usbrip is a command-line forensics tool designed for tracking USB device artifacts on Linux systems. The tool analyzes Linux log data to reconstruct USB device connection history and activity. Key capabilities include: - Building comprehensive USB event history tables with detailed device information - Tracking connected and disconnected timestamps for USB devices - Recording vendor ID, product ID, manufacturer details, and serial numbers - Monitoring USB port usage and device assignments - Exporting forensic data in JSON format for further analysis - Generating authorized USB device lists for compliance purposes - Searching for policy violation events and unauthorized device usage The tool operates through a command-line interface and focuses specifically on Linux-based systems for USB forensic analysis. It processes system logs to extract USB-related events and presents the information in structured formats suitable for digital forensic investigations.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A library and set of tools for accessing and analyzing storage media devices and partitions for forensic analysis and investigation.
A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.
A library for accessing and parsing Microsoft Internet Explorer cache files (index.dat) to extract URLs, timestamps, and cached content for digital forensic analysis.
A PowerShell-based incident response and live forensic data acquisition tool for Windows hosts.
A digital forensics tool that provides read-only access to file-system objects from various storage media types and file formats.
Exterro is a data risk management platform that optimizes e-discovery, digital forensics, and cybersecurity compliance operations.
A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.
TestDisk is a free data recovery software that can recover lost partitions and undelete files from various file systems.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.