hashlookup-forensic-analyser Logo

hashlookup-forensic-analyser

0
Free
Updated 11 March 2025
Visit Website

Analyse a forensic target (such as a directory) to find and report files found and not found from CIRCL hashlookup public service or the Bloom filter from CIRCL hashlookup. This tool can help a digital forensic investigator to know the context, origin of specific files during a digital forensic investigation. The project is a component of the hashlookup.io project. Usage: hashlookup-analyser.py [-h] [-v] [--extended-debug] [--progress] [--disable-progress] [-d DIR] [--report] [--live-linux] [--print-all] [--print-unknown] [--include-stats] [--format FORMAT] [--cache] [--bloomfilters BLOOMFILTERS [BLOOMFILTERS ...]] [--bloomfilter-algorithm BLOOMFILTER_ALGORITHM] [--bloomfilters-lower-case] Analyse a forensic target to find and report files found and not found in hashlookup CIRCL public service. Optional arguments: -h, --help show this help message and exit -v, --verbose Verbose output. --extended-debug Debug file processed along with the mode and type. --progress Print progress of the file lookup on stderr. --disable-progress Disable printing progress of the file lookup on stderr. -d DIR, --dir DIR Directory to analyse. --report Generate a report

FEATURES

SIMILAR TOOLS

Yara pattern matching tool for forensic investigations with predefined rules for magic headers in files and raw images.

A reliable end-to-end DFIR solution for boosting cyber incident response and forensics capacity.

Recover event log entries from an image by heuristically looking for record structures.

A command-line utility to show and change EXIF information in JPEG files

Hindsight is a free tool for analyzing web artifacts from Google Chrome/Chromium browsers and presenting the data in a timeline for forensic analysis.

RegRippy is a modern Python 3 alternative to RegRipper for extracting data from Windows registry hives.

Highlighter is a FireEye Market app that integrates with FireEye products to provide enhanced cybersecurity capabilities.

A suite of console tools for working with timestamps in Windows with 100-nanosecond precision.

Toolkit for performing acquisitions on iOS devices with logical and filesystem acquisition support.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

Copyright © 2025 - All rights reserved