Forensic Diff
Purpose
Forensic Diff — Forensics surface.
When to use it
- Operate Forensic Diff when your job matches this surface
- Prefer dry-run / doctor before mutating repairs on disks
- Shut down the guest before write operations
How to get there
- Doc id:
forensic-diff - Nav: Forensics → Forensic Diff
- Primary interface:
guestkit forensic-diff OLD NEW·diff/compare
Operate from CLI / TUI (UX)
guestkit forensic-diff OLD NEW·diff/compare.- Snapshot before/after.
forensic-diff before.qcow2 after.qcow2.-o jsonfor drift score.- Lighter:
guestkit diff a b. - Fleet continuous:
fleet watch. - Empty / fail: Identical images → low drift; mount fail on either side.
- Success: Drift findings / security indicators JSON.
Host needs Linux + qemu-img / losetup / qemu-nbd; mount/repair often need root. GuestKit does not invent disk contents.