Factual Rules Generator Logo

Factual Rules Generator

0
Free
Visit Website

Factual Rules Generator is an open source project that generates YARA rules about installed software from a running operating system. The software aims to use a set of rules against collected digital forensic evidences to find installed software efficiently. It can be used to baseline known software from Windows systems and create rules for identifying similar installations on other systems. Dependencies include pefile, psutil, ndjson, python-tlsh, PyInstaller, ssdeep, and additional tools like xxd and curl.

FEATURES

ALTERNATIVES

Collects and organizes Linux OS data for detailed analysis and incident response.

A comprehensive incident response tool for Windows computers, providing advanced memory forensics and access to locked systems.

An open source format for storing digital evidence and data, with a C/C++ library for creating, reading, and manipulating AFF4 images.

Python tool for remotely or locally dumping RAM of a Linux client for digital forensics analysis.

A suite of console tools for working with timestamps in Windows with 100-nanosecond precision.

A cybersecurity tool for collecting and analyzing forensic artifacts on live systems.

An anti-forensic Linux Kernel Module kill-switch for USB ports.

DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved