pkg.sopackage field notes

brew / Rang 2479

libewf mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für libewf in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install libewf

provider-native install command

Überblick

Paketzusammenfassung

Library for support of the Expert Witness Compression Format

Befehle und Aliase

  • ewfacquire
  • ewfacquirestream
  • ewfdebug
  • ewfexport
  • ewfinfo
  • ewfmount
  • ewfrecover
  • ewfverify

Verlauf

Projektgeschichte und Nutzung

libewf is the libyal library and tool suite for reading, writing, acquiring, verifying, exporting, and mounting Expert Witness Compression Format evidence files. Its package-manager identity is tied to digital forensics because EWF/E01 images are common interchange artifacts between acquisition tools, forensic suites, and open-source analysis workflows.

Projektgeschichte

Joachim Metz began documenting the EWF file format in March 2006, with libewf's legacy ChangeLog recording release-preparation work in April 2006. The project grew alongside a public working specification for the format, covering SMART, EnCase E01, logical evidence files, and later EWF2 variants.

The libyal repositories split the actively experimental libewf tree from a stable legacy tree. Homebrew's curation points at the legacy repository, while the project documentation and README describe the broader libewf effort.

Adoptionsgeschichte

EWF became important because forensic images produced by EnCase, FTK Imager, SMART, and related tools needed open readers and converters. libewf gave Unix package ecosystems a reusable C library plus tools such as ewfacquire, ewfinfo, ewfexport, ewfmount, and ewfverify.

Distribution packages under names such as libewf, ewf-tools, and ewftools made E01 handling available outside proprietary forensic workstations.

Wie es verwendet wird

Package users commonly install libewf for command-line acquisition and conversion, for mounting or inspecting EWF images, or as a dependency of forensic applications that need E01/S01/L01 support.

Warum Paket-Nerds sich dafür interessieren

libewf is package-nerd useful because it turns a proprietary-forensics file family into a normal Unix library and set of small tools. It also carries one of the clearest public format documents for EWF, making it useful to preservation, incident response, and forensic packaging work.

Zeitleiste

  • 2006-03: Initial public EWF specification revisions for the libewf project.
  • 2006-04: Legacy ChangeLog records first-release preparation and tool renames such as ewfcat to ewfexport and ewfmd5sum to ewfverify.
  • 2014: Legacy ChangeLog records stabilization work and synchronization with the experimental libewf tree.
  • 2026: The EWF specification document records maintenance through 2006-2026.

Related projects

  • Related projects include the libyal family of forensic libraries, The Sleuth Kit integrations, EnCase, FTK Imager, and forensic package sets that ship ewf-tools.

Sicherheitslage

Risikostufe: grün

library-like package without higher-risk signals.

Risikoklassifikator

grün Risiko · niedrig Konfidenz · appliance

Warum

  • library-like package without higher-risk signals

Signale

  • metadata:library-like

Installationsverhalten

  • Es wurden keine Homebrew-Bottle-Metadaten erfasst.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
ewfacquireExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
ewfacquirestreamExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
ewfdebugExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
ewfexportExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
ewfinfoExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
ewfmountExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
ewfrecoverExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.
ewfverifyExecutableindexiertes ExecutableAus dem lokalen Executable-Index erkannt.

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-08-03
Manager-Version20140816
Manager aktualisiert
lokale Datenunbekannt
Upstreamnicht verfügbar
neueste erkannte Versionnicht erkannt
  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:libewf
Version20140816
PaketmanagerHomebrew
Homepagehttps://github.com/libyal/libewf
Repositoryhttps://github.com/libyal/libewf
Bottlenicht erfasst
Dienstkeiner deklariert

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • curated package history
  • pkgdb category and tag curation