PDF manual
Current Operating Guide
Build, configure, and run bulk_extractor for forensic investigation workflows.
Open operating guide (PDF)bulk_extractor rapidly scans disk images, files, and directories for structured forensic evidence—without relying on file-system structure.
Start with the operating guide for practical use, then use the developer manual when extending or maintaining the project.
Build, configure, and run bulk_extractor for forensic investigation workflows.
Open operating guide (PDF)Architecture and implementation guidance for contributors and maintainers.
Open developer manual (PDF)Authoritative guidance for developing a scanner or loadable scanner plug-in.
Read the Scanner API ↗bulk_extractor is open source, actively tested on current macOS and Ubuntu environments, and designed to make extracted evidence easy to inspect and use in downstream analysis.