$npx skillfedfor your agent

dissect.target

This module ties all other Dissect modules together, it provides a programming API and command line tools which allow easy access to various data sources inside disk images or file collections (a.k.a. targets)

With conditionsPyPI UtilitiesReleased Feb 2026528.8K downloads / moAGPL-3.0-or-laterPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — dissect_target-3.25.1-py3-none-any.whl
v3.25.1 · released 2026-02-25 · Python >=3.10 · 12 runtime deps: defusedxml, dissect.cstruct, dissect.database, dissect.eventlog, dissect.evidence, dissect.hypervisor, dissect.ntfs, dissect.regf

Yes, if you work in digital forensics or incident response. The package is actively maintained, has no known vulnerabilities, and provides a well-designed abstraction over complex forensic formats. The AGPL license is appropriate for internal tools and open-source projects but incompatible with proprietary distribution. Install with caution in closed-source environments or verify licensing constraints with your organization.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Some plugins (e.g., YARA support) require optional dependencies installed separately.
  • Low friction installation as a pure Python wheel.

License · maintenance · safety

AGPL-3.0-or-later (agpl) — AGPL-3.0-or-later: copyleft license requiring derivative works to be released under the same terms and source code to be made available to users. Suitable for internal tools and open-source projects; not compatible with proprietary closed-source distribution.

last release 2026-02-25 (170 days) · last repo commit 2026-08-12 · 90 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 528,755 downloads/mo, #6,162 on PyPI

Verify before relying

pip install dissect.target

from dissect.target import Target

target = Target.open('/path/to/target.vmdk')
for fs in target.filesystems:
    print(fs)
  • Whether all 12 runtime dependencies are required for basic functionality or if some are optional/plugin-specific
  • Performance characteristics when working with large disk images or many targets
  • Compatibility with specific forensic image formats beyond the examples in the description
Same gist for agents: .md · .json

What it is and what it does

dissect.target is a forensic analysis framework that unifies access to various data sources in disk images, virtual machine snapshots, and file collections. It sits atop a collection of specialized Dissect modules (for NTFS, registry, event logs, hypervisors, and more) and exposes them through a consistent programming API and a suite of command-line tools. The package is designed for digital forensics and incident response workflows where analysts need to extract, query, and export evidence from diverse target formats.

The framework provides both programmatic access for custom analysis scripts and ready-made tools like target-query (for running plugin functions), target-shell (for interactive filesystem exploration), target-reg (for Windows registry inspection), and target-mount (for mounting filesystems). It handles the complexity of parsing different image formats and filesystem types, allowing users to focus on the forensic questions rather than format-specific parsing details.

Use it for

  • Query Windows event logs, PowerShell history, and command artifacts across multiple disk images using target-query plugins
  • Interactively explore a suspect disk image filesystem and registry using target-shell commands like ls, cat, and registry
  • Export forensic records (timelines, artifacts, logs) from targets to compressed archives for reporting with target-dump
  • Mount a forensic image to your analysis machine for direct filesystem access without modifying the original evidence
  • Develop custom Python scripts that parse and correlate data across multiple evidence sources using the dissect.target API

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you work in digital forensics or incident response.

The package is actively maintained, has no known vulnerabilities, and provides a well-designed abstraction over complex forensic formats. The AGPL license is appropriate for internal tools and open-source projects but incompatible with proprietary distribution. Install with caution in closed-source environments or verify licensing constraints with your organization.

Install

dissect-target on PyPI

Before you install

Low friction installation as a pure Python wheel. Active maintenance with recent commits and stable production status. Requires Python 3.10 or later.

Requires Python 3.10 or later. Some plugins (e.g., YARA support) require optional dependencies installed separately.

License in practice

AGPL-3.0-or-later: copyleft license requiring derivative works to be released under the same terms and source code to be made available to users. Suitable for internal tools and open-source projects; not compatible with proprietary closed-source distribution.

Quickstart

pip install dissect.target

from dissect.target import Target

target = Target.open('/path/to/target.vmdk')
for fs in target.filesystems:
    print(fs)

Verify before relying

  • Whether all 12 runtime dependencies are required for basic functionality or if some are optional/plugin-specific
  • Performance characteristics when working with large disk images or many targets
  • Compatibility with specific forensic image formats beyond the examples in the description

Package facts

LicenseAGPL-3.0-or-later agpl
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
12 packages
defusedxmldissect.cstructdissect.databasedissect.eventlogdissect.evidencedissect.hypervisordissect.ntfsdissect.regfdissect.utildissect.volumeflow.recordstructlog
MaintenanceActively maintained 170 days since the last release
Last repo commit
First released
Downloads528,755 / month, #6,162 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyOperating System :: OS IndependentProgramming Language :: Python :: 3Topic :: Internet :: Log AnalysisTopic :: Scientific/Engineering :: Information AnalysisTopic :: SecurityTopic :: Utilities

Evidence: dissect_target-3.25.1-py3-none-any.whl

Tags

Capabilities
disk image forensic analysisparse vmdk e01 targetsforensic evidence extractiondigital forensics frameworkquery disk image datatarget filesystem accessforensic artifact parsing
Topics
forensicsincident-responsedisk-imaging

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “disk image forensic analysis”

  • dissect.targetdissect.target provides a unified API and command-line tools to parse…
  • acquireAcquire gathers forensic artifacts from disk images or live systems…
  • dissect.hypervisorParses hypervisor disk, backup, and configuration files from various…

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also dissect.hypervisor · acquire · dissect.volume · dissect.util · dissect.ntfs · dissect.cstruct · yara-x · parsedmarc · extractcode · developer-disk-image