Forensic disk images

Identifies forensic disk images patterns in security and access control contexts. Detects potential exposure of sensitive security information in Australian systems.

Type
regex
Engine
boost_regex
Confidence
medium
Confidence justification
structural regex with domain-specific anchors and constrained context replaces phrase-only marker.
Detection quality
Mixed
Jurisdictions
au
Regulations
Criminal Code Act 1995 (Cth), Evidence Act 1977 (Qld)
Frameworks
ISO 27001
Data categories
credentials, security
Scope
wide
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported

Pattern

(?is)\b(?:E01|\.E01\b|dd\s+image|forensic\s+image|disk\s+image)\b

Corroborative evidence keywords

forensic disk images, forensic, disk, images, security, operations, threat, data

Proximity: 300 characters

Should match

Should not match

Known false positives

References