IRTriage Logo

IRTriage

0
Free
Visit Website

Incident Response Triage is a scripted collection tool that automatically runs as an administrator in Windows versions, except WinXP, to gather system information valuable to a Forensic Analyst. It collects system information, network information, registry hives, disk information, and dumps memory, providing fast forensics in situations where a full disk image is not feasible.

FEATURES

ALTERNATIVES

A library to access and parse Windows XML Event Log (EVTX) format, useful for digital forensics and incident response.

wxHexEditor is a free hex editor / disk editor with various data manipulation operations and visualization functionalities.

A tool for fixing acquired .evt Windows Event Log files in digital forensics.

DMG2IMG is a tool for converting Apple compressed dmg archives to standard image disk files with support for zlib, bzip2, and LZFSE compression.

A tool that uses Plaso to parse forensic artifacts and disk images, creating custom reports for easier analysis.

Turbinia is an open-source framework for automating the running of common forensic processing tools to help with processing evidence in the Cloud.

A command-line utility and Python package for mounting and unmounting various disk image formats with support for different volume systems and filesystems.

Create checkpoint snapshots of the state of running pods for later off-line analysis.

PINNED