📄 ils.1
字号:
.TH ILS 1 .SH NAMEils \- List inode information.SH SYNOPSIS.B ils [-emOpvV] [-f .I fstype.B ] [-s .I seconds.B ] [-i.I imgtype.B ] [-o.I imgoffset.B ].I image [images] [start-stop].B ils [-aAlLvVzZ] [-f.I fstype.B ] [-s.I seconds.B ] [-i.I imgtype.B ] [-o.I imgoffset.B ].I image [images] [start-stop].SH DESCRIPTION.B ilsopens the named .I image(s)and lists inode information. By default, .B ilslists only the inodes of removed files.Arguments:.IP \fB-e\fRList every inode in the file system..IP "\fB-f\fI fstype\fR"Specifies the file system type. Use '-f list' to list the supported file system types.If not given, autodetection methods are used..IP "\fB-s\fI seconds\fR"The time skew of the original system in seconds. For example, if theoriginal system was 100 seconds slow, this value would be -100. .IP \fB-m\fRDisplay the inode details in the format that the mactime program reads(replaces the ils2mac script from TCT).IP \fB-O\fRList only inodes of removed files that are still open or executing.This option is short-hand notation for \fB-aL\fR"(see the \fBfine controls\fR section below). (this used to be -o)..IP \fB-p\fRDisplay orphan inodes (unallocated with no file name).IP \fB-r\fR(default) List only inodes of removed files. This option is short-hand notationfor \fB-LZ\fR(see the \fBfine controls\fR section below)..IP "-i imgtype"Identify the type of image file, such as raw or split. Use '-i list' to list the supported types. If not given, autodetection methods are used..IP "-o imgoffset"The sector offset where the file system starts in the image. Non-512 bytesectors can be specified using '@' (32@2048)..IP \fB-v\fRTurn on verbose mode, output to stderr..IP \fB-V\fRDisplay Version..IP "image [images]"One (or more if split) disk or partition images whose format is given with '-i'..IP "\fIstart-stop\fR"Examine the specified inode number or number range. .PPFine controls:.IP \fB-a\fRList only allocated inodes: these belong to files with at least onedirectory entry in the file system, and to removed files thatare still open or executing..IP \fB-A\fRList only unallocated inodes: these belong to files that no longerexist..IP \fB-l\fRList only inodes with at least one hard link. These belong to fileswith at least one directory entry in the file system..IP \fB-L\fRList only inodes without any hard links. These belong to files that nolonger exist, and to removed files that are still open or executing..IP \fB-z\fRList only inodes with zero status change time. Presumably, theseinodes were never used..IP \fB-Z\fRList only inodes with non-zero status change time. Presumably, thesebelong to files that still exist, or that existed in the past..PPThe output format is in time machine format.The output begins with a two-line header thatdescribes the data origin, and is followed by a one-line headerthat lists the names of the data attributes that make up theremainder of the output:.IP st_inoThe inode number..IP st_allocAllocation status: `a' for allocated inode, `f' for free inode..IP st_uidOwner user ID..IP st_gidOwner group ID..IP st_mtimeUNIX time (seconds) of last file modification..IP st_atimeUNIX time (seconds) of last file access..IP st_ctimeUNIX time (seconds) of last inode status change..IP st_dtimeUNIX time (seconds) of file deletion (LINUX only)..IP st_modeFile type and permissions (octal)..IP st_nlinkNumber of hard links..IP st_sizeFile size in bytes..IP st_block0,st_block1The first two entries in the direct block address list..SH SEE ALSOmactime(1).SH LICENSEThis software is distributed under the IBM Public License..SH HISTORYFirst appeared in The Coroners Toolkit (TCT) 1.0..SH AUTHOR(S)Wietse VenemaIBM T.J. Watson ResearchP.O. Box 704Yorktown Heights, NY 10598, USAThis version is maintained by Brian Carrier (carrier at sleuthkit dot org)Send documentation updates to <doc-updates at sleuthkit dot org>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -