dcfldd Logo

dcfldd

0
Free
Visit Website

dcfldd is a modified version of GNU dd with added features such as hashing, fast disk wiping, and status output. Originally created by Nicholas Harbour from the DoD Computer Forensics Laboratory (DCFL), it is now maintained by him independently. The latest version can be found on GitHub at https://github.com/adulau/dcfldd/, which includes Debian patches and additional patches from Alexandre Dulaunoy.

FEATURES

ALTERNATIVES

A tool for discovering, analyzing, and remedying sensitive data

Create checkpoint snapshots of the state of running pods for later off-line analysis.

Yara pattern matching tool for forensic investigations with predefined rules for magic headers in files and raw images.

Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.

A library to access and parse OLE 2 Compound File (OLECF) format files.

A library and tools to access and analyze APFS file systems

Automated collection tool for incident response triage in Windows systems.

A library to access and parse Windows NT Registry File (REGF) format.

PINNED