins.os.windows.regf.regf.RegfPlugin method) RegfHive (class in dissect.target.helpers.regutil) RegfKey (class in dissect.target.helpers.regutil) RegFlex (class in dissect.target.helpers.regutil) RegFlexHive (class in dissect.target.helpers.regutil) RegFlexKey (class in dissect.target.helpers.regutil) RegFlexValue (class in dissect.target.helpers.regutil) RegfPlugin (class in dissect.target.plugins.os.windows.regf.regf) RegfValue (class in dissect.target.helpers.regutil) region_size (dissect.volume.lvm.metadata.MirrorSegment attribute) (dissect.volume.lvm.metadata.RAIDSegment attribute) RegionTable (class in dissect.hypervisor.disk.vhdx) register() (acquire.acquire.uploaders.plugin_registry.PluginRegistry method) (dissect.target.helpers.network_managers.NetworkManager method) (flow.record.jsonpacker.JsonRecordPacker method) (flow.record.JsonRecordPacker method) (flow.record.packer.RecordPacker method) (in module dissect.target.container) (in module dissect.target.filesystem) (in module dissect.target.loader) (in module dissect.target.plugin) register_key() (in module dissect.target.helpers.keychain) register_keychain_file() (in module dissect.target.helpers.keychain) register_module() (in module acquire.acquire.acquire) register_wildcard_value() (in module dissect.target.helpers.keychain) registered (dissect.target.helpers.network_managers.NetworkManager property) REGISTERED_PLUGIN (dissect.target.target.Event attribute) registered_plugins (dissect.target.report.TargetExecutionReport attribute) registry (acquire.acquire.collector.CollectionReport attribute) Registry (class in acquire.acquire.acquire) RegistryCli (class in dissect.target.tools.shell) RegistryCorruptError RegistryError RegistryGuid (in module dissect.etl.utils) RegistryHive (class in dissect.regf) (class in dissect.regf.regf) (class in dissect.target.helpers.regutil) RegistryKey (class in dissect.target.helpers.regutil) RegistryKeyNotFoundError, [1], [2] RegistryKeyNotFoundException RegistryKeyRecord (in module dissect.target.plugins.os.windows.regf.regf) RegistryPlugin (class in dissect.target.plugins.os.windows.registry) RegistryRecordDescriptorExtension (class in dissect.target.helpers.descriptor_extensions) RegistryValue (class in dissect.target.helpers.regutil) RegistryValueNotFoundError, [1], [2] RegistryValueRecord (in module dissect.target.plugins.os.windows.regf.regf) REGKEY_GLOBS (dissect.target.plugins.os.windows.regf.appxdebugkeys.AppxDebugKeysPlugin attribute) RELATED_ACTIVITY_ID (dissect.etl.headers.event.ExtType attribute) related_sections() (dissect.executable.elf.elf.SectionTable method) (dissect.executable.elf.SectionTable method) related_segments() (dissect.executable.elf.elf.SegmentTable method) (dissect.executable.elf.SegmentTable method) relative (dissect.archive.wim.ReparsePoint property) (dissect.ntfs.attr.ReparsePoint property) relative_to() (dissect.target.helpers.compat.path_310.PureDissectPath method) (dissect.target.helpers.compat.path_311.PureDissectPath method) (dissect.target.helpers.compat.path_39.PureDissectPath method) RelativeStream (class in dissect.util.stream) release() (dissect.target.helpers.mount.DissectMount method) releasedir() (dissect.target.helpers.mount.DissectMount method) relpath() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) rem_address (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) remainder (dissect.etl.headers.headers.Marker property) REMAINDER_MASK (dissect.etl.headers.headers.Marker attribute) remote_ip (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) remote_port (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) RemoteAccess (class in acquire.acquire.acquire) RemoteAccessPlugin (class in dissect.target.plugins.apps.remoteaccess.remoteaccess) RemoteAccessRecord (in module dissect.target.plugins.apps.remoteaccess.remoteaccess) RemoteLoader (class in dissect.target.loaders.remote) RemoteStream (class in dissect.target.loaders.remote) RemoteStreamConnection (class in dissect.target.loaders.remote) removal_time (dissect.volume.lvm.metadata.HistoricalLogicalVolume attribute) Remove (dissect.target.plugins.os.unix.packagemanager.OperationTypes attribute) remove() (acquire.acquire.uploaders.plugin_registry.PluginRegistry method) remove_handler() (flow.record.utils.EventHandler method) rename() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) render_stacktrace_only_in_debug_or_less() (in module dissect.target.tools.logging) repair_checksum() (in module dissect.util.compression.xz) reparse_point() (dissect.archive.wim.DirectoryEntry method) reparse_point_name() (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) reparse_point_record() (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) reparse_point_substitute_name() (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) ReparsePoint (class in dissect.archive.wim) (class in dissect.ntfs.attr) replace() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) replace_dash_with_none() (in module dissect.target.plugins.apps.webserver.iis) REPLACE_LIST (in module flow.record.adapter.text) REPLACEMENTS (in module dissect.target.plugins.filesystem.resolver) repo() (dissect.target.plugins.os.windows.cim.CimPlugin method) reprsid() (in module dissect.eventlog.evt) reserved (acquire.acquire.dynamic.windows.types.SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX property) RESERVED_FIELDS (in module flow.record.base) RESERVED_IDX (in module dissect.evidence.asdf.asdf) RESERVED_SPLUNK_FIELDS (in module flow.record.adapter.splunk) ReservedFlags (class in dissect.etl.headers.logfile) reset() (acquire.acquire.esxi.EsxiMemoryManager method) (dissect.btrfs.tree.Cursor method) (dissect.cstruct.BitBuffer method) (dissect.cstruct.bitbuffer.BitBuffer method) reset_flags() (dissect.cstruct.parser.TokenConsumer method) ResFile (class in dissect.target.loaders.res) reshape_count (dissect.volume.lvm.metadata.Segment attribute) RESHDR_FLAG (in module dissect.archive.c_wim) resident (dissect.ntfs.attr.Attribute property) (dissect.ntfs.attr.AttributeHeader property) (dissect.ntfs.Attribute property) (dissect.ntfs.AttributeHeader property) (dissect.target.plugins.filesystem.ntfs.mft_timeline.Extras attribute) resident() (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) ResLoader (class in dissect.target.loaders.res) RESOLVE (dissect.target.helpers.record_modifier.Modifier attribute) resolve() (dissect.cstruct.cstruct method) (dissect.cstruct.cstruct.cstruct method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) (dissect.target.plugins.filesystem.resolver.ResolverPlugin method) resolve_address() (dissect.vmfs.resource.ResourceManager method) resolve_attr_path() (in module flow.record.selector) resolve_default() (dissect.target.plugins.filesystem.resolver.ResolverPlugin method) resolve_glob_path() (dissect.target.tools.shell.TargetCli method) (dissect.target.tools.shell.UnixConfigTreeCli method) resolve_id() (dissect.esedb.tools.sru.SRU method) resolve_key() (dissect.target.tools.shell.RegistryCli method) (dissect.target.tools.shell.UnixConfigTreeCli method) resolve_link() (in module dissect.target.helpers.fsutil) resolve_path() (dissect.btrfs.btrfs.Subvolume method) (dissect.btrfs.Subvolume method) (dissect.target.tools.shell.TargetCli method) (dissect.target.tools.shell.UnixConfigTreeCli method) resolve_windows() (dissect.target.plugins.filesystem.resolver.ResolverPlugin method) ResolveError, [1] ResolverPlugin (class in dissect.target.plugins.filesystem.resolver) ResOSPlugin (class in dissect.target.loaders.res) Resource (class in dissect.archive.wim) resource_size (dissect.vmfs.resource.ResourceFile property) RESOURCE_TYPE_MAP (in module dissect.vmfs.resource) ResourceFile (class in dissect.vmfs.resource) ResourceManager (class in dissect.vmfs.resource) resources (dissect.archive.wim.WIM property) ResourceType (in module dissect.vmfs.c_vmfs) restansmit (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) result (acquire.acquire.gui.win32.Win32 attribute) reveal_text (acquire.acquire.gui.win32.Win32 attribute) reverse() (dissect.cim.mappings.Mapping method) reverse_readlines() (in module dissect.target.helpers.fsutil) reverse_search() (in module dissect.target.loaders.res) rewrite() (flow.record.stream.RecordFieldRewriter method) REWRITE_CACHE (in module dissect.target.helpers.cache) RFC4716_MAGIC (in module dissect.target.helpers.ssh) RFC4716_MARKER_END (in module dissect.target.helpers.ssh) RFC4716_MARKER_START (in module dissect.target.helpers.ssh) RFC4716_NONE (in module dissect.target.helpers.ssh) RFC4716_PADDING (in module dissect.target.helpers.ssh) rid_to_key() (in module dissect.target.plugins.os.windows.sam) RIGHT_ASYMMETRIC (dissect.volume.raid.stream.Layout attribute) RIGHT_ASYMMETRIC_6 (dissect.volume.raid.stream.Layout attribute) right_sibling (dissect.ole.ole.DirectoryEntry property) RIGHT_SYMMETRIC (dissect.volume.raid.stream.Layout attribute) RIGHT_SYMMETRIC_6 (dissect.volume.raid.stream.Layout attribute) rmdir() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) rmem (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) role_access() (dissect.target.plugins.os.windows.ual.UalPlugin method) RoleAccessRecord (in module dissect.target.plugins.os.windows.ual) root() (dissect.btrfs.btrfs.Subvolume method) (dissect.btrfs.Subvolume method) (dissect.esedb.index.Index method) (dissect.esedb.table.Table method) (dissect.ntfs.Mft method) (dissect.ntfs.mft.Mft method) (dissect.regf.regf.RegistryHive method) (dissect.regf.RegistryHive method) (dissect.target.helpers.regutil.RegfHive method) (dissect.target.helpers.regutil.RegistryHive method) (dissect.target.plugins.os.windows.registry.RegistryPlugin method) root_cause_str() (dissect.target.exceptions.UnsupportedPluginError method) ROOT_FOLDER (class in dissect.target.plugins.os.windows.regf.shellbags) ROOT_NAMESPACE_NAME (in module dissect.cim.c_cim) RootDirectory (class in dissect.fat.fat) RootFilesystem (class in dissect.target.filesystem) RootFilesystemEntry (class in dissect.target.filesystem) rotate_existing_file() (flow.record.stream.PathTemplateWriter method) ROTATING_N_CONTINUE (dissect.volume.raid.stream.Layout attribute) ROTATING_N_RESTART (dissect.volume.raid.stream.Layout attribute) ROTATING_ZERO_RESTART (dissect.volume.raid.stream.Layout attribute) Row (class in dissect.sql.sqlite3) row() (dissect.sql.sqlite3.Table method) rows() (dissect.sql.sqlite3.Table method) RtlNtStatusToDosError (in module acquire.acquire.dynamic.windows.ntdll) run() (acquire.acquire.acquire.FileHashes class method) (acquire.acquire.acquire.Module class method) (acquire.acquire.acquire.OpenHandles class method) (acquire.acquire.acquire.SSH class method) (dissect.target.plugins.os.windows.regf.mru.MRUPlugin method) run_cli() (in module dissect.target.tools.shell) RunKeyRecord (in module dissect.target.plugins.os.windows.regf.runkeys) runkeys() (dissect.target.plugins.os.windows.regf.runkeys.RunKeysPlugin method) RunKeysPlugin (class in dissect.target.plugins.os.windows.regf.runkeys) runlist (dissect.ntfs.stream.CompressedRunlistStream property) (dissect.util.stream.RunlistStream property) runlist() (dissect.fat.ExFAT method) (dissect.fat.exfat.ExFAT method) (dissect.fat.fat.FAT method) RunlistStream (class in dissect.util.stream) RunMRURecord (in module dissect.target.plugins.os.windows.regf.mru) runtime (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) rx_queue (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) S S (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) sam() (dissect.target.plugins.os.windows.sam.SamPlugin method) SAM_KEY (dissect.target.plugins.os.windows.sam.SamPlugin attribute) SamPlugin (class in dissect.target.plugins.os.windows.sam) SamRecord (in module dissect.target.plugins.os.windows.sam) save_plugin_import_failure() (in module dissect.target.plugin) sb() (dissect.hypervisor.disk.vhdx.BlockAllocationTable method) sbc (dissect.vmfs.resource.ResourceManager property) SBLOCKSEARCH (in module dissect.ffs.ffs) scandir() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry method) (dissect.target.filesystems.cb.CbFilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.exfat.ExfatFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.fat.FatFilesystemEntry method) (dissect.target.filesystems.ffs.FfsFilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemEntry method) (dissect.target.filesystems.jffs.JFFSFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.smb.SmbFilesystemEntry method) (dissect.target.filesystems.squashfs.SquashFSFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystemEntry method) (dissect.target.filesystems.vmfs.VmfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) (dissect.target.tools.shell.RegistryCli method) (dissect.target.tools.shell.TargetCli method) (in module dissect.target.helpers.compat.path_common) SchedLgU (class in dissect.target.plugins.os.windows.log.schedlgu) schedlgu() (dissect.target.plugins.os.windows.log.schedlgu.SchedLgUPlugin method) SCHEDLGU_REGEX_PATTERN (in module dissect.target.plugins.os.windows.log.schedlgu) SchedLgUPlugin (class in dissect.target.plugins.os.windows.log.schedlgu) SchedLgURecord (in module dissect.target.plugins.os.windows.log.schedlgu) ScheduledTasks (class in dissect.target.plugins.os.windows.task_helpers.tasks_xml) schema_to_descriptor() (in module flow.record.adapter.avro) scheme (flow.record.fieldtypes.uri property) ScopeManager (class in dissect.target.helpers.configutil) scrape_blocks() (in module dissect.evidence.asdf.asdf) scrape_chunks() (dissect.target.plugins.general.scrape.ScrapePlugin method) scrape_chunks_from_disks() (dissect.target.plugins.general.scrape.ScrapePlugin method) scrape_needles_from_disks() (dissect.target.plugins.general.scrape.ScrapePlugin method) scrape_pos() (in module dissect.target.loaders.phobos) scraped_evt() (dissect.target.plugins.os.windows.log.evt.EvtPlugin method) scraped_evtx() (dissect.target.plugins.os.windows.log.evtx.EvtxPlugin method) ScrapePlugin (class in dissect.target.plugins.general.scrape) SCRIPT (class in dissect.esedb.lcmapstring) SCSI (dissect.target.plugins.os.windows.regf.usb.UsbPlugin attribute) sdp_cpu_provider() (dissect.target.plugins.os.windows.sru.SRUPlugin method) sdp_network_provider() (dissect.target.plugins.os.windows.sru.SRUPlugin method) sdp_physical_disk_provider() (dissect.target.plugins.os.windows.sru.SRUPlugin method) sdp_volume_provider() (dissect.target.plugins.os.windows.sru.SRUPlugin method) SdpCpuProviderRecord (in module dissect.target.plugins.os.windows.sru) SdpNetworkProviderRecord (in module dissect.target.plugins.os.windows.sru) SdpPhysicalDiskProviderRecord (in module dissect.target.plugins.os.windows.sru) SdpVolumeProviderRecord (in module dissect.target.plugins.os.windows.sru) search() (dissect.btrfs.tree.Cursor method) (dissect.esedb.cursor.Cursor method) (dissect.esedb.index.Index method) (dissect.ntfs.Index method) (dissect.ntfs.index.Index method) search_key() (dissect.esedb.index.Index method) secrets() (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin method) SECTION (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) Section (class in dissect.executable.elf) (class in dissect.executable.elf.elf) SectionDescriptor (class in dissect.evidence.ewf) SectionTable (class in dissect.executable.elf) (class in dissect.executable.elf.elf) SECTOR_SHIFT (in module dissect.ntfs.c_ntfs) SECTOR_SIZE (in module dissect.clfs.c_clfs) (in module dissect.hypervisor.disk.c_hdd) (in module dissect.hypervisor.disk.c_vhd) (in module dissect.hypervisor.disk.c_vmdk) (in module dissect.ntfs.c_ntfs) (in module dissect.volume.dm.c_dm) (in module dissect.volume.lvm.c_lvm2) (in module dissect.volume.md.c_md) sector_to_cluster() (dissect.fat.ExFAT method) (dissect.fat.exfat.ExFAT method) sectors_per_bit (dissect.volume.lvm.metadata.IntegritySegment attribute) Secure (class in dissect.ntfs) (class in dissect.ntfs.secure) securelog() (dissect.target.plugins.os.unix.log.auth.AuthPlugin method) security_id (dissect.ntfs.attr.StandardInformation property) SECURITY_POLICY_KEY (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin attribute) SecurityBlock (class in dissect.archive.wim) SecurityDescriptor (class in dissect.ntfs) (class in dissect.ntfs.secure) seek() (acquire.acquire.crypt.EncryptedStream method) (acquire.acquire.tools.decrypter.EncryptedFile method) (acquire.acquire.volatilestream.VolatileStream method) (dissect.evidence.asdf.streams.SubStreamBase method) (dissect.target.container.Container method) (dissect.target.containers.asdf.AsdfContainer method) (dissect.target.containers.ewf.EwfContainer method) (dissect.target.containers.hdd.HddContainer method) (dissect.target.containers.hds.HdsContainer method) (dissect.target.containers.qcow2.QCow2Container method) (dissect.target.containers.split.SplitContainer method) (dissect.target.containers.vdi.VdiContainer method) (dissect.target.containers.vhd.VhdContainer method) (dissect.target.containers.vhdx.VhdxContainer method) (dissect.target.containers.vmdk.VmdkContainer method) (dissect.target.filesystem.VirtualFileHandle method) (dissect.target.volume.Volume method) (dissect.util.stream.AlignedStream method) seek_and_return() (in module dissect.thumbcache.util) seekable() (acquire.acquire.tools.decrypter.EncryptedFile method) (acquire.acquire.volatilestream.VolatileStream method) (dissect.target.container.Container method) (dissect.target.filesystem.VirtualFileHandle method) (dissect.target.volume.Volume method) (dissect.util.stream.AlignedStream method) seen_paths (acquire.acquire.collector.CollectionReport attribute) Segment (class in dissect.evidence.ewf) (class in dissect.executable.elf) (class in dissect.executable.elf.elf) (class in dissect.volume.lvm.metadata) segment_count (dissect.volume.lvm.metadata.LogicalVolume attribute) segment_reference() (in module dissect.ntfs.c_ntfs) segments (dissect.volume.lvm.metadata.LogicalVolume property) segments() (dissect.ntfs.Mft method) (dissect.ntfs.mft.Mft method) SegmentTable (class in dissect.executable.elf) (class in dissect.executable.elf.elf) select_event_header() (in module dissect.etl.headers.utils) select_header() (dissect.target.plugins.os.windows.recyclebin.RecyclebinPlugin method) Selector (class in flow.record.selector) SelectorResult (class in flow.record.selector) SEMAPHORE (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) send_event() (dissect.target.Target method) (dissect.target.target.Target method) SendEmailRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) SendMessage (in module acquire.acquire.gui.win32) separator (dissect.target.helpers.configutil.ParserConfig attribute) (dissect.target.helpers.configutil.ParserOptions attribute) SEPFirewallRecord (in module dissect.target.plugins.apps.av.symantec) SEPLogRecord (in module dissect.target.plugins.apps.av.symantec) seqno (dissect.volume.lvm.metadata.VolumeGroup attribute) SEQPACKET (dissect.target.plugins.os.unix.linux.proc.Sockets.SocketStreamType attribute) SEQUENCE (dissect.etl.headers.headers.EventProperty attribute) sequence_number (dissect.etl.headers.headers.MessageTraceHeader property) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTable property) serial (dissect.target.plugins.filesystem.ntfs.mft_timeline.Extras attribute) (dissect.volume.disk.Disk property) (dissect.volume.disk.disk.Disk property) serial() (dissect.ntfs.NTFS method) (dissect.ntfs.ntfs.NTFS method) SERIAL_TYPES (in module dissect.sql.c_sqlite3) serialise_record_column_values() (in module dissect.esedb.record) Serialization (class in dissect.target.tools.dump.utils) serialization (dissect.target.tools.dump.state.DumpState attribute) serialize() (dissect.target.tools.dump.state.DumpState method) serialize_handles_into_csv() (in module acquire.acquire.dynamic.windows.handles) serialize_into_csv() (in module acquire.acquire.hashes) serialize_obj() (in module dissect.target.tools.dump.state) serialize_path() (in module acquire.acquire.collector) SERIALIZERS (in module dissect.target.tools.dump.utils) SERVICE_ENUMS (in module dissect.target.plugins.os.windows.services) SERVICE_GLOBS (dissect.target.plugins.apps.remoteaccess.anydesk.AnydeskPlugin attribute) ServiceRecord (in module dissect.target.plugins.os.windows.services) services() (dissect.target.plugins.os.unix.linux.services.ServicesPlugin method) (dissect.target.plugins.os.windows.services.ServicesPlugin method) ServicesPlugin (class in dissect.target.plugins.os.unix.linux.services) (class in dissect.target.plugins.os.windows.services) SESPARSE_MAGIC (in module dissect.hypervisor.disk.c_vmdk) SESSION (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) sessionmanager() (dissect.target.plugins.os.windows.generic.GenericPlugin method) SessionManagerRecord (in module dissect.target.plugins.os.windows.generic) sessions() (dissect.target.plugins.apps.ssh.putty.PuTTYPlugin method) SessionStateChangeTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) set() (dissect.eventlog.bxml.BxmlSub method) (dissect.target.plugins.os.unix.linux.fortios._os.ConfigNode method) set_cli_args() (dissect.target.report.ExecutionReport method) set_event_callback() (dissect.target.Target class method) (dissect.target.target.Target class method) set_event_callbacks() (dissect.target.report.ExecutionReport method) set_filename() (acquire.acquire.log.DelayedFileHandler method) set_name() (dissect.target.helpers.network_managers.Template method) set_name_reader() (dissect.eventlog.bxml.Bxml method) set_plugin_stats() (dissect.target.report.ExecutionReport method) set_stream() (acquire.acquire.log.DelayedFileHandler method) SetLastError (in module acquire.acquire.dynamic.windows.handles) setup() (acquire.acquire.esxi.EsxiMemoryManager method) setup_logging() (in module acquire.acquire.log) (in module acquire.acquire.tools.decrypter) (in module dissect.hypervisor.tools.vma) sevenzip() (dissect.target.plugins.os.windows.regf.7zip.SevenZipPlugin method) SevenZipPlugin (class in dissect.target.plugins.os.windows.regf.7zip) SEVERITY (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) SHA1 (acquire.acquire.hashes.HashFunc attribute) sha1 (flow.record.fieldtypes.digest property) sha1() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (in module dissect.target.helpers.hashutil) SHA1_NEEDLE (in module dissect.target.plugins.os.windows.catroot) SHA256 (acquire.acquire.hashes.HashFunc attribute) sha256 (flow.record.fieldtypes.digest property) sha256() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (in module dissect.target.helpers.hashutil) SHA_GENERIC_NEEDLE (in module dissect.target.plugins.os.windows.catroot) ShadowPlugin (class in dissect.target.plugins.os.unix.shadow) shard (acquire.acquire.gui.base.GUI property) shell32 (in module acquire.acquire.gui.win32) ShellBagRecord (in module dissect.target.plugins.os.windows.regf.shellbags) shellbags() (dissect.target.plugins.os.windows.regf.shellbags.ShellBagsPlugin method) ShellBagsPlugin (class in dissect.target.plugins.os.windows.regf.shellbags) SHIM_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) ShimCache (class in dissect.target.plugins.os.windows.regf.shimcache) shimcache() (dissect.target.plugins.os.windows.regf.shimcache.ShimcachePlugin method) SHIMCACHE_WIN_TYPE (class in dissect.target.plugins.os.windows.regf.shimcache) ShimCacheGeneratorType (in module dissect.target.plugins.os.windows.regf.shimcache) ShimcachePlugin (class in dissect.target.plugins.os.windows.regf.shimcache) ShimcacheRecord (in module dissect.target.plugins.os.windows.regf.shimcache) SHITEM (class in dissect.target.plugins.os.windows.regf.shellbags) SHITEMID (class in acquire.acquire.gui.win32) SHN (in module dissect.executable.elf.c_elf) ShortcutAppcompatRecord (in module dissect.target.plugins.os.windows.amcache) shortcuts() (dissect.target.plugins.os.windows.amcache.AmcachePlugin method) SHORTNAMES (dissect.target.plugins.os.windows.registry.RegistryPlugin attribute) Shot (class in dissect.hypervisor.disk.hdd) shots (dissect.hypervisor.disk.hdd.Snapshots attribute) should_ignore_file() (in module dissect.target.plugins.os.unix.linux.services) should_ignore_ip() (in module dissect.target.helpers.network_managers) show() (acquire.acquire.gui.base.GUI method) (acquire.acquire.gui.win32.Win32 method) (dissect.cstruct.Structure method) (dissect.cstruct.types.Structure method) (dissect.cstruct.types.structure.Structure method) (dissect.cstruct.types.structure.Union method) (dissect.cstruct.types.Union method) (dissect.cstruct.Union method) show_duplicates() (in module acquire.acquire.tools.decrypter) ShowMessageRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) SHT (in module dissect.executable.elf.c_elf) shutdown() (dissect.target.plugins.os.windows.log.etl.EtlPlugin method) SID (dissect.etl.headers.event.ExtType attribute) (dissect.eventlog.bxml.BxmlType attribute) signature (dissect.target.plugins.os.windows.regf.shellbags.EXTENSION_BLOCK property) SIGNATURE (in module dissect.ole.c_ole) SIGNATURE_BETA (in module dissect.ole.c_ole) SIGNATURE_MASK (in module dissect.util.compression.lznt1) Sink (class in dissect.target.tools.dump.state) sink_path (dissect.target.tools.dump.run.RecordStreamElement attribute) sink_records() (in module dissect.target.tools.dump.run) sinks (dissect.target.tools.dump.state.DumpState attribute) size (dissect.etl.Buffer property) (dissect.etl.etl.Buffer property) (dissect.etl.etl.EventRecord property) (dissect.etl.headers.headers.Header property) (dissect.etl.headers.system.SystemSpecificHeader property) (dissect.eventlog.bxml.BxmlTemplateDescriptor property) (dissect.eventlog.wevt.WEVT property) (dissect.eventlog.wevt.WEVT_TYPE property) (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) (dissect.fat.fat.DirectoryEntry property) (dissect.fat.fat.RootDirectory property) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) (dissect.ntfs.attr.AttributeHeader property) (dissect.ntfs.AttributeHeader property) (dissect.squashfs.INode property) (dissect.squashfs.squashfs.INode property) (dissect.target.loaders.itunes.FileInfo property) (dissect.target.plugins.filesystem.ntfs.mft_timeline.Extras attribute) (dissect.target.plugins.os.unix.linux.modules.Module attribute) (dissect.target.plugins.os.windows.regf.shellbags.EXTENSION_BLOCK property) (dissect.vmfs.vmfs.FileDescriptor property) (dissect.xfs.xfs.INode property) size() (dissect.archive.wim.DirectoryEntry method) (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.esedb.table.Column method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) (dissect.ntfs.mft.MftRecord method) (dissect.ntfs.MftRecord method) (dissect.ntfs.util.AttributeCollection method) size_bytes (dissect.target.tools.dump.state.Sink attribute) SIZE_MASK (in module dissect.util.compression.lznt1) size_threshold (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) size_to_clusters() (in module dissect.hypervisor.disk.qcow2) size_to_subclusters() (in module dissect.hypervisor.disk.qcow2) SIZET (dissect.eventlog.bxml.BxmlType attribute) sk (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) skip() (dissect.util.compression.lzxpress_huffman.BitString method) SKIP_TABLES (in module dissect.esedb.tools.sru) (in module dissect.esedb.tools.ual) sl (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) slab_size_mb (dissect.volume.lvm.metadata.VdoPoolSegment attribute) SLUG_RE (in module dissect.target.helpers.utils) slugify() (in module dissect.target.helpers.utils) slugify_descriptor_name() (in module dissect.target.tools.dump.utils) SmallFileBlockResource (class in dissect.vmfs.resource) SmbFilesystem (class in dissect.target.filesystems.smb) SmbFilesystemEntry (class in dissect.target.filesystems.smb) SmbLoader (class in dissect.target.loaders.smb) SmbRegistry (class in dissect.target.loaders.smb) SmbRegistryHive (class in dissect.target.loaders.smb) SmbRegistryKey (class in dissect.target.loaders.smb) SmbRegistryValue (class in dissect.target.loaders.smb) SmbStream (class in dissect.target.filesystems.smb) Snapshots (class in dissect.hypervisor.disk.hdd) snapshots() (dissect.hypervisor.disk.qcow2.QCow2 method) SnapshotSegment (class in dissect.volume.lvm.metadata) SnapshotTableEntry (in module dissect.evidence.asdf.asdf) sock (flow.record.adapter.splunk.SplunkWriter attribute) SOCKET_TIMEOUT (dissect.target.loaders.remote.RemoteStreamConnection attribute) Sockets (class in dissect.target.plugins.os.unix.linux.proc) Sockets.PacketProtocolTypes (class in dissect.target.plugins.os.unix.linux.proc) Sockets.SocketStateType (class in dissect.target.plugins.os.unix.linux.proc) Sockets.SocketStreamType (class in dissect.target.plugins.os.unix.linux.proc) Sockets.TCPStates (class in dissect.target.plugins.os.unix.linux.proc) Sockets.UDPStates (class in dissect.target.plugins.os.unix.linux.proc) SOLARIS_DEV_DIR (in module dissect.target.loaders.local) SOLARIS_DRIVE_REGEX (in module dissect.target.loaders.local) some_other_way_of_using_a_variable_comment (in module codestyle) some_random_variable (in module codestyle) sophoshomelogs() (dissect.target.plugins.apps.av.sophos.SophosPlugin method) SophosLogRecord (in module dissect.target.plugins.apps.av.sophos) SophosPlugin (class in dissect.target.plugins.apps.av.sophos) SORT_DIGITSASNUMBERS (dissect.esedb.lcmapstring.MapFlags attribute) sort_files() (in module acquire.acquire.acquire) SORT_STRINGSORT (dissect.esedb.lcmapstring.MapFlags attribute) SortedKeysJsonRecordPacker (class in dissect.target.tools.dump.utils) SPACE (dissect.sql.sqlite3.Column attribute) SPARSE (in module dissect.hypervisor.disk.c_vdi) SPARSE_BYTES (in module dissect.evidence.asdf.asdf) SparseDisk (class in dissect.hypervisor.disk.vmdk) SparseExtentHeader (class in dissect.hypervisor.disk.vmdk) SPEC (acquire.acquire.acquire.ActiveDirectory attribute) (acquire.acquire.acquire.ActivitiesCache attribute) (acquire.acquire.acquire.Appcompat attribute) (acquire.acquire.acquire.AV attribute) (acquire.acquire.acquire.BITS attribute) (acquire.acquire.acquire.Boot attribute) (acquire.acquire.acquire.BSD attribute) (acquire.acquire.acquire.DNS attribute) (acquire.acquire.acquire.Drivers attribute) (acquire.acquire.acquire.ESXi attribute) (acquire.acquire.acquire.Etc attribute) (acquire.acquire.acquire.ETL attribute) (acquire.acquire.acquire.History attribute) (acquire.acquire.acquire.Home attribute) (acquire.acquire.acquire.Misc attribute) (acquire.acquire.acquire.Module attribute) (acquire.acquire.acquire.Netstat attribute) (acquire.acquire.acquire.NTDS attribute) (acquire.acquire.acquire.OSX attribute) (acquire.acquire.acquire.OSXApplicationsInfo attribute) (acquire.acquire.acquire.PCA attribute) (acquire.acquire.acquire.PowerShell attribute) (acquire.acquire.acquire.Prefetch attribute) (acquire.acquire.acquire.QuarantinedFiles attribute) (acquire.acquire.acquire.Recents attribute) (acquire.acquire.acquire.Registry attribute) (acquire.acquire.acquire.RemoteAccess attribute) (acquire.acquire.acquire.SSH attribute) (acquire.acquire.acquire.Startup attribute) (acquire.acquire.acquire.Syscache attribute) (acquire.acquire.acquire.Tasks attribute) (acquire.acquire.acquire.ThumbnailCache attribute) (acquire.acquire.acquire.Var attribute) (acquire.acquire.acquire.WBEM attribute) (acquire.acquire.acquire.WebHosting attribute) (acquire.acquire.acquire.WinDnsClientCache attribute) (acquire.acquire.acquire.WindowsNotifications attribute) (acquire.acquire.acquire.WinMemFiles attribute) (acquire.acquire.acquire.WinProcEnv attribute) (acquire.acquire.acquire.WinProcesses attribute) SPECIAL_FOLDER_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) split() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) split_column_def() (in module dissect.sql.utils) split_into_records() (in module dissect.target.plugins.os.unix.linux.debian.apt) split_package_names() (in module dissect.target.plugins.os.unix.linux.debian.apt) split_sql_list() (in module dissect.sql.utils) SplitContainer (class in dissect.target.containers.split) splitdrive (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) splitext (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) SplitIoGuid (in module dissect.etl.utils) splitroot() (in module dissect.target.helpers.fsutil) (in module dissect.target.helpers.polypath) SplitWriter (class in flow.record.adapter.split) splunkify() (in module flow.record.adapter.splunk) SplunkReader (class in flow.record.adapter.splunk) SplunkWriter (class in flow.record.adapter.splunk) SQLite3 (class in dissect.sql) (class in dissect.sql.sqlite3) sqlite3_def (in module dissect.sql.c_sqlite3) SQLITE3_HEADER_MAGIC (in module dissect.sql.c_sqlite3) SQLITE_FIELD_MAP (in module flow.record.adapter.sqlite) SqliteReader (class in flow.record.adapter.sqlite) SqliteWriter (class in flow.record.adapter.sqlite) SquashFS (class in dissect.squashfs) (class in dissect.squashfs.squashfs) squashfs_def (in module dissect.squashfs.c_squashfs) SquashFSFilesystem (class in dissect.target.filesystems.squashfs) SquashFSFilesystemEntry (class in dissect.target.filesystems.squashfs) SRU (class in dissect.esedb.tools.sru) SRUPlugin (class in dissect.target.plugins.os.windows.sru) SRURecord (in module dissect.target.plugins.os.windows.sru) SS_LEFT (in module acquire.acquire.gui.win32) SSH (class in acquire.acquire.acquire) ssh_directory_globs() (dissect.target.plugins.apps.ssh.openssh.OpenSSHPlugin method) SSHD_BOOLEAN_FIELDS (in module dissect.target.plugins.apps.ssh.opensshd) SSHD_BOOLEAN_VALUES (in module dissect.target.plugins.apps.ssh.opensshd) SSHD_DIRECTORIES (dissect.target.plugins.apps.ssh.openssh.OpenSSHPlugin attribute) SSHD_INTEGER_FIELDS (in module dissect.target.plugins.apps.ssh.opensshd) SSHD_MULTIPLE_DEFINITIONS_ALLOWED_FIELDS (in module dissect.target.plugins.apps.ssh.opensshd) SSHPlugin (class in dissect.target.plugins.apps.ssh.ssh) SSHPrivateKey (class in dissect.target.helpers.ssh) SSHServerPlugin (class in dissect.target.plugins.apps.ssh.opensshd) STACK_TRACE32 (dissect.etl.headers.event.ExtType attribute) STACK_TRACE64 (dissect.etl.headers.event.ExtType attribute) StackWalkGuid (in module dissect.etl.utils) standard_header_fields() (dissect.etl.headers.headers.Header method) STANDARD_INFORMATION (dissect.target.plugins.filesystem.ntfs.utils.InformationType attribute) STANDARD_RIGHTS_ALL (in module acquire.acquire.dynamic.windows.ntdll) StandardInformation (class in dissect.ntfs.attr) start (dissect.hypervisor.disk.hdd.Storage attribute) start_button (acquire.acquire.gui.win32.Win32 attribute) start_extent (dissect.volume.lvm.metadata.Segment attribute) START_PATTERN (in module dissect.target.plugins.apps.remoteaccess.teamviewer) start_time (dissect.etl.headers.logfile.LogfileHeader property) (dissect.target.tools.dump.state.DumpState attribute) starttime (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) Startup (class in acquire.acquire.acquire) startupinfo() (dissect.target.plugins.os.windows.startupinfo.StartupInfoPlugin method) StartupInfoPlugin (class in dissect.target.plugins.os.windows.startupinfo) StartupInfoRecord (in module dissect.target.plugins.os.windows.startupinfo) stat() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.filesystem.MappedFile method) (dissect.target.filesystem.RootFilesystemEntry method) (dissect.target.filesystem.VirtualDirectory method) (dissect.target.filesystem.VirtualFile method) (dissect.target.filesystem.VirtualSymlink method) (dissect.target.filesystems.ad1.AD1FilesystemEntry method) (dissect.target.filesystems.btrfs.BtrfsFilesystemEntry method) (dissect.target.filesystems.cb.CbFilesystemEntry method) (dissect.target.filesystems.config.ConfigurationEntry method) (dissect.target.filesystems.dir.DirectoryFilesystemEntry method) (dissect.target.filesystems.exfat.ExfatFilesystemEntry method) (dissect.target.filesystems.extfs.ExtFilesystemEntry method) (dissect.target.filesystems.fat.FatFilesystemEntry method) (dissect.target.filesystems.ffs.FfsFilesystemEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemDirectoryEntry method) (dissect.target.filesystems.itunes.ITunesFilesystemEntry method) (dissect.target.filesystems.jffs.JFFSFilesystemEntry method) (dissect.target.filesystems.ntfs.NtfsFilesystemEntry method) (dissect.target.filesystems.smb.SmbFilesystemEntry method) (dissect.target.filesystems.squashfs.SquashFSFilesystemEntry method) (dissect.target.filesystems.tar.TarFilesystemDirectoryEntry method) (dissect.target.filesystems.tar.TarFilesystemEntry method) (dissect.target.filesystems.vmfs.VmfsFilesystemEntry method) (dissect.target.filesystems.xfs.XfsFilesystemEntry method) (dissect.target.filesystems.zip.ZipFilesystemDirectoryEntry method) (dissect.target.filesystems.zip.ZipFilesystemEntry method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) (dissect.target.loaders.res.ResFile method) (dissect.target.plugins.os.unix.linux.proc.ProcProcess method) stat_modestr() (in module dissect.evidence.tools.asdf.meta) (in module dissect.target.tools.shell) stat_result (class in dissect.target.helpers.fsutil) STAT_TEMPLATE (in module dissect.target.tools.shell) state (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) STATE_FILE_NAME (in module dissect.target.tools.dump.state) state_string (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) status (dissect.target.plugins.os.windows.log.schedlgu.SchedLgU attribute) (dissect.volume.lvm.metadata.LogicalVolume attribute) (dissect.volume.lvm.metadata.PhysicalVolume attribute) (dissect.volume.lvm.metadata.VolumeGroup attribute) status() (dissect.target.plugins.os.unix.linux.debian.dpkg.DpkgPlugin method) (in module dissect.evidence.tools.asdf.verify) STATUS_ACCESS_DENIED (acquire.acquire.dynamic.windows.ntdll.NtStatusCode attribute) STATUS_BUFFER_OVERFLOW (acquire.acquire.dynamic.windows.ntdll.NtStatusCode attribute) STATUS_EXIT (in module acquire.acquire.tools.decrypter) STATUS_FIELD_MAPPINGS (in module dissect.target.plugins.os.unix.linux.debian.dpkg) STATUS_FIELDS_TO_EXTRACT (in module dissect.target.plugins.os.unix.linux.debian.dpkg) STATUS_FILE_NAME (in module dissect.target.plugins.os.unix.linux.debian.dpkg) STATUS_FLAG_ALLOCATABLE (in module dissect.volume.lvm.c_lvm2) STATUS_FLAG_READ (in module dissect.volume.lvm.c_lvm2) STATUS_FLAG_RESIZEABLE (in module dissect.volume.lvm.c_lvm2) STATUS_FLAG_VISIBLE (in module dissect.volume.lvm.c_lvm2) STATUS_FLAG_WRITE (in module dissect.volume.lvm.c_lvm2) STATUS_INFO (in module acquire.acquire.tools.decrypter) STATUS_INFO_LENGTH_MISMATCH (acquire.acquire.dynamic.windows.ntdll.NtStatusCode attribute) STATUS_INVALID_HANDLE (acquire.acquire.dynamic.windows.ntdll.NtStatusCode attribute) STATUS_MORE_ENTRIES (acquire.acquire.dynamic.windows.ntdll.NtStatusCode attribute) STATUS_NO_MORE_ENTRIES (acquire.acquire.dynamic.windows.ntdll.NtStatusCode attribute) STATUS_START (in module acquire.acquire.tools.decrypter) STATUS_SUCCESS (acquire.acquire.dynamic.windows.ntdll.NtStatusCode attribute) STATUS_UPDATE (in module acquire.acquire.tools.decrypter) STB (in module dissect.executable.elf.c_elf) STGTY (in module dissect.ole.c_ole) STILL_INFECTED (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) Storage (class in dissect.hypervisor.disk.hdd) StorageData (class in dissect.hypervisor.disk.hdd) storages (dissect.hypervisor.disk.hdd.StorageData attribute) StorageStream (class in dissect.hypervisor.disk.hdd) Store (class in dissect.cim.index) (class in dissect.cim.objects) (class in dissect.volume.vss) STORE_BLOCK_SIZE (in module dissect.volume.vss) STORE_BLOCKLIST_ENTRY_SIZE (in module dissect.volume.vss) STORE_RANGELIST_ENTRY_SIZE (in module dissect.volume.vss) store_volume_identifier (dissect.volume.vss.VSS property) StoreBitmap (class in dissect.volume.vss) StoreStream (class in dissect.volume.vss) STREAM (dissect.target.plugins.os.unix.linux.proc.Sockets.SocketStreamType attribute) stream (flow.record.adapter.stream.StreamReader attribute) (flow.record.adapter.stream.StreamWriter attribute) Stream (in module dissect.clfs.blf) stream() (in module flow.record) (in module flow.record.base) STREAM_ATTRIBUTES (in module dissect.target.plugins.os.windows.defender) STREAM_BUFFER_SIZE (in module dissect.util.stream) STREAM_ENTRY (in module dissect.fat.c_exfat) STREAM_FORMATTER (in module acquire.acquire.log) STREAM_ID (in module dissect.target.plugins.os.windows.defender) stream_type_string (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) streaming_bulk_thread() (flow.record.adapter.elastic.ElasticWriter method) StreamReader (class in flow.record.adapter.stream) streams() (dissect.evidence.asdf.asdf.AsdfSnapshot method) (dissect.evidence.asdf.AsdfSnapshot method) (dissect.evidence.AsdfSnapshot method) StreamWriter (class in flow.record.adapter.stream) StrEnum (class in acquire.acquire.utils) (class in dissect.target.helpers.utils) string (class in flow.record.fieldtypes) STRING (dissect.eventlog.bxml.BxmlType attribute) (dissect.sql.sqlite3.Column attribute) string() (dissect.cim.index.IndexPage method) string_type (in module flow.record.fieldtypes) string_types (in module flow.record.selector) stringlist (class in flow.record.fieldtypes) StringTable (class in dissect.executable.elf) (class in dissect.executable.elf.elf) strip_log() (in module dissect.target.plugins.apps.container.docker) strip_namespace() (dissect.target.plugins.os.windows.task_helpers.tasks_xml.ScheduledTasks method) (dissect.target.plugins.os.windows.task_helpers.tasks_xml.XmlTask method) STRIP_RE (in module dissect.target.helpers.utils) Stripe (class in dissect.btrfs.stream) stripe_count (dissect.volume.lvm.metadata.RAIDSegment attribute) (dissect.volume.lvm.metadata.StripedSegment attribute) stripe_length (dissect.btrfs.stream.Chunk attribute) stripe_size (dissect.volume.lvm.metadata.RAIDSegment attribute) (dissect.volume.lvm.metadata.StripedSegment attribute) StripedSegment (class in dissect.volume.lvm.metadata) stripes (dissect.btrfs.stream.Chunk attribute) (dissect.volume.lvm.metadata.StripedSegment attribute) STRUCT (dissect.target.plugins.os.windows.regf.shellbags.CDBURN attribute) (dissect.target.plugins.os.windows.regf.shellbags.COMPRESSED_FOLDER attribute) (dissect.target.plugins.os.windows.regf.shellbags.CONTROL_PANEL attribute) (dissect.target.plugins.os.windows.regf.shellbags.CONTROL_PANEL_CATEGORY attribute) (dissect.target.plugins.os.windows.regf.shellbags.CONTROL_PANEL_CPL_FILE attribute) (dissect.target.plugins.os.windows.regf.shellbags.DELEGATE attribute) (dissect.target.plugins.os.windows.regf.shellbags.FILE_ENTRY attribute) (dissect.target.plugins.os.windows.regf.shellbags.GAME_FOLDER attribute) (dissect.target.plugins.os.windows.regf.shellbags.MTP_FILE_ENTRY attribute) (dissect.target.plugins.os.windows.regf.shellbags.MTP_VOLUME attribute) (dissect.target.plugins.os.windows.regf.shellbags.NETWORK attribute) (dissect.target.plugins.os.windows.regf.shellbags.ROOT_FOLDER attribute) (dissect.target.plugins.os.windows.regf.shellbags.SHITEM attribute) (dissect.target.plugins.os.windows.regf.shellbags.UNKNOWN0 attribute) (dissect.target.plugins.os.windows.regf.shellbags.UNKNOWN1 attribute) (dissect.target.plugins.os.windows.regf.shellbags.UNKNOWN_0x74 attribute) (dissect.target.plugins.os.windows.regf.shellbags.URI attribute) (dissect.target.plugins.os.windows.regf.shellbags.USERS_PROPERTY_VIEW attribute) (dissect.target.plugins.os.windows.regf.shellbags.VOLUME attribute) STRUCT_FMT (in module dissect.etl.manifest) Structure (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.structure) STT (in module dissect.executable.elf.c_elf) Stub (class in acquire.acquire.gui.base) STV (in module dissect.executable.elf.c_elf) sub_stripes (dissect.btrfs.stream.Chunk attribute) SubBlockResource (class in dissect.vmfs.resource) subkey() (dissect.regf.regf.FastLeaf method) (dissect.regf.regf.HashLeaf method) (dissect.regf.regf.IndexLeaf method) (dissect.regf.regf.IndexRoot method) (dissect.regf.regf.NamedKey method) (dissect.target.helpers.regutil.KeyCollection method) (dissect.target.helpers.regutil.RegfKey method) (dissect.target.helpers.regutil.RegistryKey method) (dissect.target.helpers.regutil.VirtualKey method) (dissect.target.loaders.cb.CbRegistryKey method) (dissect.target.loaders.smb.SmbRegistryKey method) (dissect.target.plugins.os.windows.registry.RegistryPlugin method) subkey_list (dissect.regf.regf.NamedKey property) subkeys() (dissect.regf.regf.NamedKey method) (dissect.target.helpers.regutil.KeyCollection method) (dissect.target.helpers.regutil.RegfKey method) (dissect.target.helpers.regutil.RegistryKey method) (dissect.target.helpers.regutil.VirtualKey method) (dissect.target.loaders.cb.CbRegistryKey method) (dissect.target.loaders.smb.SmbRegistryKey method) subnet (class in flow.record.fieldtypes.net.ipv4) Subnet (in module flow.record.fieldtypes.net.ipv4) SubnetList (class in flow.record.fieldtypes.net.ipv4) subnets (flow.record.fieldtypes.net.ipv4.SubnetList attribute) subscriber (flow.record.adapter.broker.BrokerReader attribute) SUBSCRIPT (dissect.esedb.lcmapstring.CASE attribute) substitute_name (dissect.archive.wim.ReparsePoint property) (dissect.ntfs.attr.ReparsePoint property) substitute_token_and_add_to_template() (dissect.eventlog.bxml.Bxml method) SubStreamBase (class in dissect.evidence.asdf.streams) Subvolume (class in dissect.btrfs) (class in dissect.btrfs.btrfs) subvolumes() (dissect.btrfs.Btrfs method) (dissect.btrfs.btrfs.Btrfs method) SUCCESS (acquire.acquire.collector.Outcome attribute) suid_binaries() (dissect.target.plugins.filesystem.unix.suid.SuidPlugin method) SuidPlugin (class in dissect.target.plugins.filesystem.unix.suid) SuidRecord (in module dissect.target.plugins.filesystem.unix.suid) SUNDAY (in module dissect.target.plugins.os.windows.datetime) SundayFirstCalendar (in module dissect.target.plugins.os.windows.datetime) super_class_name (dissect.cim.classes.ClassDefinition property) SuSEPlugin (class in dissect.target.plugins.os.unix.linux.suse._os) SW_SHOWNORMAL (in module acquire.acquire.gui.win32) swap() (in module dissect.cstruct) (in module dissect.cstruct.utils) swap16() (in module dissect.cstruct) (in module dissect.cstruct.utils) swap32() (in module dissect.cstruct) (in module dissect.cstruct.utils) swap64() (in module dissect.cstruct) (in module dissect.cstruct.utils) SymantecPlugin (class in dissect.target.plugins.apps.av.symantec) Symbol (class in dissect.executable.elf) (class in dissect.executable.elf.elf) (in module dissect.util.compression.lzxpress_huffman) symbol() (dissect.etl.etl.Event method) SYMBOL_1 (dissect.esedb.lcmapstring.SCRIPT attribute) SYMBOL_2 (dissect.esedb.lcmapstring.SCRIPT attribute) SYMBOL_3 (dissect.esedb.lcmapstring.SCRIPT attribute) SYMBOL_4 (dissect.esedb.lcmapstring.SCRIPT attribute) SYMBOL_5 (dissect.esedb.lcmapstring.SCRIPT attribute) SYMBOL_6 (dissect.esedb.lcmapstring.SCRIPT attribute) SYMBOLIC_LINK (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) SymbolTable (class in dissect.executable.elf) (class in dissect.executable.elf.elf) SYMLINK (acquire.acquire.collector.ArtifactType attribute) symlink() (dissect.target.filesystem.RootFilesystem method) (dissect.target.filesystem.VirtualFilesystem method) SYMLINK_FLAG (in module dissect.archive.c_wim) symlink_to() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) SymlinkRecursionError SymlinkUnavailableException, [1] SYN_RECV (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) SYN_SENT (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) SYNCHRONIZE (acquire.acquire.dynamic.windows.types.ProcessAccess attribute) Sys (class in acquire.acquire.acquire) Syscache (class in acquire.acquire.acquire) syscache() (dissect.target.plugins.os.windows.syscache.SyscachePlugin method) SyscachePlugin (class in dissect.target.plugins.os.windows.syscache) SyscacheRecord (in module dissect.target.plugins.os.windows.syscache) syskey() (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin method) syslog() (dissect.target.plugins.os.unix.log.messages.MessagesPlugin method) sysmodules() (dissect.target.plugins.os.unix.linux.modules.ModulePlugin method) SYSOBJ (in module dissect.esedb.c_esedb) SYSTEM (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin attribute) (dissect.target.plugins.os.windows.registry.RegistryPlugin attribute) SYSTEM_HANDLE_INFORMATION_EX (class in acquire.acquire.dynamic.windows.types) SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX (class in acquire.acquire.dynamic.windows.types) system_id (dissect.volume.lvm.metadata.VolumeGroup attribute) system_identities() (dissect.target.plugins.os.windows.ual.UalPlugin method) SYSTEM_INFORMATION_CLASS (class in acquire.acquire.dynamic.windows.types) SYSTEM_KEY (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin attribute) SYSTEM_NAMESPACE_NAME (in module dissect.cim.c_cim) SYSTEM_USERNAME (dissect.target.plugins.os.windows.dpapi.dpapi.DPAPIPlugin attribute) SystemD (class in dissect.target.helpers.configutil) systemd() (dissect.target.plugins.os.unix.linux.services.ServicesPlugin method) SYSTEMD_PATHS (dissect.target.plugins.os.unix.linux.services.ServicesPlugin attribute) SystemData (class in dissect.target.plugins.os.windows.regf.cit) SystemDataBitmaps (class in dissect.target.plugins.os.windows.regf.cit) SystemExtendedHandleInformation (acquire.acquire.dynamic.windows.types.SYSTEM_INFORMATION_CLASS attribute) SystemHandleInformation (acquire.acquire.dynamic.windows.types.SYSTEM_INFORMATION_CLASS attribute) SystemHeader (class in dissect.etl.headers.system) SystemIdentityRecord (in module dissect.target.plugins.os.windows.ual) SYSTEMINFO (dissect.etl.headers.headers.EventProperty attribute) SystemSpecificHeader (class in dissect.etl.headers.system) SYSTEMTIME (dissect.eventlog.bxml.BxmlType attribute) SYSVOL_SUBST (in module acquire.acquire.utils) T T (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) t (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) T (in module acquire.acquire.uploaders.plugin_registry) (in module dissect.executable.elf.elf) (in module dissect.target.target) Table (class in dissect.esedb.table) (class in dissect.executable.elf.elf) (class in dissect.sql.sqlite3) table (in module dissect.esedb.sorting_table) table() (dissect.esedb.EseDB method) (dissect.esedb.esedb.EseDB method) (dissect.esedb.table.Catalog method) (dissect.sql.SQLite3 method) (dissect.sql.sqlite3.SQLite3 method) TABLE_FIELD (dissect.target.plugins.apps.av.mcafee.McAfeePlugin attribute) TABLE_LOG (dissect.target.plugins.apps.av.mcafee.McAfeePlugin attribute) table_names() (flow.record.adapter.sqlite.SqliteReader method) tables() (dissect.esedb.EseDB method) (dissect.esedb.esedb.EseDB method) (dissect.sql.SQLite3 method) (dissect.sql.sqlite3.SQLite3 method) TableSection (class in dissect.evidence.ewf) Tag (class in dissect.esedb.page) tag (dissect.ntfs.attr.ReparsePoint property) tag() (dissect.esedb.page.Page method) TAG_FLAG (in module dissect.esedb.c_esedb) TAG_MASKS (in module dissect.util.compression.lznt1) tag_size (dissect.volume.lvm.metadata.IntegritySegment attribute) TagField (class in dissect.esedb.record) TAGFLD_HEADER (in module dissect.esedb.c_esedb) tags (dissect.volume.lvm.metadata.LogicalVolume attribute) (dissect.volume.lvm.metadata.PhysicalVolume attribute) (dissect.volume.lvm.metadata.Segment attribute) (dissect.volume.lvm.metadata.VolumeGroup attribute) tags() (dissect.esedb.page.Page method) (dissect.extfs.journal.DescriptorBlock method) TaniumLoader (class in dissect.target.loaders.tanium) TarFilesystem (class in dissect.target.filesystems.tar) (in module dissect.target.filesystem) TarFilesystemDirectoryEntry (class in dissect.target.filesystems.tar) TarFilesystemEntry (class in dissect.target.filesystems.tar) Target (class in dissect.target) (class in dissect.target.target) target (dissect.target.report.TargetExecutionReport attribute) (dissect.target.tools.dump.run.RecordStreamElement attribute) target_path (dissect.target.tools.dump.state.Sink attribute) target_paths (dissect.target.tools.dump.state.DumpState attribute) target_reports (dissect.target.report.ExecutionReport attribute) target_shell() (in module dissect.target.tools.shell) TargetCli (class in dissect.target.tools.shell) TargetCmd (class in dissect.target.tools.shell) TARGETD_AVAILABLE (in module dissect.target.loaders.targetd), [1] TargetdInvalidStateError TargetdLoader (class in dissect.target.loaders.targetd) TargetdStream (class in dissect.target.helpers.targetd) TargetError TargetExecutionReport (class in dissect.target.report) TargetHubCli (class in dissect.target.tools.shell) TargetLoader (class in dissect.target.loaders.target) TargetLogAdapter (class in dissect.target.target) TargetPath (class in dissect.target.helpers.compat.path_310) (class in dissect.target.helpers.compat.path_311) (class in dissect.target.helpers.compat.path_312) (class in dissect.target.helpers.compat.path_39) TargetRecordDescriptor (in module dissect.target.helpers.record) TargetRecordDescriptorExtension (class in dissect.target.helpers.descriptor_extensions) TarLoader (class in dissect.target.loaders.tar) TarOutput (class in acquire.acquire.outputs.tar) TASK (class in dissect.eventlog.wevt_object) TaskRecord (in module dissect.target.plugins.os.windows.tasks) Tasks (class in acquire.acquire.acquire) tasks() (dissect.target.plugins.os.windows.tasks.TasksPlugin method) TasksPlugin (class in dissect.target.plugins.os.windows.tasks) tcp() (dissect.target.plugins.os.unix.linux.proc.Sockets method) (dissect.target.plugins.os.unix.linux.sockets.NetSocketPlugin method) tcp6() (dissect.target.plugins.os.unix.linux.proc.Sockets method) TCP_CLOSE (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) TCP_INIT (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) TcpIpGuid (in module dissect.etl.utils) TeamviewerPlugin (class in dissect.target.plugins.apps.remoteaccess.teamviewer) Tee (in module dissect.target.helpers.cache) telemetry() (dissect.target.plugins.os.windows.regf.cit.CITPlugin method) tell() (acquire.acquire.crypt.EncryptedStream method) (dissect.evidence.asdf.streams.SubStreamBase method) (dissect.target.container.Container method) (dissect.target.containers.asdf.AsdfContainer method) (dissect.target.containers.ewf.EwfContainer method) (dissect.target.containers.hdd.HddContainer method) (dissect.target.containers.hds.HdsContainer method) (dissect.target.containers.qcow2.QCow2Container method) (dissect.target.containers.split.SplitContainer method) (dissect.target.containers.vdi.VdiContainer method) (dissect.target.containers.vhd.VhdContainer method) (dissect.target.containers.vhdx.VhdxContainer method) (dissect.target.containers.vmdk.VmdkContainer method) (dissect.target.volume.Volume method) (dissect.util.stream.AlignedStream method) TEMP (class in dissect.eventlog.wevt_object) TEMP_DESCRIPTOR (class in dissect.eventlog.wevt_object) Template (class in dissect.eventlog.bxml) (class in dissect.target.helpers.network_managers) TEMPLATE_ID_INFECTION (dissect.target.plugins.apps.av.mcafee.McAfeePlugin attribute) TEMPLATES (in module dissect.target.helpers.network_managers) TerminalServerMRURecord (in module dissect.target.plugins.os.windows.regf.mru) TextWriter (class in flow.record.adapter.text) thin_pool (dissect.volume.lvm.metadata.ThinSegment attribute) ThinDevice (class in dissect.volume.dm.thin) ThinPool (class in dissect.volume.dm.thin) ThinPoolSegment (class in dissect.volume.lvm.metadata) ThinSegment (class in dissect.volume.lvm.metadata) THREAD (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) thread (acquire.acquire.gui.base.GUI attribute) thread_id (dissect.etl.headers.event.EventHeader property) (dissect.etl.headers.headers.EventInstanceGUIDHeader property) (dissect.etl.headers.headers.EventTraceHeader property) (dissect.etl.headers.headers.MessageTraceHeader property) (dissect.etl.headers.system.CompactSystemHeader property) (dissect.etl.headers.system.SystemHeader property) ThreadGuid (in module dissect.etl.utils) ThreadPoolGuid (in module dissect.etl.utils) Thumbcache (class in dissect.thumbcache) (class in dissect.thumbcache.thumbcache) thumbcache() (dissect.target.plugins.os.windows.thumbcache.ThumbcachePlugin method) ThumbcacheEntry (class in dissect.thumbcache) (class in dissect.thumbcache.thumbcache_file) ThumbcacheFile (class in dissect.thumbcache) (class in dissect.thumbcache.thumbcache_file) ThumbcachePlugin (class in dissect.target.plugins.os.windows.thumbcache) ThumbcacheRecord (in module dissect.target.plugins.os.windows.thumbcache) ThumbnailCache (class in acquire.acquire.acquire) ThumbnailIndex (class in dissect.thumbcache) (class in dissect.thumbcache.index) ThumbnailType (class in dissect.thumbcache.util) time_delta (dissect.etl.headers.headers.Header property) (dissect.etl.headers.headers.MessageTraceHeader property) TIME_WAIT (dissect.target.plugins.os.unix.linux.proc.Sockets.TCPStates attribute) timeout (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) TIMER (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) timestamp (acquire.acquire.tools.decrypter.EncryptedFile property) (dissect.cim.classes.ClassDefinition property) TIMESTAMP (dissect.etl.headers.headers.EventProperty attribute) timestamp (dissect.etl.headers.headers.Header property) (dissect.ntfs.usnjrnl.UsnRecord property) (dissect.ntfs.UsnRecord property) (dissect.regf.regf.NamedKey property) (dissect.target.helpers.regutil.KeyCollection property) (dissect.target.helpers.regutil.RegfKey property) (dissect.target.helpers.regutil.RegistryKey property) (dissect.target.helpers.regutil.VirtualKey property) (dissect.target.loaders.cb.CbRegistryKey property) (dissect.target.loaders.smb.SmbRegistryKey property) timestamp_ns (dissect.ntfs.usnjrnl.UsnRecord property) (dissect.ntfs.UsnRecord property) TimestampRecord (in module flow.record.base) TimeTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) timezone() (dissect.target.plugins.os.unix.linux.fortios.locale.LocalePlugin method) (dissect.target.plugins.os.unix.locale.LocalePlugin method) (dissect.target.plugins.os.windows.locale.LocalePlugin method) timezone_from_path() (in module dissect.target.plugins.os.unix.locale) TimezoneInformation (in module dissect.target.plugins.os.windows.datetime) to_base64() (in module flow.record.utils) to_bytes() (in module flow.record.utils) to_native_str() (in module flow.record.utils) to_str() (in module flow.record.utils) to_unix() (in module dissect.util.ts) to_unix_ms() (in module dissect.util.ts) to_unix_ns() (in module dissect.util.ts) to_unix_us() (in module dissect.util.ts) to_utc() (dissect.target.plugins.os.unix.datetime.DateTimePlugin method) (dissect.target.plugins.os.windows.datetime.DateTimePlugin method) TOC (class in dissect.cim.objects) TOKEN (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) Token (class in dissect.cstruct.parser) (class in dissect.eventlog.bxml) TOKEN_ADJUST_PRIVILEGES (acquire.acquire.dynamic.windows.types.ProcessToken attribute) TOKEN_MASK (dissect.eventlog.bxml.Token attribute) TOKEN_PRIVILEGES (class in acquire.acquire.dynamic.windows.types) TOKEN_QUERY (acquire.acquire.dynamic.windows.types.ProcessToken attribute) TokenCollection (class in dissect.cstruct.parser) TokenConsumer (class in dissect.cstruct.parser) tokenize() (dissect.cstruct.expression.ExpressionTokenizer method) TOKENIZER_EXPRESSION (dissect.sql.sqlite3.Column attribute) TokenParser (class in dissect.cstruct.parser) TOOLS (dissect.target.plugins.os.unix.packagemanager.PackageManagerPlugin attribute) TOP (acquire.acquire.acquire.ExecutionOrder attribute) top_guid (dissect.hypervisor.disk.hdd.Snapshots attribute) total_entries (dissect.thumbcache.index.ThumbnailIndex property) (dissect.thumbcache.ThumbnailIndex property) touch() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) TP_WORKER_FACTORY (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) tr_tm_when (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) TRACKER_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) transaction_id (dissect.volume.lvm.metadata.ThinPoolSegment attribute) (dissect.volume.lvm.metadata.ThinSegment attribute) transform_app_id() (in module dissect.target.plugins.os.windows.sru) TRANSFORMS (in module dissect.target.plugins.os.windows.sru) translate() (dissect.target.helpers.network_managers.Parser method) translate_file_path() (in module dissect.target.loaders.itunes) translate_network_config() (dissect.target.helpers.network_managers.Parser method) translate_timezone() (in module dissect.target.plugins.os.unix.linux.fortios.locale) translate_tz() (in module dissect.target.plugins.os.windows.datetime) transport_agents() (dissect.target.plugins.os.windows.exchange.exchange.ExchangePlugin method) tree() (dissect.btrfs.btrfs.Subvolume method) (dissect.btrfs.Subvolume method) TrendMicroPlugin (class in dissect.target.plugins.apps.av.trendmicro) TrendMicroWFFirewallRecord (in module dissect.target.plugins.apps.av.trendmicro) TrendMicroWFLogRecord (in module dissect.target.plugins.apps.av.trendmicro) TriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) TRIGRAM_SIZE_BYTES (dissect.target.plugins.os.unix.locate.plocate.PLocateFile attribute) truncate_records() (dissect.clfs.blf.BLF method) TruncateRecord (class in dissect.clfs.blf) trusteddocs() (dissect.target.plugins.os.windows.regf.trusteddocs.TrustedDocumentsPlugin method) TrustedDocumentsPlugin (class in dissect.target.plugins.os.windows.regf.trusteddocs) TrustedDocumentsRecord (in module dissect.target.plugins.os.windows.regf.trusteddocs) try_decode_sz() (in module dissect.regf.regf) try_idna() (in module dissect.target.plugins.apps.browser.browser) ts (dissect.target.helpers.regutil.RegistryKey property) (dissect.target.plugins.os.unix.locate.mlocate.MLocate attribute) (dissect.target.plugins.os.windows.log.schedlgu.SchedLgU attribute) ts() (dissect.etl.etl.Event method) TS_ID (dissect.etl.headers.event.ExtType attribute) ts_ns (dissect.target.plugins.os.unix.locate.mlocate.MLocate attribute) ts_to_ns() (in module dissect.ntfs.util) TTBL_WEVT_TYPE (class in dissect.eventlog.wevt) TUNNEL_NAME_RE (dissect.target.plugins.apps.vpn.wireguard.WireGuardPlugin attribute) tx_queue (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) tx_rx_queue (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) Txt (class in dissect.target.helpers.configutil) TYPE (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) type (dissect.btrfs.stream.Chunk attribute) (dissect.cim.cim.Property property) (dissect.cim.classes.ClassInstanceProperty property) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) (dissect.hypervisor.disk.hdd.Image attribute) (dissect.ntfs.ACE property) (dissect.ntfs.attr.Attribute property) (dissect.ntfs.attr.AttributeHeader property) (dissect.ntfs.Attribute property) (dissect.ntfs.AttributeHeader property) (dissect.ntfs.secure.ACE property) (dissect.regf.regf.KeyValue property) (dissect.squashfs.INode property) (dissect.squashfs.squashfs.INode property) (dissect.target.helpers.regutil.RegfValue property) (dissect.target.helpers.regutil.RegistryValue property) (dissect.target.helpers.regutil.ValueCollection property) (dissect.target.helpers.regutil.VirtualValue property) (dissect.target.loaders.cb.CbRegistryValue property) (dissect.target.loaders.smb.SmbRegistryValue property) (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) (dissect.target.plugins.os.unix.linux.proc.UnixSocket attribute) (dissect.thumbcache.index.ThumbnailIndex property) (dissect.thumbcache.ThumbnailIndex property) (dissect.vmfs.vmfs.FileDescriptor property) (dissect.volume.lvm.metadata.LogicalVolume property) (dissect.volume.lvm.metadata.Segment attribute) (flow.record.base.RecordField attribute) (flow.record.RecordField attribute) type() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.ffs.ffs.INode method) (dissect.jffs.jffs2.INode method) TYPE_MAP (in module dissect.squashfs.c_squashfs) (in module dissect.util.cpio) TYPE_MAX (dissect.etl.headers.event.ExtType attribute) type_name (acquire.acquire.dynamic.windows.types.OBJECT_DIRECTORY_INFORMATION property) TYPE_READERS (in module dissect.eventlog.bxml) type_to_mode() (in module dissect.vmfs.c_vmfs) TYPE_VARIATIONS (in module dissect.target.plugins.os.windows.regf.shimcache) typedlist (class in flow.record.fieldtypes) TypeMatcher (class in flow.record.selector) TypeMatcherInstance (class in flow.record.selector) typename (flow.record.base.RecordField attribute) (flow.record.RecordField attribute) TYPES (dissect.cstruct.Compiler attribute) (dissect.cstruct.compiler.Compiler attribute) types (dissect.sql.sqlite3.Cell property) TYPES (dissect.volume.disk.schemes.BSD attribute) (dissect.volume.disk.schemes.bsd.BSD attribute) (flow.record.packer.RecordPacker attribute) tz() (dissect.target.plugins.os.unix.datetime.DateTimePlugin method) (dissect.target.plugins.os.windows.datetime.DateTimePlugin method) tz_def (in module dissect.target.plugins.os.windows.datetime) tzinfo() (dissect.target.plugins.os.unix.datetime.DateTimePlugin method) (dissect.target.plugins.os.windows.datetime.DateTimePlugin method) tzname() (dissect.target.plugins.os.windows.datetime.WindowsTimezone method) (dissect.util.ts.UTC method) U u16() (in module dissect.cstruct) (in module dissect.cstruct.utils) u32() (in module dissect.cstruct) (in module dissect.cstruct.utils) u64() (in module dissect.cstruct) (in module dissect.cstruct.utils) u8() (in module dissect.cstruct) (in module dissect.cstruct.utils) UAL (class in dissect.esedb.tools.ual) UalPlugin (class in dissect.target.plugins.os.windows.ual) UalValue (in module dissect.esedb.tools.ual) udp() (dissect.target.plugins.os.unix.linux.proc.Sockets method) (dissect.target.plugins.os.unix.linux.sockets.NetSocketPlugin method) udp6() (dissect.target.plugins.os.unix.linux.proc.Sockets method) UDP_DATA (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) UdpIpGuid (in module dissect.etl.utils) ufstimestamp (in module dissect.util.ts) uid (dissect.squashfs.INode property) (dissect.squashfs.squashfs.INode property) (dissect.target.plugins.os.unix.linux.proc.NetSocket attribute) (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) uid() (dissect.btrfs.btrfs.INode method) (dissect.btrfs.INode method) (dissect.jffs.jffs2.INode method) uint16 (class in flow.record.fieldtypes) UINT16 (dissect.eventlog.bxml.BxmlType attribute) uint32 (class in flow.record.fieldtypes) UINT32 (dissect.eventlog.bxml.BxmlType attribute) UINT64 (dissect.eventlog.bxml.BxmlType attribute) UINT8 (dissect.eventlog.bxml.BxmlType attribute) ulDAEMagic (in module dissect.esedb.c_esedb) UmsEventGuid (in module dissect.etl.utils) UNALLOCATED (in module dissect.hypervisor.disk.c_vdi) UNALLOCATED_SUBCLUSTER_TYPES (in module dissect.hypervisor.disk.c_qcow2) unbind() (acquire.acquire.collector.Collector method) UNICODE_STRING (class in acquire.acquire.dynamic.windows.types) UnimplementedHeader (class in dissect.etl.headers.headers) Union (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.structure) unique_process_id (acquire.acquire.dynamic.windows.types.SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX property) UNIX (dissect.target.plugin.OperatingSystem attribute) unix() (dissect.target.plugins.os.unix.linux.proc.Sockets method) (dissect.target.plugins.os.unix.linux.sockets.NetSocketPlugin method) UNIX_ACCESSORS (in module dissect.target.loaders.velociraptor) unix_file_mode (class in flow.record.fieldtypes) unix_now() (in module dissect.util.ts) unix_now_ms() (in module dissect.util.ts) unix_now_ns() (in module dissect.util.ts) unix_now_us() (in module dissect.util.ts) UnixConfigTreeCli (class in dissect.target.tools.shell) UnixKeyboardRecord (in module dissect.target.plugins.os.unix.locale) UnixPlugin (class in dissect.target.plugins.os.unix._os) UnixShadowRecord (in module dissect.target.plugins.os.unix.shadow) UnixSocket (class in dissect.target.plugins.os.unix.linux.proc) UnixSocketRecord (in module dissect.target.plugins.os.unix.linux.sockets) UnixUserRecord (in module dissect.target.helpers.record) UNKNOWN (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) (class in dissect.target.plugins.os.windows.regf.shellbags) (dissect.etl.headers.event.ExtType attribute) UNKNOWN0 (class in dissect.target.plugins.os.windows.regf.shellbags) UNKNOWN1 (class in dissect.target.plugins.os.windows.regf.shellbags) UNKNOWN_0x74 (class in dissect.target.plugins.os.windows.regf.shellbags) UNKNOWN_BYTES (in module dissect.thumbcache.thumbcache_file) UnknownSignatureException, [1] UnknownThumbnailTypeError unlink() (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) unlock() (dissect.hypervisor.descriptor.vmx.Pair method) unlock_volume() (dissect.target.volumes.bde.BitlockerVolumeSystem method) (dissect.target.volumes.luks.LUKSVolumeSystem method) unlock_with_bek_file() (dissect.target.volumes.bde.BitlockerVolumeSystem method) unlock_with_key_file() (dissect.target.volumes.luks.LUKSVolumeSystem method) unlock_with_passcode_key() (dissect.target.loaders.itunes.KeyBag method) unlock_with_passphrase() (dissect.target.volumes.bde.BitlockerVolumeSystem method) (dissect.target.volumes.luks.LUKSVolumeSystem method) unlock_with_phrase() (dissect.hypervisor.descriptor.vmx.Pair method) (dissect.hypervisor.descriptor.vmx.VMX method) unlock_with_recovery_key() (dissect.target.volumes.bde.BitlockerVolumeSystem method) unlock_with_volume_encryption_key() (dissect.target.volumes.luks.LUKSVolumeSystem method) UNMAPPED_PAGE_VALUE (in module dissect.cim.c_cim) UnmappedPageError, [1] unpack() (flow.record.jsonpacker.JsonRecordPacker method) (flow.record.JsonRecordPacker method) (flow.record.packer.RecordPacker method) (in module dissect.cstruct) (in module dissect.cstruct.utils) unpack_obj() (flow.record.jsonpacker.JsonRecordPacker method) (flow.record.JsonRecordPacker method) (flow.record.packer.RecordPacker method) unpack_timestamps() (dissect.target.plugins.os.windows.regf.usb.UsbPlugin method) unpackb (in module flow.record.packer) unseal_with_phrase() (dissect.hypervisor.descriptor.vmx.KeySafe method) UNSORTABLE (dissect.esedb.lcmapstring.SCRIPT attribute) UnsupportedDataforkException, [1] UnsupportedPluginError UnsupportedVersion unwrap() (dissect.hypervisor.descriptor.vmx.Phrase method) (dissect.target.helpers.configutil.ListUnwrapper static method) (dissect.target.loaders.itunes.ClassKey method) (dissect.target.loaders.itunes.KeyBag method) unwrapped (dissect.target.loaders.itunes.ClassKey property) UPCASE_TABLE_ENTRY (in module dissect.fat.c_exfat) Update (dissect.target.plugins.os.unix.packagemanager.OperationTypes attribute) update() (dissect.evidence.tools.asdf.dd.Progress method) (dissect.target.helpers.configutil.ScopeManager method) (dissect.target.tools.dump.state.DumpState method) (in module dissect.util.crc32c) update_descriptor_columns() (in module flow.record.adapter.sqlite) update_dict_recursive() (in module dissect.target.plugins.general.plugins) update_prev() (dissect.target.helpers.configutil.ScopeManager method) UPF (class in dissect.target.loaders.res) upload_available (acquire.acquire.gui.base.GUI attribute) upload_file() (acquire.acquire.uploaders.minio.MinIO method) (acquire.acquire.uploaders.plugin.UploaderPlugin method) upload_files() (in module acquire.acquire.acquire) upload_files_using_uploader() (in module acquire.acquire.uploaders.plugin) upload_label (acquire.acquire.gui.win32.Win32 attribute) UploaderPlugin (class in acquire.acquire.uploaders.plugin) UploaderRegistry (in module acquire.acquire.uploaders.plugin_registry) UPPER (dissect.esedb.lcmapstring.CASE attribute) upper() (in module flow.record.selector) UPR (class in dissect.target.loaders.res) uptime (dissect.target.plugins.os.unix.linux.proc.ProcProcess property) URI (class in dissect.target.plugins.os.windows.regf.shellbags) uri (class in flow.record.fieldtypes) USAGE_FORMAT_TMPL (in module dissect.target.tools.query) USB (dissect.target.plugins.os.windows.regf.usb.UsbPlugin attribute) usb() (dissect.target.plugins.os.windows.regf.usb.UsbPlugin method) USB_DEVICE_PROPERTY_KEYS (in module dissect.target.plugins.os.windows.regf.usb) USB_STOR (dissect.target.plugins.os.windows.regf.usb.UsbPlugin attribute) UsbPlugin (class in dissect.target.plugins.os.windows.regf.usb) UsbRegistryRecord (in module dissect.target.plugins.os.windows.regf.usb) use_compression (dissect.volume.lvm.metadata.VdoPoolSegment attribute) use_deduplication (dissect.volume.lvm.metadata.VdoPoolSegment attribute) use_metadata_hints (dissect.volume.lvm.metadata.VdoPoolSegment attribute) use_sparse_index (dissect.volume.lvm.metadata.VdoPoolSegment attribute) used_by (dissect.target.plugins.os.unix.linux.modules.Module attribute) used_entries (dissect.thumbcache.index.ThumbnailIndex property) (dissect.thumbcache.ThumbnailIndex property) user (dissect.target.plugins.general.users.UserDetails attribute) (dissect.target.plugins.os.unix.linux.proc.PacketSocket attribute) user() (dissect.target.plugins.os.windows.regf.clsid.CLSIDPlugin method) user32 (in module acquire.acquire.gui.win32) user_config_paths (dissect.target.plugins.apps.vpn.openvpn.OpenVPNPlugin attribute) user_env() (dissect.target.plugins.os.windows.env.EnvironmentVariablePlugin method) USER_GLOBS (dissect.target.plugins.apps.remoteaccess.anydesk.AnydeskPlugin attribute) USER_PATH (dissect.target.plugins.os.unix.bsd.osx.user.UserPlugin attribute) USER_VARIABLES (dissect.target.plugins.os.windows.env.EnvironmentVariablePlugin attribute) userassist() (dissect.target.plugins.os.windows.regf.userassist.UserAssistPlugin method) userassist_def (in module dissect.target.plugins.os.windows.regf.userassist) UserAssistPlugin (class in dissect.target.plugins.os.windows.regf.userassist) UserAssistRecord (in module dissect.target.plugins.os.windows.regf.userassist) UserAssistRecordDescriptor (in module dissect.target.plugins.os.windows.regf.userassist) UserDetails (class in dissect.target.plugins.general.users) username (class in flow.record.fieldtypes.credential) (flow.record.fieldtypes.uri property) UserPlugin (class in dissect.target.plugins.os.unix.bsd.osx.user) UserRecordDescriptorExtension (class in dissect.target.helpers.descriptor_extensions) UserRegistryRecordDescriptor (in module dissect.target.plugins.os.windows.generic) (in module dissect.target.plugins.os.windows.regf.mru) users() (dissect.target.loaders.profile.ProfileOSPlugin method) (dissect.target.loaders.res.ResOSPlugin method) (dissect.target.plugin.OSPlugin method) (dissect.target.plugins.general.default.DefaultPlugin method) (dissect.target.plugins.os.unix._os.UnixPlugin method) (dissect.target.plugins.os.unix.bsd.citrix._os.CitrixPlugin method) (dissect.target.plugins.os.unix.bsd.ios._os.IOSPlugin method) (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin method) (dissect.target.plugins.os.unix.linux.android._os.AndroidPlugin method) (dissect.target.plugins.os.unix.linux.fortios._os.FortiOSPlugin method) (dissect.target.plugins.os.windows._os.WindowsPlugin method) USERS_PROPERTY_VIEW (class in dissect.target.plugins.os.windows.regf.shellbags) UsersPlugin (class in dissect.target.plugins.general.users) USN_PAGE_SIZE (in module dissect.ntfs.c_ntfs) UsnJrnl (class in dissect.ntfs) (class in dissect.ntfs.usnjrnl) usnjrnl() (dissect.target.plugins.filesystem.ntfs.usnjrnl.UsnjrnlPlugin method) USNJRNL_PATHS (in module dissect.target.loaders.kape) UsnjrnlPlugin (class in dissect.target.plugins.filesystem.ntfs.usnjrnl) UsnjrnlRecord (in module dissect.target.plugins.filesystem.ntfs.usnjrnl) UsnRecord (class in dissect.ntfs) (class in dissect.ntfs.usnjrnl) UTC (class in dissect.util.ts) (in module flow.record.fieldtypes) (in module flow.record.packer) utcoffset() (dissect.target.plugins.os.windows.datetime.WindowsTimezone method) (dissect.util.ts.UTC method) UtmLoader (class in dissect.target.loaders.utm) utmp (in module dissect.target.plugins.os.unix.log.utmp) UTMP_ENTRY (in module dissect.target.plugins.os.unix.log.utmp) UTMP_FIELDS (in module dissect.target.plugins.os.unix.log.utmp) UtmpFile (class in dissect.target.plugins.os.unix.log.utmp) UtmpPlugin (class in dissect.target.plugins.os.unix.log.utmp) uuid() (dissect.btrfs.btrfs.Subvolume method) (dissect.btrfs.Subvolume method) uuid1timestamp() (in module dissect.util.ts) V val (flow.record.fieldtypes.net.ip.ipaddress attribute) (flow.record.fieldtypes.net.ip.ipnetwork attribute) (flow.record.fieldtypes.net.ipaddress attribute) (flow.record.fieldtypes.net.ipnetwork attribute) (flow.record.fieldtypes.net.ipv4.address attribute) valid (dissect.clfs.blf.ControlRecord property) (dissect.sql.sqlite3.WALFrame property) VALID_BPB_MEDIA (in module dissect.fat.c_fat) valid_signatures (dissect.eventlog.wevt.WEVT_TYPE attribute) validate_bpb() (in module dissect.fat.fat) validate_header() (dissect.etl.headers.event.EventHeaderExtendedDataItem method) validate_ntstatus() (in module acquire.acquire.dynamic.windows.ntdll) validate_signature() (in module dissect.eventlog.wevt) value (dissect.cim.classes.ClassInstanceProperty property) (dissect.executable.elf.elf.Symbol property) (dissect.executable.elf.Symbol property) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) (dissect.regf.regf.KeyValue property) (dissect.target.helpers.keychain.Key attribute) (dissect.target.helpers.regutil.RegFlexValue property) (dissect.target.helpers.regutil.RegfValue property) (dissect.target.helpers.regutil.RegistryValue property) (dissect.target.helpers.regutil.ValueCollection property) (dissect.target.helpers.regutil.VirtualValue property) (dissect.target.loaders.cb.CbRegistryValue property) (dissect.target.loaders.smb.SmbRegistryValue property) (flow.record.fieldtypes.boolean attribute) (flow.record.fieldtypes.bytes attribute) (flow.record.fieldtypes.uint16 attribute) (flow.record.fieldtypes.uint32 attribute) value() (dissect.regf.regf.NamedKey method) (dissect.target.helpers.regutil.KeyCollection method) (dissect.target.helpers.regutil.RegfKey method) (dissect.target.helpers.regutil.RegistryKey method) (dissect.target.helpers.regutil.VirtualKey method) (dissect.target.loaders.cb.CbRegistryKey method) (dissect.target.loaders.smb.SmbRegistryKey method) (dissect.target.plugins.os.windows.registry.RegistryPlugin method) (dissect.volume.dm.btree.Node method) value_based_on_shndx() (dissect.executable.elf.elf.Symbol method) (dissect.executable.elf.Symbol method) VALUE_MAP (dissect.target.plugins.os.windows.regf.firewall.FirewallPlugin attribute) value_size (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry property) value_type (dissect.eventlog.bxml.BxmlTemplateDescriptor property) ValueCollection (class in dissect.target.helpers.regutil) ValueList (class in dissect.regf.regf) values (dissect.sql.sqlite3.Cell property) values() (dissect.hypervisor.descriptor.hyperv.HyperVFile method) (dissect.hypervisor.descriptor.hyperv.HyperVStorageKeyTableEntry method) (dissect.regf.regf.NamedKey method) (dissect.target.helpers.regutil.KeyCollection method) (dissect.target.helpers.regutil.RegfKey method) (dissect.target.helpers.regutil.RegistryKey method) (dissect.target.helpers.regutil.VirtualKey method) (dissect.target.loaders.cb.CbRegistryKey method) (dissect.target.loaders.smb.SmbRegistryKey method) ValueType (in module dissect.target.helpers.regutil) Var (class in acquire.acquire.acquire) variable (dissect.target.plugins.os.unix.linux.proc.Environ attribute) VARIABLES (dissect.target.plugins.os.windows.env.EnvironmentVariablePlugin attribute) varint (class in flow.record.fieldtypes) varint() (in module dissect.ntfs.c_ntfs) (in module dissect.sql.sqlite3) varint_type (in module flow.record.fieldtypes) VBLoader (class in dissect.target.loaders.vb) VBox (class in dissect.hypervisor.descriptor.vbox) VBOX_XML_NAMESPACE (dissect.hypervisor.descriptor.vbox.VBox attribute) VBoxLoader (class in dissect.target.loaders.vbox) VDI (class in dissect.hypervisor.disk.vdi) vdi_def (in module dissect.hypervisor.disk.c_vdi) VDI_SIGNATURE (in module dissect.hypervisor.disk.c_vdi) VdiContainer (class in dissect.target.containers.vdi) vdo_offset (dissect.volume.lvm.metadata.VdoSegment attribute) vdo_pool (dissect.volume.lvm.metadata.VdoSegment attribute) VdoPoolSegment (class in dissect.volume.lvm.metadata) VdoSegment (class in dissect.volume.lvm.metadata) VelociraptorLoader (class in dissect.target.loaders.velociraptor) VERBOSITY_ALL (flow.record.selector.Selector attribute) VERBOSITY_BRANCHES (flow.record.selector.Selector attribute) VERBOSITY_NONE (flow.record.selector.Selector attribute) verify() (acquire.acquire.tools.decrypter.EncryptedFile method) VerifyError version (dissect.etl.headers.headers.Header property) (dissect.etl.headers.headers.MessageTraceHeader property) (dissect.hypervisor.descriptor.hyperv.HyperVFile property) VERSION (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin attribute) version (dissect.target.plugins.os.windows.log.schedlgu.SchedLgU attribute) (dissect.target.plugins.os.windows.regf.shellbags.EXTENSION_BLOCK property) (dissect.thumbcache.index.ThumbnailIndex property) (dissect.thumbcache.thumbcache_file.ThumbcacheFile property) (dissect.thumbcache.ThumbcacheFile property) (dissect.thumbcache.ThumbnailIndex property) VERSION (in module acquire.acquire.acquire) version (in module acquire.acquire.acquire) VERSION (in module dissect.evidence.asdf.asdf) version (in module flow.record.tools.rdump) version() (dissect.target.loaders.profile.ProfileOSPlugin method) (dissect.target.loaders.res.ResOSPlugin method) (dissect.target.plugin.OSPlugin method) (dissect.target.plugins.general.default.DefaultPlugin method) (dissect.target.plugins.os.unix.bsd.citrix._os.CitrixPlugin method) (dissect.target.plugins.os.unix.bsd.freebsd._os.FreeBsdPlugin method) (dissect.target.plugins.os.unix.bsd.ios._os.IOSPlugin method) (dissect.target.plugins.os.unix.bsd.openbsd._os.OpenBsdPlugin method) (dissect.target.plugins.os.unix.bsd.osx._os.MacPlugin method) (dissect.target.plugins.os.unix.esxi._os.ESXiPlugin method) (dissect.target.plugins.os.unix.linux._os.LinuxPlugin method) (dissect.target.plugins.os.unix.linux.android._os.AndroidPlugin method) (dissect.target.plugins.os.unix.linux.debian.vyos._os.VyosPlugin method) (dissect.target.plugins.os.unix.linux.fortios._os.FortiOSPlugin method) (dissect.target.plugins.os.unix.log.atop.AtopFile method) (dissect.target.plugins.os.windows._os.WindowsPlugin method) VERSION_NT52 (dissect.target.plugins.os.windows.regf.shimcache.SHIMCACHE_WIN_TYPE attribute) VERSION_NT61 (dissect.target.plugins.os.windows.regf.shimcache.SHIMCACHE_WIN_TYPE attribute) VERSION_WIN10 (dissect.target.plugins.os.windows.regf.shimcache.SHIMCACHE_WIN_TYPE attribute) VERSION_WIN10_CREATORS (dissect.target.plugins.os.windows.regf.shimcache.SHIMCACHE_WIN_TYPE attribute) VERSION_WIN81 (dissect.target.plugins.os.windows.regf.shimcache.SHIMCACHE_WIN_TYPE attribute) VERSION_WIN81_NO_HEADER (dissect.target.plugins.os.windows.regf.shimcache.SHIMCACHE_WIN_TYPE attribute) VFS_CAP_FLAGS_EFFECTIVE (in module dissect.target.plugins.filesystem.unix.capability) VFS_CAP_FLAGS_MASK (in module dissect.target.plugins.filesystem.unix.capability) VFS_CAP_REVISION_1 (in module dissect.target.plugins.filesystem.unix.capability) VFS_CAP_REVISION_2 (in module dissect.target.plugins.filesystem.unix.capability) VFS_CAP_REVISION_3 (in module dissect.target.plugins.filesystem.unix.capability) VFS_CAP_REVISION_MASK (in module dissect.target.plugins.filesystem.unix.capability) VFS_CAP_REVISION_SHIFT (in module dissect.target.plugins.filesystem.unix.capability) VFS_CAP_U32_1 (in module dissect.target.plugins.filesystem.unix.capability) VFS_CAP_U32_2 (in module dissect.target.plugins.filesystem.unix.capability) VFS_CAP_U32_3 (in module dissect.target.plugins.filesystem.unix.capability) vfu() (dissect.target.plugins.os.windows.sru.SRUPlugin method) VfuRecord (in module dissect.target.plugins.os.windows.sru) vg (dissect.volume.lvm.LVM2 property) (dissect.volume.lvm.lvm2.LVM2 property) (dissect.volume.lvm.metadata.HistoricalLogicalVolume property) (dissect.volume.lvm.metadata.LogicalVolume property) (dissect.volume.lvm.metadata.PhysicalVolume property) VHD (class in dissect.hypervisor.disk.vhd) vhd_def (in module dissect.hypervisor.disk.c_vhd) VhdContainer (class in dissect.target.containers.vhd) VHDX (class in dissect.hypervisor.disk.vhdx) vhdx_def (in module dissect.hypervisor.disk.c_vhdx) VHDX_PARENT_LOCATOR_GUID (in module dissect.hypervisor.disk.c_vhdx) VhdxContainer (class in dissect.target.containers.vhdx) virtual_disk_configuration_record (dissect.volume.ddf.ddf.DDFVirtualDisk property) VIRTUAL_DISK_ID_GUID (in module dissect.hypervisor.disk.c_vhdx) virtual_disk_record (dissect.volume.ddf.ddf.DDFVirtualDisk property) VIRTUAL_DISK_SIZE_GUID (in module dissect.hypervisor.disk.c_vhdx) virtual_extents (dissect.volume.lvm.metadata.VdoPoolSegment attribute) virtual_machines() (dissect.target.plugins.os.windows.ual.UalPlugin method) VirtualDirectory (class in dissect.target.filesystem) VirtualDisk (class in dissect.volume.raid.raid) VirtualDiskConfigurationRecord (class in dissect.volume.ddf.ddf) VirtualDiskRecord (class in dissect.volume.ddf.ddf) VirtualFile (class in dissect.target.filesystem) VirtualFileHandle (class in dissect.target.filesystem) VirtualFilesystem (class in dissect.target.filesystem) VirtualHive (class in dissect.target.helpers.regutil) VirtualKey (class in dissect.target.helpers.regutil) VirtualMachineRecord (in module dissect.target.plugins.os.unix.esxi._os) (in module dissect.target.plugins.os.windows.ual) VirtualSymlink (class in dissect.target.filesystem) VirtualValue (class in dissect.target.helpers.regutil) VirtuozzoChildTargetPlugin (class in dissect.target.plugins.child.virtuozzo) VIRUS_TYPE (dissect.target.plugins.apps.av.symantec.SymantecPlugin attribute) VisorTarFile() (in module dissect.hypervisor.util.vmtar) VisorTarInfo (class in dissect.hypervisor.util.vmtar) VISTA_AND_ABOVE_IDLIST_PROPS (dissect.shellitem.lnk.c_lnk.EXTRA_DATA_BLOCK_SIGNATURES attribute) vm_inventory() (dissect.target.plugins.os.unix.esxi._os.ESXiPlugin method) VMA (class in dissect.hypervisor.backup.vma) vma_def (in module dissect.hypervisor.backup.c_vma) VMA_EXTENT_MAGIC (in module dissect.hypervisor.backup.c_vma) VMA_MAGIC (in module dissect.hypervisor.backup.c_vma) VmaLoader (class in dissect.target.loaders.vma) VMAP (class in dissect.eventlog.wevt_object) VMDK (class in dissect.hypervisor.disk.vmdk) vmdk_def (in module dissect.hypervisor.disk.c_vmdk) VMDK_MAGIC (in module dissect.hypervisor.disk.c_vmdk) VmdkContainer (class in dissect.target.containers.vmdk) VMFS (class in acquire.acquire.acquire) (class in dissect.vmfs) (class in dissect.vmfs.vmfs) vmfs (in module dissect.target.volume) vmfs_def (in module dissect.vmfs.c_vmfs) VMFS_LVM_BASES (in module dissect.vmfs.lvm) VMFS_LVM_PE_SIZE (in module dissect.vmfs.lvm) vmfs_uuid() (in module dissect.vmfs.c_vmfs) VmfsFilesystem (class in dissect.target.filesystems.vmfs) VmfsFilesystemEntry (class in dissect.target.filesystems.vmfs) VmfsVolumeSystem (class in dissect.target.volumes.vmfs) VmtarFilesystem (class in dissect.target.filesystems.vmtar) VmwarevmLoader (class in dissect.target.loaders.vmwarevm) VMX (class in dissect.hypervisor.descriptor.vmx) VmxLoader (class in dissect.target.loaders.vmx) VoidType (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.voidtype) VOLATILE (in module acquire.acquire.acquire) VOLATILE_LINUX_PATHS (in module dissect.target.loaders.local) VolatileProfile (class in acquire.acquire.acquire) VolatileStream (class in acquire.acquire.volatilestream) VOLUME (class in dissect.target.plugins.os.windows.regf.shellbags) Volume (class in dissect.target.volume) volume_group (dissect.volume.lvm.metadata.HistoricalLogicalVolume property) (dissect.volume.lvm.metadata.LogicalVolume property) (dissect.volume.lvm.metadata.PhysicalVolume property) VOLUME_HEADER_OFFSET (in module dissect.volume.vss) volume_identifier (dissect.volume.vss.VSS property) VOLUME_LABEL_ENTRY (in module dissect.fat.c_exfat) volume_name() (dissect.ntfs.NTFS method) (dissect.ntfs.ntfs.NTFS method) volume_uuid (dissect.target.plugins.filesystem.ntfs.mft_timeline.Extras attribute) VolumeCollection (class in dissect.target.target) VolumeGroup (class in dissect.volume.lvm.metadata) VolumeNotAvailableError volumes (dissect.target.volume.VolumeSystem property) VolumeSection (class in dissect.evidence.ewf) VolumeSystem (class in dissect.target.volume) VolumeSystemError VolumeUnavailable VSS (class in dissect.volume.vss) vss_def (in module dissect.volume.vss) VSS_IDENTIFIER (in module dissect.volume.vss) VYOS (dissect.target.plugin.OperatingSystem attribute) VyosPlugin (class in dissect.target.plugins.os.unix.linux.debian.vyos._os) W W (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) WAIT_COMPLETION_PACKET (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) wait_for_quit() (acquire.acquire.gui.base.GUI method) (acquire.acquire.gui.base.Stub method) wait_for_start() (acquire.acquire.gui.base.GUI method) (acquire.acquire.gui.base.Stub method) WAL (class in dissect.sql) (class in dissect.sql.sqlite3) wal_checksum() (in module dissect.sql.sqlite3) WAL_HEADER_MAGIC (in module dissect.sql.c_sqlite3) WAL_HEADER_MAGIC_BE (in module dissect.sql.c_sqlite3) WAL_HEADER_MAGIC_LE (in module dissect.sql.c_sqlite3) WALCheckpoint (class in dissect.sql.sqlite3) WALFrame (class in dissect.sql.sqlite3) walk() (dissect.btrfs.tree.Cursor method) (dissect.evidence.ad1.AD1 method) (dissect.extfs.JDB2 method) (dissect.extfs.journal.JDB2 method) (dissect.ole.ole.DirectoryEntry method) (dissect.regf.regf.RegistryHive method) (dissect.regf.RegistryHive method) (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) (dissect.target.plugins.os.windows.regf.regf.RegfPlugin method) (in module dissect.target.helpers.fsutil) (in module dissect.target.tools.fs) walk_agi() (dissect.xfs.XFS method) (dissect.xfs.xfs.AllocationGroup method) (dissect.xfs.xfs.XFS method) walk_ext() (dissect.target.filesystem.Filesystem method) (dissect.target.filesystem.FilesystemEntry method) (in module dissect.target.helpers.fsutil) walk_extents() (dissect.xfs.XFS method) (dissect.xfs.xfs.AllocationGroup method) (dissect.xfs.xfs.XFS method) walk_large_tree() (dissect.xfs.XFS method) (dissect.xfs.xfs.XFS method) walk_small_tree() (dissect.xfs.XFS method) (dissect.xfs.xfs.XFS method) walk_tree() (dissect.xfs.xfs.AllocationGroup method) (in module dissect.sql.sqlite3) walkfs() (dissect.target.plugins.filesystem.walkfs.WalkFSPlugin method) WalkFSPlugin (class in dissect.target.plugins.filesystem.walkfs) was_path_seen() (acquire.acquire.collector.CollectionReport method) wb (flow.record.adapter.xlsx.XlsxWriter attribute) WBEM (class in acquire.acquire.acquire) WcharType (class in dissect.cstruct) (class in dissect.cstruct.types) (class in dissect.cstruct.types.wchartype) WebCache (class in dissect.target.plugins.apps.browser.iexplore) WebHosting (class in acquire.acquire.acquire) webkittimestamp() (in module dissect.util.ts) WebserverAccessLogRecord (in module dissect.target.plugins.apps.webserver.webserver) WebserverErrorLogRecord (in module dissect.target.plugins.apps.webserver.webserver) WebserverPlugin (class in dissect.target.plugins.apps.webserver.webserver) WeeklyTriggerRecord (in module dissect.target.plugins.os.windows.task_helpers.tasks_records) WER (class in acquire.acquire.acquire) wer() (dissect.target.plugins.os.windows.wer.WindowsErrorReportingPlugin method) WER_LOG_DIRS (dissect.target.plugins.os.windows.wer.WindowsErrorReportingPlugin attribute) WEVT (class in dissect.eventlog.wevt) wevt_headers() (dissect.eventlog.CRIM method) (dissect.eventlog.wevt.CRIM method) wevt_object_def (in module dissect.eventlog.wevt_object) wevt_objects (in module dissect.eventlog.wevt_object) WEVT_TYPE (class in dissect.eventlog.wevt) WevtName (class in dissect.eventlog.wevt_object) WevtNameReader (class in dissect.eventlog.bxml) WevtObject (class in dissect.eventlog.wevt_object) WevtutilWrapper (class in dissect.eventlog.wevtutil) wffirewall() (dissect.target.plugins.apps.av.trendmicro.TrendMicroPlugin method) wflogs() (dissect.target.plugins.apps.av.trendmicro.TrendMicroPlugin method) WHITE (dissect.target.helpers.cyber.Color attribute) WHITE_BRUSH (in module acquire.acquire.gui.win32), [1] WHITELIST (in module flow.record.whitelist) WHITELIST_TREE (in module flow.record.whitelist) WIM (class in dissect.archive.wim) wim_def (in module dissect.archive.c_wim) WIM_IMAGE_TAG (in module dissect.archive.c_wim) Win32 (class in acquire.acquire.gui.win32) win_10_path() (in module dissect.target.plugins.os.windows.regf.shimcache) win_8_path() (in module dissect.target.plugins.os.windows.regf.shimcache) WIN_DATETIME_FIELDS (dissect.esedb.tools.ual.UAL attribute) WinArpCache (class in acquire.acquire.acquire) WinDnsClientCache (class in acquire.acquire.acquire) WINDOWS (dissect.target.filesystems.cb.OS attribute) (dissect.target.plugin.OperatingSystem attribute) WINDOWS_10 (dissect.thumbcache.util.ThumbnailType attribute) WINDOWS_7 (dissect.thumbcache.util.ThumbnailType attribute) WINDOWS_81 (dissect.thumbcache.util.ThumbnailType attribute) WINDOWS_ACCESSORS (in module dissect.target.loaders.velociraptor) WINDOWS_DRIVE_FIXED (in module dissect.target.loaders.local) WINDOWS_ERROR_INSUFFICIENT_BUFFER (in module dissect.target.loaders.local) windows_path (class in flow.record.fieldtypes) WINDOWS_STATION (acquire.acquire.dynamic.windows.named_objects.NamedObjectType attribute) WINDOWS_VISTA (dissect.thumbcache.util.ThumbnailType attribute) WINDOWS_ZONE_MAP (in module dissect.target.helpers.localeutil) WindowsDynamicError WindowsErrorReportingPlugin (class in dissect.target.plugins.os.windows.wer) WindowsEventlogsMixin (class in dissect.target.plugins.os.windows.log.evt) WindowsKeyboardRecord (in module dissect.target.plugins.os.windows.locale) WindowsNotifications (class in acquire.acquire.acquire) WindowsPlugin (class in dissect.target.plugins.os.windows._os) WindowsProfile (class in acquire.acquire.acquire) WindowsTimezone (class in dissect.target.plugins.os.windows.datetime) WindowsUserRecord (in module dissect.target.helpers.record) WinMemDump (class in acquire.acquire.acquire) WinMemFiles (class in acquire.acquire.acquire) WinProcEnv (class in acquire.acquire.acquire) WinProcesses (class in acquire.acquire.acquire) winrar() (dissect.target.plugins.os.windows.generic.GenericPlugin method) WinRarRecord (in module dissect.target.plugins.os.windows.generic) WinRDPSessions (class in acquire.acquire.acquire) winsocknamespaceprovider() (dissect.target.plugins.os.windows.generic.GenericPlugin method) WinSockNamespaceProviderRecord (in module dissect.target.plugins.os.windows.generic) wintimestamp() (in module dissect.util.ts) WireGuardInterfaceRecord (in module dissect.target.plugins.apps.vpn.wireguard) WireGuardPeerRecord (in module dissect.target.plugins.apps.vpn.wireguard) WireGuardPlugin (class in dissect.target.plugins.apps.vpn.wireguard) with_metaclass() (in module flow.record.adapter) with_name() (dissect.target.helpers.compat.path_310.PureDissectPath method) (dissect.target.helpers.compat.path_311.PureDissectPath method) (dissect.target.helpers.compat.path_39.PureDissectPath method) with_segments() (dissect.target.helpers.compat.path_312.PureDissectPath method) with_stem() (dissect.target.helpers.compat.path_310.PureDissectPath method) (dissect.target.helpers.compat.path_311.PureDissectPath method) (dissect.target.helpers.compat.path_39.PureDissectPath method) with_suffix() (dissect.target.helpers.compat.path_310.PureDissectPath method) (dissect.target.helpers.compat.path_311.PureDissectPath method) (dissect.target.helpers.compat.path_39.PureDissectPath method) WM_CLOSE (in module acquire.acquire.gui.win32) WM_COMMAND (in module acquire.acquire.gui.win32) WM_CTLCOLORSTATIC (in module acquire.acquire.gui.win32) WM_DESTROY (in module acquire.acquire.gui.win32) WM_ENABLE (in module acquire.acquire.gui.win32) WM_PAINT (in module acquire.acquire.gui.win32) WM_SETFONT (in module acquire.acquire.gui.win32) WM_USER (in module acquire.acquire.gui.win32) WNDCLASSW (class in acquire.acquire.gui.win32) WNDPROC (in module acquire.acquire.gui.win32) WnfGuid (in module dissect.etl.utils) worker() (in module acquire.acquire.tools.decrypter) WORKER_COUNT (in module acquire.acquire.tools.decrypter) WorkstationChildTargetPlugin (class in dissect.target.plugins.child.vmware_workstation) wpndatabase() (dissect.target.plugins.os.windows.notifications.NotificationsPlugin method) WpnDatabaseNotificationHandlerRecord (in module dissect.target.plugins.os.windows.notifications) WpnDatabaseNotificationRecord (in module dissect.target.plugins.os.windows.notifications) wrap() (in module dissect.target.helpers.cache) WRAP_PASSCODE (dissect.target.loaders.itunes.ClassKey attribute) WrappedRecord (class in flow.record.selector) write() (acquire.acquire.crypt.EncryptedStream method) (acquire.acquire.outputs.base.Output method) (acquire.acquire.outputs.dir.DirectoryOutput method) (acquire.acquire.outputs.tar.TarOutput method) (acquire.acquire.outputs.zip.ZipOutput method) (dissect.cstruct.BaseType method) (dissect.cstruct.BitBuffer method) (dissect.cstruct.bitbuffer.BitBuffer method) (dissect.cstruct.Instance method) (dissect.cstruct.types.base.BaseType method) (dissect.cstruct.types.BaseType method) (dissect.cstruct.types.Instance method) (dissect.cstruct.types.instance.Instance method) (dissect.evidence.asdf.streams.CompressedStream method) (dissect.evidence.asdf.streams.Crc32Stream method) (dissect.evidence.asdf.streams.HashedStream method) (dissect.evidence.asdf.streams.SubStreamBase method) (dissect.target.helpers.cache.LineWriter method) (dissect.target.helpers.cyber.CyberIO method) (flow.record.adapter.AbstractWriter method) (flow.record.adapter.archive.ArchiveWriter method) (flow.record.adapter.avro.AvroWriter method) (flow.record.adapter.broker.BrokerWriter method) (flow.record.adapter.csvfile.CsvfileWriter method) (flow.record.adapter.elastic.ElasticWriter method) (flow.record.adapter.jsonfile.JsonfileWriter method) (flow.record.adapter.line.LineWriter method) (flow.record.adapter.mongo.MongoWriter method) (flow.record.adapter.split.SplitWriter method) (flow.record.adapter.splunk.SplunkWriter method) (flow.record.adapter.sqlite.SqliteWriter method) (flow.record.adapter.stream.StreamWriter method) (flow.record.adapter.text.TextWriter method) (flow.record.adapter.xlsx.XlsxWriter method) (flow.record.stream.PathTemplateWriter method) (flow.record.stream.RecordPrinter method) (flow.record.stream.RecordStreamWriter method) write_bytes() (acquire.acquire.collector.Collector method) (acquire.acquire.outputs.base.Output method) (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) write_entry() (acquire.acquire.outputs.base.Output method) (in module dissect.thumbcache.tools.utils) write_header() (acquire.acquire.crypt.EncryptedStream method) write_policy (dissect.volume.lvm.metadata.VdoPoolSegment attribute) write_text() (dissect.target.helpers.compat.path_310.TargetPath method) (dissect.target.helpers.compat.path_311.TargetPath method) (dissect.target.helpers.compat.path_312.TargetPath method) (dissect.target.helpers.compat.path_39.TargetPath method) write_volatile() (acquire.acquire.outputs.base.Output method) writeback_jobs (dissect.volume.lvm.metadata.WriteCacheSegment attribute) writebehind (dissect.volume.lvm.metadata.RAIDSegment attribute) writecache (dissect.volume.lvm.metadata.WriteCacheSegment attribute) writecache_block_size (dissect.volume.lvm.metadata.WriteCacheSegment attribute) writecache_setting_key (dissect.volume.lvm.metadata.WriteCacheSegment attribute) writecache_setting_val (dissect.volume.lvm.metadata.WriteCacheSegment attribute) WriteCacheSegment (class in dissect.volume.lvm.metadata) writeheader() (flow.record.stream.RecordStreamWriter method) writer (flow.record.adapter.archive.ArchiveWriter attribute) (flow.record.adapter.avro.AvroWriter attribute) (flow.record.adapter.split.SplitWriter attribute) WS_BORDER (in module acquire.acquire.gui.win32) WS_CHILD (in module acquire.acquire.gui.win32) WS_DISABLED (in module acquire.acquire.gui.win32) WS_OVERLAPPEDWINDOW (in module acquire.acquire.gui.win32) WS_VISIBLE (in module acquire.acquire.gui.win32) WSLChildTargetPlugin (class in dissect.target.plugins.child.wsl) wstring (in module flow.record.fieldtypes) wtmp() (dissect.target.plugins.os.unix.log.utmp.UtmpPlugin method) WTMP_GLOB (dissect.target.plugins.os.unix.log.utmp.UtmpPlugin attribute) WtmpRecord (in module dissect.target.plugins.os.unix.log.utmp) X X (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) x (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) XAttr (class in dissect.extfs.extfs) xattr (dissect.extfs.extfs.INode property) (dissect.extfs.INode property) XATTR_NAME_MAP (in module dissect.extfs.c_ext) XATTR_PREFIX_MAP (in module dissect.extfs.c_ext) XFS (class in dissect.xfs) (class in dissect.xfs.xfs) xfs_def (in module dissect.xfs.c_xfs) XFS_NULL (in module dissect.xfs.c_xfs) XfsFilesystem (class in dissect.target.filesystems.xfs) XfsFilesystemEntry (class in dissect.target.filesystems.xfs) xfstimestamp() (in module dissect.util.ts) XlsxReader (class in flow.record.adapter.xlsx) XlsxWriter (class in flow.record.adapter.xlsx) xmemoryview() (in module dissect.util.xmemoryview) Xml (class in dissect.target.helpers.configutil) xml_as_dict() (in module dissect.target.loaders.hyperv) XMLEntry (class in dissect.hypervisor.disk.hdd) XmlTask (class in dissect.target.plugins.os.windows.task_helpers.tasks_xml) xor32_crc() (in module dissect.regf.regf) XVA (class in dissect.hypervisor.backup.xva) XvaLoader (class in dissect.target.loaders.xva) XVAStream (class in dissect.hypervisor.backup.xva) Y Yaml (class in dissect.target.helpers.configutil) yara() (dissect.target.plugins.filesystem.yara.YaraPlugin method) YaraMatchRecord (in module dissect.target.plugins.filesystem.yara) YaraPlugin (class in dissect.target.plugins.filesystem.yara) year_rollover_helper() (in module dissect.target.helpers.utils) YELLOW (dissect.target.helpers.cyber.Color attribute) YUM_LOG_KEYWORDS (in module dissect.target.plugins.os.unix.linux.redhat.yum) YumPlugin (class in dissect.target.plugins.os.unix.linux.redhat.yum) Z Z (dissect.target.plugins.os.unix.linux.proc.ProcessStateEnum attribute) ZERO (in module dissect.target.plugins.os.windows.datetime) zero_new_blocks (dissect.volume.lvm.metadata.ThinPoolSegment attribute) ZERO_SUBCLUSTER_TYPES (in module dissect.hypervisor.disk.c_qcow2) ZeroSegment (class in dissect.volume.lvm.metadata) ZipFilesystem (class in dissect.target.filesystems.zip) ZipFilesystemDirectoryEntry (class in dissect.target.filesystems.zip) ZipFilesystemEntry (class in dissect.target.filesystems.zip) ZipOutput (class in acquire.acquire.outputs.zip) zla (dissect.vmfs.vmfs.FileDescriptor property) ZlibStream (class in dissect.util.stream) Zone (class in dissect.volume.raid.stream) zone_end (dissect.volume.raid.stream.Zone attribute) ZSTD (dissect.target.tools.dump.utils.Compression attribute) ZSTD_MAGIC (in module flow.record.base) ZypperPlugin (class in dissect.target.plugins.os.unix.linux.suse.zypper)