Digital forensics Institution-led
usbsas
Linux tool for forensic examination of untrusted USB devices, with read-only mounting, disk imaging and controlled file transfer.
By CEA IT Security · France
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Digital forensics
- Developer or maintainer
- CEA IT Security
- Recorded country
- France
- Product model
- Open source
- Deployment
- Desktop/CLI
- Software license
- GPL-3.0-or-later
- Upstream status
- Active
- Evidence class
- Institution-led
What the sources establish
Origin noteDeveloped in CEA IT Security, the French Alternative Energies and Atomic Energy Commission security group.
Reported capabilities
- Supports forensic analysis of untrusted USB mass-storage devices.
- Can mount a device read-only and create a device image.
- Separates parsing tasks into restricted user-space processes.
Scope and limits
Requires physical access to the USB medium and a compatible GNU/Linux host; a focused evidence-intake tool, not an end-to-end DFIR platform.
Inspect the research evidence 2 source observations
identity / capabilities / deployment / license
README says GNU/Linux Rust software for secure reading of untrusted USB devices, expressly includes forensic analysis as a use case, lists read-only mount and imaging, and grants GPL version 3 or any later version.
Read sourceorigin / country / maintenance
CEA IT Security identifies its affiliation with the French national commission; its repository list shows usbsas updated 8 October 2026.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.
A digital forensics triage and evidence workflow