LfLe Logo

LfLe

0
Free
Visit Website

Recover event log entries from an image by heuristically looking for record structures. Dependencies: argparse (http://pypi.python.org/pypi/argparse available via easy_install/pip). Usage: Use this tool to extract event log messages from an image file by looking for things that appear to be records. Then, feed the resulting file into an event log viewer, such as Event Log Explorer (http://www.eventlogxp.com/, use 'direct' mode when opening). Sample Output: evt/LfLe - [master●] » python lfle.py '/media/truecrypt2/VM/Windows XP Professional - Service Pack 3 - TEMPLATE/Windows XP Professional - Service Pack 3-cl1.vmdk' recovered.evt 100% complete% done. Wrote 5413 records. Skipped 48 records with length greater than 0x10000. Skipped 12.

FEATURES

ALTERNATIVES

Tool for live forensics acquisition on Windows systems, collecting artefacts for early compromise detection.

Recreates the File/Directory tree structure from an extracted $MFT file with detailed record mapping and analysis capabilities.

LiME is a Linux Memory Extractor tool for acquiring volatile memory from Linux and Linux-based devices, including Android, with features like full memory captures and minimal process footprint.

Visually inspect regex matches in binary data/text with YARA and regular expressions, displaying matched bytes and surrounding context.

Toolkit for post-mortem analysis of Docker runtime environments using forensic HDD copies.

Open source Python library for NTFS analysis

A Python tool for in-depth PDF analysis and modification.

Orochi is a collaborative forensic memory dump analysis framework.