DFTimewolf Logo

DFTimewolf

0
Free
Visit Website

DFTimewolf is a framework for orchestrating forensic collection, processing, and data export. It consists of collectors, processors, and exporters (modules) that pass data on to one another. The orchestration of modules is defined in predefined 'recipes'. Documentation is hosted on GitHub pages.

FEATURES

ALTERNATIVES

A script to assist in creating templates for VirtualBox to enhance VM detection evasion.

An open source format for storing digital evidence and data, with a C/C++ library for creating, reading, and manipulating AFF4 images.

A collaborative forensic timeline analysis tool for organizing and analyzing data with rich annotations and comments.

An anti-forensic kill-switch tool for USB ports to shut down the computer immediately in case of unauthorized access.

A Forensic Framework for Skype with various investigative options.

A framework/scripting tool to standardize and simplify the process of scripting favorite Live Acquisition utilities for Incident Responders.

IE10Analyzer can parse and recover records from WebCacheV01.dat, providing detailed information and conversion capabilities.

ForensicMiner, Redefine DFIR Automations