dcfldd is a modified version of GNU dd with added features such as hashing, fast disk wiping, and status output. Originally created by Nicholas Harbour from the DoD Computer Forensics Laboratory (DCFL), it is now maintained by him independently. The latest version can be found on GitHub at https://github.com/adulau/dcfldd/, which includes Debian patches and additional patches from Alexandre Dulaunoy.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A command-line utility and Python package for mounting and unmounting various disk image formats with support for different volume systems and filesystems.
A forensic analysis tool that extracts and parses logs, notifications, and system information from iOS/iPadOS devices and backups.
A forensic research tool for gathering forensic traces on Android and iOS devices, supporting the use of public indicators of compromise.
Malscan is a tool to scan process memory for YARA matches and execute Python scripts.
wxHexEditor is a free hex editor / disk editor with various data manipulation operations and visualization functionalities.
A simple Golang application for storing NIST National Software Reference Library Reference Data Set (NSRL RDS) with md5 and sha1 hash lookup searches.
Recreates the File/Directory tree structure from an extracted $MFT file with detailed record mapping and analysis capabilities.
Rekall is a discontinued project that aimed to improve memory analysis methodology but faced challenges due to the nature of in-memory structure and increasing security measures.
A cross-platform registry hive editor for forensic analysis with advanced features like hex viewer and reporting engine.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.