pkg.sopackage field notes

brew / rank 2799

Install foremost with Homebrew

Console program to recover files based on their headers and footers. Version 1.5.7 via Homebrew; verified from local package data.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install foremost

provider-native install command

overview

Package summary

Console program to recover files based on their headers and footers

Commands and aliases

  • foremost

history

Project history and usage

Foremost is a console data-carving utility for recovering files from disk images, raw drives, and forensic images by matching file headers, footers, and internal structures.

Project history

The upstream site says Foremost was originally developed by the United States Air Force Office of Special Investigations and the Center for Information Systems Security Studies and Research, then opened to the general public.

The bundled README credits Special Agents Kris Kendall and Jesse Kornblum of the USAF Office of Special Investigations, starting in March 2001, and says the project was inspired by CarvThis from the Defense Computer Forensic Lab.

Adoption history

Foremost's adoption is tied to digital forensics workflows rather than a single language ecosystem. The official site advertises use on images from tools such as dd, Safeback, and EnCase, and links to DFRWS challenge material and sample carving test images.

It is packaged broadly across Unix package managers because it is a small C command-line tool with a stable forensic niche: file recovery by signatures without depending on a full forensic suite.

How it is used

Foremost can scan a disk image or drive directly, write recovered files to an output directory, and use built-in file-type detectors or a configuration file that defines extensions, case sensitivity, maximum size, headers, and optional footers.

If no configuration file is specified, the manual says Foremost first checks foremost.conf in the current directory and then /etc/foremost.conf.

Why package nerds care

Foremost is a classic package-manager utility: small, scriptable, old, and still useful because it implements one forensic primitive well.

Its configuration-file format is significant for package users because distributions can ship a system-wide foremost.conf while investigators can keep case-specific signatures beside evidence images.

Timeline

  • 1999: CarvThis from the Defense Computer Forensic Lab inspires the project.
  • 2001: Foremost development starts at the USAF Office of Special Investigations.
  • 2002: The SourceForge project metadata records public project hosting beginning in April 2002.
  • 2006: The official site links Foremost material for the DFRWS 2006 challenge.
  • 2007: The official site links Foremost material for the DFRWS 2007 challenge.
  • 2009: Foremost 1.5.7 is published as the latest upstream source archive on the project site.

Related projects

  • Foremost is related to forensic imaging tools such as dd, Safeback, and EnCase as input sources for evidence images.
  • Its README names CarvThis as an inspiration, placing Foremost in the older data-carving lineage of command-line forensic recovery tools.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
./foremost.conf/etc/foremost.conf

executables

Installed executables

CommandKindExposureNote
foremostexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version1.5.7
manager updated
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:foremost
Version1.5.7
Package managerHomebrew
Homepagehttps://foremost.sourceforge.net/
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation