Digital forensics Institution-led

usbsas

Linux tool for forensic examination of untrusted USB devices, with read-only mounting, disk imaging and controlled file transfer.

By CEA IT Security · France

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
CEA IT Security
Recorded country
France
Product model
Open source
Deployment
Desktop/CLI
Software license
GPL-3.0-or-later
Upstream status
Active
Evidence class
Institution-led

What the sources establish

Origin note

Developed in CEA IT Security, the French Alternative Energies and Atomic Energy Commission security group.

Reported capabilities

  • Supports forensic analysis of untrusted USB mass-storage devices.
  • Can mount a device read-only and create a device image.
  • Separates parsing tasks into restricted user-space processes.

Scope and limits

Requires physical access to the USB medium and a compatible GNU/Linux host; a focused evidence-intake tool, not an end-to-end DFIR platform.

Inspect the research evidence 2 source observations
  1. identity / capabilities / deployment / license

    README says GNU/Linux Rust software for secure reading of untrusted USB devices, expressly includes forensic analysis as a use case, lists read-only mount and imaging, and grants GPL version 3 or any later version.

    Read source
  2. origin / country / maintenance

    CEA IT Security identifies its affiliation with the French national commission; its repository list shows usbsas updated 8 October 2026.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow