Silk Guardian is an anti-forensic Linux Kernel Module (LKM) kill-switch that monitors USB ports for changes, deletes files, and shuts down the computer. It was inspired by usbkill and serves as a fun project for learning. The tool is designed to prevent unauthorized access to the system and enhance security, especially in scenarios where physical access to the machine is a concern. To run Silk Guardian, compile the module using 'make', load it using 'sudo insmod silk.ko', and ensure the linux-headers package is installed. It is recommended to use (partial) disk encryption in conjunction with this tool for enhanced protection.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A library to access the Extensible Storage Engine (ESE) Database File (EDB) format used in various Windows applications.
A library to access FileVault Drive Encryption (FVDE) encrypted volumes on Mac OS X systems.
An open source format for storing digital evidence and data, with a C/C++ library for creating, reading, and manipulating AFF4 images.
Exterro is a data risk management platform that optimizes e-discovery, digital forensics, and cybersecurity compliance operations.
A library to access and read QEMU Copy-On-Write (QCOW) image file formats with support for zlib compression and AES-CBC encryption.
A comprehensive incident response tool for Windows computers, providing advanced memory forensics and access to locked systems.
A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.
Stegextract is a Bash script that extracts hidden files and strings from images, supporting PNG, JPG, and GIF formats.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.