Factual Rules Generator Logo

Factual Rules Generator

0
Free
Visit Website

Factual Rules Generator is an open source project that generates YARA rules about installed software from a running operating system. The software aims to use a set of rules against collected digital forensic evidences to find installed software efficiently. It can be used to baseline known software from Windows systems and create rules for identifying similar installations on other systems. Dependencies include pefile, psutil, ndjson, python-tlsh, PyInstaller, ssdeep, and additional tools like xxd and curl.

FEATURES

ALTERNATIVES

Hoarder is a tool to collect and parse windows artifacts.

A forensic tool to find hidden processes and TCP/UDP ports by rootkits or other hidden techniques.

Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.

A library to access and parse Windows XML Event Log (EVTX) format, useful for digital forensics and incident response.

OSXCollector is a forensic evidence collection & analysis toolkit for OSX.

A forensic analysis tool that extracts and parses logs, notifications, and system information from iOS/iPadOS devices and backups.

Tool used for dumping memory from Android devices with root access requirement and forensic soundness considerations.

mXtract is a Linux-based tool for memory analysis and dumping with regex pattern search capabilities.

PINNED