dcfldd Logo

dcfldd

0
Free
Visit Website

dcfldd is a modified version of GNU dd with added features such as hashing, fast disk wiping, and status output. Originally created by Nicholas Harbour from the DoD Computer Forensics Laboratory (DCFL), it is now maintained by him independently. The latest version can be found on GitHub at https://github.com/adulau/dcfldd/, which includes Debian patches and additional patches from Alexandre Dulaunoy.

FEATURES

ALTERNATIVES

An open source format for storing digital evidence and data, with a C/C++ library for creating, reading, and manipulating AFF4 images.

Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.

GUI-based memory forensic capture tool for cyber forensics and cyber crime investigation.

A bash script for automating Linux swap analysis for post-exploitation or forensics purposes.

A command-line utility for extracting human-readable text from binary files.

A library to access and parse OLE 2 Compound File (OLECF) format files.

Digital investigation tool for extracting forensic data from computers and managing investigations.

A library to access the Extensible Storage Engine (ESE) Database File (EDB) format used in various Windows applications.