RSS 12 projects tagged "Forensics"

No download Website Updated 16 Aug 2009 LibForensics

Screenshot
Pop 26.61
Vit 37.11

LibForensics is a framework for developing digital forensics applications in Python.

No download No website Updated 26 May 2010 libpff

Screenshot
Pop 39.87
Vit 1.55

libpff is a library and tools to access the Personal Folder File (PFF) and the Offline Folder File (OFF) format. PFF is used by Outlook in PAB (Personal Address Book), PST (Personal Storage Table), and OST (Offline Storage Table) files.

Download No website Updated 14 Jan 2010 FileExtractor

Screenshot
Pop 33.05
Vit 35.06

FileExtractor is a tool for recovering files from a binary data source. It is useful when sources such as digital cameras, partitions, hard drives, memory sticks, or floppy disks are corrupted, deleted, or formatted by mistake.

No download No website Updated 24 Nov 2010 CarvPath

Screenshot
Pop 48.28
Vit 1.61

CarvPath (libcarvpath) is a library aimed at computer forensic tools that process disk and/or memory dump images or other large data files. The library allows the creation and manipulation of CarvPath annotations, which are a way to annotate partitions, files, alternate streams, processes etc. within a disk or memory image as a string. Entities within a CarvPath notation can be fragmented and/or nested, and allow for the expression of 'sparse' fragments within an entity. The CarvPath annotations resemble a path string in a filesystem, and thus present a basis for the interaction between computer forensics tools and the CarvPath-based user space file-system, CarvFs.

No download No website Updated 24 Nov 2010 CarvFS

Screenshot
Pop 54.92
Vit 1.97

CarvFS is a user space FUSE filesystem aimed at computer forensic tools that process disk and/or memory dump images or other large data files. The filesystem allows CarvPath-aware tools to use CarvPath annotations as a way to designate partitions, files, alternate streams, processes etc. within a disk or memory image as a string, making them available trough the filesystem as a pseudo file that can be handed to other tools. This removes the need to copy the information out of the disk image and reduces storage requirements.

Download Website Updated 14 Feb 2013 mount_dd

Screenshot
Pop 127.11
Vit 4.11

Mount_dd is a GUI for mounting a raw image in Gnome. You can mount a dd-image in read-write or read-only mode. You can mount ISO, .img, raw, .00x formats, EWF, and AFF in read-only mode. You can also mount exfat partitions in read-only mode.

Download No website Updated 30 Jul 2010 mbrChunker

Screenshot
Pop 101.38
Vit 2.03

mbrChunker is a utility that allows you to mount raw disk images (created by dd, dcfldd, dc3dd, ftk imager, etc.) and create VMDK files. It does this by taking the raw image, analyzing the master boot record (physical sector 0), and getting specific information that is need to create a working VMDK file that points to your raw image. It can also extract information such as heads, cylinders, and sectors per track. With version 0.3.15, the tool now has the ability to search for hex byte offsets within any binary file. It will give you the byte location for every hex pattern found. More information about this can be found in the README.

Download No website Updated 24 Dec 2011 NetXtract

Screenshot
Pop 61.73
Vit 1.04

Xtract attempts to demonstrate how Wireshark's powerful network traffic analysis capabilities can be combined with the file carving capabilities of programs such as Foremost and NetworkMiner in a manner that is portable and extensible (hence the choice of Perl). Specifically, it offers automated extraction of network stream sessions; visualization of networks via GraphViz; and integration of file carving capability. The scripts are intended as a proof-of-concept for how tedious tasks of reassembling TCP/UDP streams from network capture files and file carving based on these streams can be automated.

Download No website Updated 13 Nov 2011 XtractCarver

Screenshot
Pop 30.98
Vit 23.61

Xtract attempts to demonstrate how Wireshark's powerful network traffic analysis capabilities can be combined with the file carving capabilities of programs such as Foremost and NetworkMiner in a manner that is portable and extensible (hence the choice of Perl). Specifically, it offers: automated extraction of network stream sessions; visualization of networks via GraphViz; and integration of file carving capability. The scripts are intended as a proof-of-concept for how tedious tasks of reassembling TCP/UDP streams from network capture files and file carving based on these streams can be automated.

Download Website Updated 13 Mar 2013 Fortools_dd

Screenshot
Pop 160.32
Vit 2.03

Fortools_dd is a set of forensic apps, created with zenity, for terminal commandos and bash scripts in Linux. It includes Mount_dd (a mounting images app), kijknekerap (a Dutch Terminal app), fgrep_dd (grep apps), convert_dd (a conversion app for aff > dd > EWF), shred_dd (a shredding app), filecopy_dd (a search-and-copy app), forensic_wine_dd (a Windows software with Wine app), reportmaker_dd (a small reportmaking app), Browserhistory_dd (a history app), and Offsetgrabber_dd (an offset viewing app).

Screenshot

Project Spotlight

Gearmand

A job dispatching server.

Screenshot

Project Spotlight

TreeLine

A tree-structured information storage program.