dcfldd Logo

dcfldd

0
Free
Visit Website

dcfldd is a modified version of GNU dd with added features such as hashing, fast disk wiping, and status output. Originally created by Nicholas Harbour from the DoD Computer Forensics Laboratory (DCFL), it is now maintained by him independently. The latest version can be found on GitHub at https://github.com/adulau/dcfldd/, which includes Debian patches and additional patches from Alexandre Dulaunoy.

FEATURES

ALTERNATIVES

Web interface for the Volatility Memory Analysis framework with advanced features.

MalConfScan is a Volatility plugin for extracting configuration data of known malware and analyzing memory images.

A network forensics toolkit that transforms network traffic data into graph-based representations for interactive analysis and visualization through a web interface.

Recover event log entries from an image by heuristically looking for record structures.

A tool for fixing acquired .evt Windows Event Log files in digital forensics.

RegRippy is a modern Python 3 alternative to RegRipper for extracting data from Windows registry hives.

WinSearchDBAnalyzer can parse and recover records in Windows.edb, providing detailed insights into various data types.

Create checkpoint snapshots of the state of running pods for later off-line analysis.