Factual Rules Generator Logo

Factual Rules Generator

0
Free
Visit Website

Factual Rules Generator is an open source project that generates YARA rules about installed software from a running operating system. The software aims to use a set of rules against collected digital forensic evidences to find installed software efficiently. It can be used to baseline known software from Windows systems and create rules for identifying similar installations on other systems. Dependencies include pefile, psutil, ndjson, python-tlsh, PyInstaller, ssdeep, and additional tools like xxd and curl.

FEATURES

ALTERNATIVES

Yara pattern matching tool for forensic investigations with predefined rules for magic headers in files and raw images.

Exiv2 is a C++ library and command-line utility for image metadata manipulation.

A framework for orchestrating forensic collection, processing, and data export.

An extensible network forensic analysis framework with deep packet analysis and plugin support.

A python module for orchestrating content acquisitions and analysis via Amazon SSM.

A command-line utility to show and change EXIF information in JPEG files

An open source digital forensic tool for processing and analyzing digital evidence with high performance and multiplatform support.

A collection of Mac OS X and iOS forensics resources with a focus on artifact collection and collaboration.

PINNED