Factual Rules Generator Logo

Factual Rules Generator

0
Free
Visit Website

Factual Rules Generator is an open source project that generates YARA rules about installed software from a running operating system. The software aims to use a set of rules against collected digital forensic evidences to find installed software efficiently. It can be used to baseline known software from Windows systems and create rules for identifying similar installations on other systems. Dependencies include pefile, psutil, ndjson, python-tlsh, PyInstaller, ssdeep, and additional tools like xxd and curl.

FEATURES

ALTERNATIVES

Analyzing WiFiConfigStore.xml file for digital forensics on Android devices.

Automated collection tool for incident response triage in Windows systems.

Open Source computer forensics platform with modular design for easy automation and scripting.

A binary analysis platform for analyzing binary programs

A forensic tool to find hidden processes and TCP/UDP ports by rootkits or other hidden techniques.

A tool for parsing and extracting information from the Master File Table of NTFS file systems.

A cross-platform registry hive editor for forensic analysis with advanced features like hex viewer and reporting engine.

Web interface for the Volatility Memory Analysis framework with advanced features.