Factual Rules Generator Logo

Factual Rules Generator

0
Free
Visit Website

Factual Rules Generator is an open source project that generates YARA rules about installed software from a running operating system. The software aims to use a set of rules against collected digital forensic evidences to find installed software efficiently. It can be used to baseline known software from Windows systems and create rules for identifying similar installations on other systems. Dependencies include pefile, psutil, ndjson, python-tlsh, PyInstaller, ssdeep, and additional tools like xxd and curl.

FEATURES

ALTERNATIVES

Windows anti-forensics USB monitoring tool with the ability to shutdown the computer upon detecting the unplugging of a specified USB device.

Online platform for image steganography analysis

ID-spoofing NFS client

Visually inspect regex matches in binary data/text with YARA and regular expressions, displaying matched bytes and surrounding context.

A tool for creating compact Linux memory dumps compatible with popular debugging tools.

Tool for live forensics acquisition on Windows systems, collecting artefacts for early compromise detection.

A Forensic Framework for Skype with various investigative options.

A software utility with forensic tools for smartphones, offering powerful data extraction and decoding capabilities.