Versions:

  • 0.8.5
  • 0.8.3

disk4n6 is a forensic disk analyzer published by SecurityRonin, currently at version 0.8.5 with two versions recorded in the catalog. The software is designed to decode forensic disk images and live devices, map partitions, and flag anomalies, placing it within the digital forensics and disk analysis category. It supports a broad range of disk image formats, including E01, VMDK, VHDX, VHD, QCOW2, DMG, raw dd, and ISO files, allowing analysts to work with evidence captured through many common acquisition and virtualization workflows. Once an image is loaded, disk4n6 automatically detects the partitioning scheme in use, recognizing MBR, GPT, and APM layouts, and routes ISO 9660 media to dedicated filesystem analysis. When run with no arguments, the tool enumerates the host's physical disks and partitions, presenting a proportional partition-layout view alongside acquisition-integrity findings that help examiners assess the reliability of captured data. This cross-platform enumeration capability operates across macOS, Linux, and Windows, making the utility suitable for heterogeneous investigative environments where examiners must inspect whatever system is at hand. Typical use cases include forensic examination of acquired disk images, verification of partition structures during evidence triage, identification of anomalous or unexpected regions on storage devices, and live inspection of a host machine's storage configuration. By combining multi-format image decoding, automatic partition scheme detection, integrity reporting, and zero-configuration host enumeration in a single tool, disk4n6 serves incident responders, forensic analysts, and security practitioners who need rapid, structured insight into disk layouts and image contents without switching between separate utilities for different formats or operating systems.

Tags: