pkg.sopackage field notes

brew / 排名 2479

使用 Homebrew 安装 libewf

查看 libewf 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

安装

其他安装命令

macOS

Homebrew已验证 · 100%
brew install libewf

provider-native install command

概览

软件包摘要

Library for support of the Expert Witness Compression Format

命令和别名

  • ewfacquire
  • ewfacquirestream
  • ewfdebug
  • ewfexport
  • ewfinfo
  • ewfmount
  • ewfrecover
  • ewfverify

历史

项目历史与用法

libewf is the libyal library and tool suite for reading, writing, acquiring, verifying, exporting, and mounting Expert Witness Compression Format evidence files. Its package-manager identity is tied to digital forensics because EWF/E01 images are common interchange artifacts between acquisition tools, forensic suites, and open-source analysis workflows.

项目历史

Joachim Metz began documenting the EWF file format in March 2006, with libewf's legacy ChangeLog recording release-preparation work in April 2006. The project grew alongside a public working specification for the format, covering SMART, EnCase E01, logical evidence files, and later EWF2 variants.

The libyal repositories split the actively experimental libewf tree from a stable legacy tree. Homebrew's curation points at the legacy repository, while the project documentation and README describe the broader libewf effort.

采用历史

EWF became important because forensic images produced by EnCase, FTK Imager, SMART, and related tools needed open readers and converters. libewf gave Unix package ecosystems a reusable C library plus tools such as ewfacquire, ewfinfo, ewfexport, ewfmount, and ewfverify.

Distribution packages under names such as libewf, ewf-tools, and ewftools made E01 handling available outside proprietary forensic workstations.

使用方式

Package users commonly install libewf for command-line acquisition and conversion, for mounting or inspecting EWF images, or as a dependency of forensic applications that need E01/S01/L01 support.

为什么软件包爱好者会关心

libewf is package-nerd useful because it turns a proprietary-forensics file family into a normal Unix library and set of small tools. It also carries one of the clearest public format documents for EWF, making it useful to preservation, incident response, and forensic packaging work.

时间线

  • 2006-03: Initial public EWF specification revisions for the libewf project.
  • 2006-04: Legacy ChangeLog records first-release preparation and tool renames such as ewfcat to ewfexport and ewfmd5sum to ewfverify.
  • 2014: Legacy ChangeLog records stabilization work and synchronization with the experimental libewf tree.
  • 2026: The EWF specification document records maintenance through 2006-2026.

Related projects

  • Related projects include the libyal family of forensic libraries, The Sleuth Kit integrations, EnCase, FTK Imager, and forensic package sets that ship ewf-tools.

安全态势

风险级别:绿色

library-like package without higher-risk signals.

风险分类器

绿色 风险 · 低 置信度 · appliance

原因

  • library-like package without higher-risk signals

信号

  • metadata:library-like

安装行为

  • 未记录 Homebrew bottle 元数据。

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

可执行文件

已安装的可执行文件

命令类型暴露范围备注
ewfacquire可执行文件已索引可执行文件从本地可执行文件索引发现。
ewfacquirestream可执行文件已索引可执行文件从本地可执行文件索引发现。
ewfdebug可执行文件已索引可执行文件从本地可执行文件索引发现。
ewfexport可执行文件已索引可执行文件从本地可执行文件索引发现。
ewfinfo可执行文件已索引可执行文件从本地可执行文件索引发现。
ewfmount可执行文件已索引可执行文件从本地可执行文件索引发现。
ewfrecover可执行文件已索引可执行文件从本地可执行文件索引发现。
ewfverify可执行文件已索引可执行文件从本地可执行文件索引发现。

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-08-03
管理器版本20140816
管理器更新时间
本地数据未知
上游不可用
检测到的最新版本未检测到
  • OK没有生成新鲜度警告。

安装元数据

软件包元数据

软件包键brew:libewf
版本20140816
软件包管理器Homebrew
主页https://github.com/libyal/libewf
仓库https://github.com/libyal/libewf
Bottle未记录
服务未声明

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Geiger risk classifier
  • Nucleus package database
  • curated package history
  • pkgdb category and tag curation