Linux Expl0rer Logo

Linux Expl0rer

0
Free
Visit Website

Easy-to-use live forensics toolbox for Linux endpoints written in Python & Flask. Capabilities: - View full process list - Inspect process memory map & fetch memory strings easily - Dump process memory in one click - Automatically search hash in public services (VirusTotal, Intezer, Analyze AlienVault OTX, MalShare) - Users list find - Search for suspicious files by name/regex - netstat - Whois - Logs: syslog, auth.log (user authentication log), ufw.log (firewall log), bash history - Anti-rootkit chkrootkit - YARA: Scan a file or directory using YARA signatures by @Neo23x0, Scan a running process memory address space, Upload your own YARA signature Requirements: Python 3.6 Installation: - wget https://github.com/intezer/linux-explorer/archive/master.zip -O master.zip - unzip master.zip - cd linux-explorer-master - ./deploy.sh Usage: Start your browser firefox http://127.0.0.1:8080 Configure API keys (optional): - nano config.py - Edit following lines: INTEZER_APIKEY = '<key>', VT_APIKEY = '<key>', OTX_APIKEY = '<key>', MALSHARE_APIKEY = '<key>' Notes: We recommend using NGINX reverse proxy with basic http auth & ssl for secure remote access. Tested with Ubuntu 16.04 Misc: "How to"

FEATURES

ALTERNATIVES

A command-line utility and Python package for mounting and unmounting various disk image formats with support for different volume systems and filesystems.

Review of various MFT parsers used in digital forensics for analyzing NTFS file systems.

Second-order subdomain takeover scanner

A console program for file recovery through data carving.

mXtract is a Linux-based tool for memory analysis and dumping with regex pattern search capabilities.

Yara pattern matching tool for forensic investigations with predefined rules for magic headers in files and raw images.

A free, open-source file data recovery software that can recover lost files from hard disks, CD-ROMs, and digital camera memory.

ID-spoofing NFS client