Digital forensics, at scale

Find evidence in every byte.

bulk_extractor rapidly scans disk images, files, and directories for structured forensic evidence without relying on file-system structure.

Documentation

Start with the user manual for practical and investigative use, then use the programmer's manual when extending or maintaining the project.

PDF manual

User Manual

Understand, build, configure, run, tune, and interpret bulk_extractor through practical forensic workflows and worked investigations.

Open user manual (PDF)
PDF manual

Programmer's Manual

Architecture, API, concurrency, output, examples, testing, and implementation guidance for contributors and maintainers.

Open programmer's manual (PDF)
Reference

Scanner API

Authoritative guidance for developing a scanner or loadable scanner plug-in.

Read the Scanner API ↗

Explore the project

bulk_extractor is open source, actively tested on current macOS and Ubuntu environments, and designed to make extracted evidence easy to inspect and use in downstream analysis.