usbrip Logo

usbrip

0
Free
Visit Website

usbrip is a forensics tool with a command line interface for tracking USB device artifacts on Linux machines. It analyzes Linux log data and can build USB event history tables with details like connected/disconnected date & time, vendor ID, product ID, manufacturer, serial number, and port. It can export data as JSON, generate a list of authorized USB devices, and search for violation events.

FEATURES

ALTERNATIVES

A tool for parsing and extracting information from the Master File Table of NTFS file systems.

A library to access the Extensible Storage Engine (ESE) Database File (EDB) format used in various Windows applications.

Tool for analyzing Windows Recycle Bin INFO2 file

Tool for parsing NTFS journal files, $Logfile, and $MFT.

An open source format for storing digital evidence and data, with a C/C++ library for creating, reading, and manipulating AFF4 images.

A forensic research tool for gathering forensic traces on Android and iOS devices, supporting the use of public indicators of compromise.

A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.

Customizable live OS constructor tool for remote forensics and incident response.