DFTimewolf is a framework for orchestrating forensic collection, processing, and data export. It consists of collectors, processors, and exporters (modules) that pass data on to one another. The orchestration of modules is defined in predefined 'recipes'. Documentation is hosted on GitHub pages.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Stegextract is a Bash script that extracts hidden files and strings from images, supporting PNG, JPG, and GIF formats.
TestDisk is a free data recovery software that can recover lost partitions and undelete files from various file systems.
Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.
A PowerShell-based incident response and live forensic data acquisition tool for Windows hosts.
A library to access FileVault Drive Encryption (FVDE) encrypted volumes on Mac OS X systems.
Zenduty's platform provides real-time operational health monitoring and incident response orchestration to improve incident response times and build a solid on-call culture.
A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.
A library to access and parse Windows XML Event Log (EVTX) format, useful for digital forensics and incident response.