# Sleuthkit/Autospy with BTRFS support ?

**URL:** <https://sleuthkit.discourse.group/t/sleuthkit-autospy-with-btrfs-support/3854>\
**Category:** Autopsy Help\
**Created:** [July 19, 2023, 1:12pm UTC](https://sleuthkit.discourse.group/t/sleuthkit-autospy-with-btrfs-support/3854 "2023-07-19T13:12:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![e-ferrari](https://avatars.discourse-cdn.com/v4/letter/e/898d66/32.png) [@e-ferrari](https://sleuthkit.discourse.group/u/e-ferrari)\
**Post date:** [July 19, 2023, 1:12pm UTC](https://sleuthkit.discourse.group/t/sleuthkit-autospy-with-btrfs-support/3854/1 "2023-07-19T13:12:44Z")

</div>

I’m completely new to forensic. Sorry if i ask obvious stuff.  
I have a BTRFS volume i’d like to examine. But what is about BTRFS support ?  
I found [GitHub - shujianyang/btrForensics: Forensic Analysis Tool for Btrfs File System.](https://github.com/shujianyang/btrForensics) , but the project seems to be dead. Last commits 5 years ago. Does Sleuthkit or Autospy now have BTRFS support ?

Thanks.

Bernd

---

<div class="post-metadata">

**Author:** ![Richard](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/richard/32/1847_2.png) [@Richard](https://sleuthkit.discourse.group/u/Richard)\
**Post date:** [July 19, 2023, 2:22pm UTC](https://sleuthkit.discourse.group/t/sleuthkit-autospy-with-btrfs-support/3854/2 "2023-07-19T14:22:57Z")

</div>

I would look at ways to mount a BTRFS in Windows, once you have mounted the volume, then you can image it and process the image in Autopsy.  
This looks useful:

> **[GitHub - maharmstone/btrfs: WinBtrfs - an open-source btrfs driver for Windows](https://github.com/maharmstone/btrfs)**
>
> WinBtrfs - an open-source btrfs driver for Windows - GitHub - maharmstone/btrfs: WinBtrfs - an open-source btrfs driver for Windows

FTK imager is a good tool for imaging a volume once you have it mounted.
