aff4 / pyaff4
The Python implementation of the AFF4 standard.
☆45Updated 6 months ago
Related projects ⓘ
Alternatives and complementary repositories for pyaff4
- AFF4 Standard Documents☆26Updated 2 years ago
- A fork of The Sleuthkit with Pooled Storage and APFS support. See https://www.youtube.com/watch?v=k1XPillJ7aw for more info and usage.☆26Updated 5 years ago
- Yet another registry parser☆130Updated 2 years ago
- Extract common Windows artifacts from source images and VSCs☆65Updated 3 years ago
- It is based on bulk_extractor (https://github.com/simsong/bulk_extractor) and add scanners for record carving☆37Updated 4 years ago
- A rewrite of mactime, a bodyfile reader☆36Updated 3 months ago
- Papers and Presentations from the DFRWS Conferences☆19Updated 2 years ago
- Different DFIR and CTI utilities☆36Updated 4 years ago
- Volatility plugins created by the author☆44Updated 9 years ago
- Example programs used in the automating DFIR series☆64Updated 5 years ago
- Python library for parsing AccessData AD1 images☆29Updated last year
- Converting data from services like Censys and Shodan to a common data model☆48Updated 2 months ago
- Command line utility and Python package to ease the (un)mounting of forensic disk images☆120Updated last year
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated last year
- Open source training materials for law-enforcement and organisations interested in DFIR.☆56Updated 2 months ago
- Digital Forensics Windows Registry (dfWinReg)☆49Updated last month
- Specifications used in the MISP project including MISP core format☆46Updated last month
- Python bindings for The Sleuth Kit (libtsk)☆93Updated last month
- This is a GUI (for Windows 64 bit) for a procedure to virtualize your EWF(E01), DD (raw), AFF disk image file without converting it, dire…☆50Updated 5 years ago
- Digital Forensic Investigative Scripts☆72Updated this week
- Yara-Endpoint is a tool useful for incident response as well as anti-malware enpoint base on Yara signatures.☆104Updated 6 years ago
- Script that checks for available updates for the most commonly used Digital Forensics tools☆57Updated 3 years ago
- Python bindings for https://github.com/omerbenamram/evtx/☆49Updated 2 weeks ago
- Simple yara rule manager☆65Updated last year
- Connect your mail client/infrastructure to MISP in order to create events based on the information contained within mails.☆69Updated last year
- Documentation site for Velociraptor☆37Updated last week
- Registry Explorer bookmark definitions☆41Updated last year
- ☆31Updated last month