hashlookup-forensic-analyser Logo

hashlookup-forensic-analyser

0
Free
Visit Website

Analyse a forensic target (such as a directory) to find and report files found and not found from CIRCL hashlookup public service or the Bloom filter from CIRCL hashlookup. This tool can help a digital forensic investigator to know the context, origin of specific files during a digital forensic investigation. The project is a component of the hashlookup.io project. Usage: hashlookup-analyser.py [-h] [-v] [--extended-debug] [--progress] [--disable-progress] [-d DIR] [--report] [--live-linux] [--print-all] [--print-unknown] [--include-stats] [--format FORMAT] [--cache] [--bloomfilters BLOOMFILTERS [BLOOMFILTERS ...]] [--bloomfilter-algorithm BLOOMFILTER_ALGORITHM] [--bloomfilters-lower-case] Analyse a forensic target to find and report files found and not found in hashlookup CIRCL public service. Optional arguments: -h, --help show this help message and exit -v, --verbose Verbose output. --extended-debug Debug file processed along with the mode and type. --progress Print progress of the file lookup on stderr. --disable-progress Disable printing progress of the file lookup on stderr. -d DIR, --dir DIR Directory to analyse. --report Generate a report

FEATURES

ALTERNATIVES

A toolkit for forensic analysis of network appliances with YARA decoding options and frame extraction capabilities.

A library for working with Windows NT data types, providing access and manipulation functions.

Create checkpoint snapshots of the state of running pods for later off-line analysis.

MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.

A tool for creating compact Linux memory dumps compatible with popular debugging tools.

iOS Mobile Backup Xtractor tool for extracting iOS backups.

A tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container, aiding in digital forensic triage.

A forensic tool to find hidden processes and TCP/UDP ports by rootkits or other hidden techniques.