Truehunter Logo

Truehunter

0
Free
Updated 11 March 2025
Visit Website

The goal of Truehunter is to detect encrypted containers using a fast and memory efficient approach without any external dependencies for ease of portability. It was designed to detect Truecrypt and Veracrypt containers, however it may detect any encrypted file with a 'header' not included in its database. Truehunter performs the following checks: Test the first 8 bytes of the file against its own database. File size modulo 64 must be zero. Calculates file entropy. Truehunter is part of BlackArch forensic tools. Installation: Any Python version from 2.7-3.7 should work, it does not need any additional libraries. Usage: The headers database file will be created with the first use, and can be updated after every scan. Note this is not a correct header database, just the first 8 bytes of every file, extension and date (It does the job as a PoC). Fast Scan: Searches for files with a size % 64 = 0 (block ciphers), unknown headers and appearing less than MAXHEADER value (default 3). Default Scan: Performs a fast scan and calculates the entropy of the resulting files to reduce false positives. Usage: truehunter.py [-h] [-D HEADERSFILE] [-m MINSIZ

FEATURES

SIMILAR TOOLS

Fridump is an open source memory dumping tool using the Frida framework for dumping memory addresses from various platforms.

A recognition framework for identifying products, services, operating systems, and hardware by matching fingerprints against network probes.

A repository containing material from a talk on sub-domain enumeration techniques

A console program for file recovery through data carving.

DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.

A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.

Windows event log fast forensics timeline generator and threat hunting tool.

A library to access and parse OLE 2 Compound File (OLECF) format files.

A library to access and manipulate RAW image files.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved