DFIR ORC Logo

DFIR ORC

0
Free
Visit Website

Build Branch Status: - main release/10.1 - release/10.2 Requirements: - Visual Studio From 2017 to 2022 - English only (vcpkg limitation) Use this installer configuration or alternatively use vstools. Check also 'Desktop development with C++'. Kitware's CMake >= 3.25 or Visual Studio integrated version. Build environment can be setup quickly using Microsoft's developer virtual machines. Import this .vsconfig from Visual Studio Installer. Commands: - Both 32-bit and 64-bit versions should be built for maximum compatibility before deployment. - See https://dfir-orc.github.io for more details about deployment and configuration. In a prompt like Developer Command Prompt for VS 2019 (prefer to avoid using cmd.exe): - git clone --recursive https://github.com/dfir-orc/dfir-orc.git - cd dfir-orc - mkdir build-x86 build-x64 - cd build-x86 - cmake -G 'Visual Studio 17 2022' -A Win32 -T v141_xp .. - cmake --build . --config MinSizeRel -- -maxcpucount - cd ../build-x64 - cmake -G 'Visual Studio 17 2022' -A x64 -T v141_xp .. - cmake --build . --config MinSizeRel -- -maxcpucount The -T v141_xp option will allow compatibility with Windows XP SP2 and later, it can safely be removed if not needed.

FEATURES

ALTERNATIVES

DMG2IMG is a tool for converting Apple compressed dmg archives to standard image disk files with support for zlib, bzip2, and LZFSE compression.

LiME is a Linux Memory Extractor tool for acquiring volatile memory from Linux and Linux-based devices, including Android, with features like full memory captures and minimal process footprint.

CyLR is a Live Response Collection tool for quickly and securely collecting forensic artifacts from hosts with NTFS file systems.

A binary analysis platform for analyzing binary programs

A library and tools to access and analyze APFS file systems

Exterro is a data risk management platform that optimizes e-discovery, digital forensics, and cybersecurity compliance operations.

Python script to parse macOS MRU plist files into human-friendly format

A Python-based engine for automatic creation of timelines in digital forensic analysis