Digital forensics, at scale

Find evidence in every byte.

bulk_extractor rapidly scans disk images, files, and directories for structured forensic evidence—without relying on file-system structure.

Documentation

Start with the operating guide for practical use, then use the developer manual when extending or maintaining the project.

PDF manual

Current Operating Guide

Build, configure, and run bulk_extractor for forensic investigation workflows.

Open operating guide (PDF)
Reference

Scanner API

Authoritative guidance for developing a scanner or loadable scanner plug-in.

Read the Scanner API ↗

Explore the project

bulk_extractor is open source, actively tested on current macOS and Ubuntu environments, and designed to make extracted evidence easy to inspect and use in downstream analysis.