Awesome-anti-forensic
Section: Analysis / Gathering tool (Know your ennemies) · Bulk Email and URL extraction tool.
Entry
Appears in 6 awesome lists
Computer forensics tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures. Because of ignoring the file system structure, the program distinguishes itself in terms of speed and thoroughness.
Section: Analysis / Gathering tool (Know your ennemies) · Bulk Email and URL extraction tool.
Section: Evidence Collection · Computer forensics tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures. Because of ignoring the file system structure, the program distinguishes itself in terms of speed and thoroughness.
Section: File Carving · Fast file carving tool.
Section: General · This is the development tree. For downloads please see:.
Section: Carving · Extracts informations like email adresses, creditscard numbers and histrograms of disk images
Section: General
Python based memory extraction and analysis framework.
The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
ir-rescue is a Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.
POSIX-compliant Bash script that scans a host for various signs of malware.
A free, community-sourced, machine-readable knowledge base of digital forensic artifacts.
Command line utility (that works with or without Amazon EC2 instances) to parallelize remote memory acquisition.
gem:; Collection of rules from Didier Stevens, author of a suite of tools for inspecting OLE/RTF/PDF. Didier's rules are worth scrutinizing and are generally written purposed towards hunting. New rules are frequently announced through the NVISO Labs Blog.
The Rekall Framework is a completely open collection of tools, implemented in Python under the Apache and GNU General Public License, for the extraction and analysis of digital artifacts computer systems.