Factual Rules Generator Logo

Factual Rules Generator

0
Free
Visit Website

Factual Rules Generator is an open source project that generates YARA rules about installed software from a running operating system. The software aims to use a set of rules against collected digital forensic evidences to find installed software efficiently. It can be used to baseline known software from Windows systems and create rules for identifying similar installations on other systems. Dependencies include pefile, psutil, ndjson, python-tlsh, PyInstaller, ssdeep, and additional tools like xxd and curl.

FEATURES

ALTERNATIVES

A repository containing material from a talk on sub-domain enumeration techniques

PowerForensics is a PowerShell digital forensics framework for hard drive forensic analysis.

RegRippy is a modern Python 3 alternative to RegRipper for extracting data from Windows registry hives.

A tool for discovering, analyzing, and remedying sensitive data

A modified version of GNU dd with added features like hashing and fast disk wiping.

A DFVFS backed viewer project with a WxPython GUI, aiming to enhance file extraction and viewing capabilities.

GVfs is a userspace virtual filesystem implementation for GIO with various backends and features.

Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.