Skip to content

Entry

bulk_extractor

Appears in 6 awesome lists

Computer forensics tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures. Because of ignoring the file system structure, the program distinguishes itself in terms of speed and thoroughness.

Open github.comsimsong/bulk_extractor

Found in these lists

Awesome-anti-forensic

Section: Analysis / Gathering tool (Know your ennemies) · Bulk Email and URL extraction tool.

StaleScore 50

Awesome Incident Response

Section: Evidence Collection · Computer forensics tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures. Because of ignoring the file system structure, the program distinguishes itself in terms of speed and thoroughness.

ActiveScore 82

Awesome Malware Analysis

Section: File Carving · Fast file carving tool.

StaleScore 58

Awesome Termux Hacking

Section: General · This is the development tree. For downloads please see:.

StaleScore 47

Forensics Tools

Section: Carving · Extracts informations like email adresses, creditscard numbers and histrograms of disk images

ActiveScore 77

Security lists for SOC/DFIR detections

Section: General

FreshScore 84

Volatility

Python based memory extraction and analysis framework.

In 8 listsDetails

Sleuthkit

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

In 4 lists

ir-rescue

ir-rescue is a Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

In 4 lists

Rootkit Hunter (rkhunter)

POSIX-compliant Bash script that scans a host for various signs of malware.

In 5 lists

Forensic Artifacts

A free, community-sourced, machine-readable knowledge base of digital forensic artifacts.

In 3 lists

Margarita Shotgun

Command line utility (that works with or without Amazon EC2 instances) to parallelize remote memory acquisition.

In 3 lists

Emldump

gem:; Collection of rules from Didier Stevens, author of a suite of tools for inspecting OLE/RTF/PDF. Didier's rules are worth scrutinizing and are generally written purposed towards hunting. New rules are frequently announced through the NVISO Labs Blog.

In 3 lists

Rekall

The Rekall Framework is a completely open collection of tools, implemented in Python under the Apache and GNU General Public License, for the extraction and analysis of digital artifacts computer systems.

In 3 lists