FLAG was designed to simplify the process of log file analysis and forensic investigations. It uses a database as a backend to assist in managing the large volumes of data. This allows it to remain responsive and expedite data manipulation operations. It features compatibility with encase images, Windows registry support, and network dump analysis.
| Tags | Security |
|---|---|
| Licenses | GPL |
| Operating Systems | POSIX Linux |
| Implementation | Python |
Recent releases


Changes: This release features major improvements and bugfixes. An enhanced Virtual File System allows automatic searching/ scanning withing Zip files/PST files etc. The documentation is now much better, with a revamped Web site. A hooker library allows users to wrap any external program to work on Encase files.


Changes: Recursive scanner support was added. The scanners include virus scanning, NSRL hash comparison, PST files, and recursive zip files. The log file support was improved, and a powerful new GUI was included. The binary distribution now includes MySQL, making it totaly self contained and trivial to install.


No changes have been submitted for this release.