Category: app-forensics
Search
Compact View
app-forensics/RdpCacheStitcher::hamari
- Ebuilds: 2, Testing: 1.1 , Snapshot: 9999
Description: A tool that supports reconstructing useful images out of RDP cache bitmaps.
Homepage: https://github.com/BSI-Bund/RdpCacheStitcher
License: GPL-3+ LGPL-3+
app-forensics/acstore::pkalin
- Ebuilds: 1, Testing: 20240407
Description: A stand-alone implementation to read and write Attribute Container stores
Homepage: https://github.com/log2timeline/acstore
License: Apache-2.0
app-forensics/afflib::gentoo
- Ebuilds: 2, Stable: 3.7.22 , Testing: 3.7.22
Description: Library that implements the AFF image standard
Homepage: https://github.com/sshock/AFFLIBv3/
License: BSD
app-forensics/afl::gentoo
- Ebuilds: 1, Testing: 2.57b
Description: american fuzzy lop - compile-time instrumentation fuzzer
Homepage: https://lcamtuf.coredump.cx/afl/
License: Apache-2.0
app-forensics/aflplusplus::gentoo
- Ebuilds: 3, Stable: 4.32c , Testing: 4.35c
Description: Fork of AFL, the popular compile-time instrumentation fuzzer
Homepage: https://github.com/AFLplusplus/AFLplusplus
License: Apache-2.0
aide (available in: app-forensics/aide::gentoo , app-forensics/aide::inode64-overlay )
- Ebuilds: 4, Stable: 0.18.8 , Testing: 0.19.4 , 0.18.8
Description: AIDE (Advanced Intrusion Detection Environment) is a file integrity checker
Homepage: https://aide.github.io/ https://github.com/aide/aide
License: GPL-2+
app-forensics/analyzemft::pentoo
- Ebuilds: 1, Stable: 3.1.1 , Testing: 3.1.1
Description: Analyze the MFT from a NTFS filesystem
Homepage: https://github.com/rowingdude/analyzeMFT
License: MIT
app-forensics/bindiff::ngg
- Ebuilds: 1, Stable: 8
Description: Comparison tool for binary files
Homepage: https://github.com/google/bindiff/
License: Apache-2.0
app-forensics/brakeman::graaff
- Ebuilds: 3, Testing: 7.1.2
Description: Static analysis tool which checks RoR applications for security vulnerabilities
Homepage: https://brakemanscanner.org/
License: BPUL
app-forensics/bulk_extractor::pentoo
- Ebuilds: 2, Stable: 2.1.1 , Testing: 2.2.0
Description: Scans a disk image for regular expressions and other content
Homepage: https://github.com/simsong/bulk_extractor
License: GPL-2
app-forensics/chkrootkit::gentoo
- Ebuilds: 2, Stable: 0.58b , Testing: 0.59
Description: Tool to locally check for signs of a rootkit
Homepage: https://www.chkrootkit.org/
License: BSD-2
app-forensics/cmospwd::gentoo
- Ebuilds: 1, Stable: 5.1
Description:
CmosPwd decrypts password stored in cmos used to access BIOS SETUP.
Works with the following BIOSes
- ACER/IBM BIOS
- AMI BIOS
- AMI WinBIOS 2.5
- Award 4.5x/4.6x/6.0
- Compaq (1992)
- Compaq (New version)
- IBM (PS/2, Activa, Thinkpad)
- Packard Bell
- Phoenix 1.00.09.AC0 (1994), a486 1.03, 1.04, 1.10 A03, 4.05 rev 1.02.943, 4.06 rev 1.13.1107
- Phoenix 4 release 6 (User)
- Gateway Solo - Phoenix 4.0 release 6
- Toshiba
- Zenith AMI
Homepage: https://www.cgsecurity.org/wiki/CmosPwd
License: GPL-2
dfvfs (available in: app-forensics/dfvfs::pentoo , app-forensics/dfvfs::pkalin )
- Ebuilds: 3, Stable: 20251019 , Testing: 20260731
Description: Digital Forensics Virtual File System (dfVFS)
Homepage: https://github.com/log2timeline/dfvfs
License: Apache-2.0
dfwinreg (available in: app-forensics/dfwinreg::pentoo , app-forensics/dfwinreg::pkalin )
- Ebuilds: 4, Testing: 20260411
Description: Digital Forensics Windows Registry (dfWinReg)
Homepage: https://github.com/log2timeline/dfwinreg
License: Apache-2.0
app-forensics/dfxml::gentoo
- Ebuilds: 1, Testing: 20170921
Description: Digital Forensics XML
Homepage: https://github.com/simsong/dfxml
License: LGPL-3
app-forensics/examiner::gentoo
- Ebuilds: 1, Stable: 0.5
Description: Utilizes the objdump command to disassemble and comment foreign binaries
Homepage: http://www.academicunderground.org/examiner/
License: GPL-2+
app-forensics/fatback::mva
- Ebuilds: 1, Testing: 1.3
Description: Tool to undelete files from FAT file systems
Homepage: https://fatback.sourceforge.net/
License: GPL-2
app-forensics/foremost::gentoo
- Ebuilds: 1, Stable: 1.5.7 , Testing: 1.5.7
Description: Console program to recover files based on their headers and footers
Homepage: https://foremost.sourceforge.net/
License: public-domain
app-forensics/ftimes::pkalin
- Ebuilds: 2, Testing: 3.13.0
Description: A system baselining and evidence collection tool
Homepage: http://ftimes.sourceforge.net/FTimes/
License: BSD
app-forensics/galleta::gentoo
- Ebuilds: 1, Stable: 20040505_p1 , Testing: 20040505_p1
Description: IE Cookie Parser
Homepage: https://sourceforge.net/projects/odessa/
License: BSD
app-forensics/gitleaks::nest
- Ebuilds: 2, Testing: 8.30.1 , Snapshot: 9999
Description:
A tool for searches full repo history for secrets and keys.
in all commits on all branches in topological order with
regex/entropy checks
Homepage: https://github.com/gitleaks/gitleaks
License: MIT
app-forensics/hindsight::pkalin
- Ebuilds: 2, Snapshot: 9999
Description: Internet history forensics for Google Chrome/Chromium
Homepage: https://github.com/obsidianforensics/hindsight
License: Apache-2.0
honggfuzz (available in: app-forensics/honggfuzz::gentoo , app-forensics/honggfuzz::ngg )
- Ebuilds: 2, Testing: 2.6 , Snapshot: 9999
Description: A general purpose fuzzer with feedback support
Homepage: https://honggfuzz.dev/
License: Apache-2.0
app-forensics/inception::pentoo
- Ebuilds: 1, Testing: 0.4.2
Description: Firewire physical memory manipulation tool exploiting IEEE 1394 SBP-2 DMA
Homepage: http://www.breaknenter.org/projects/inception/
License: GPL-3
app-forensics/kerbrute::nest
- Ebuilds: 2, Testing: 1.0.3_p20201116 , Snapshot: 9999
Description:
A tool for searches full repo history for secrets and keys.
in all commits on all branches in topological order with
regex/entropy checks
Homepage: https://github.com/ropnop/kerbrute
License: Apache-2.0
app-forensics/lazagne::pentoo
- Ebuilds: 2, Testing: 2.4.3 , Snapshot: 9999
Description: Credentials recovery project
Homepage: https://github.com/AlessandroZ/LaZagne
License: LGPL-3 GPL-3 MIT
libbde (available in: app-forensics/libbde::pentoo , app-forensics/libbde::pkalin )
- Ebuilds: 2, Stable: 20240502 , Testing: 20240502
Virtual
Description: Library and tools to access BitLocker Drive Encryption (BDE) encrypted volumes
Homepage: https://github.com/libyal/libbde
License: LGPL-3
libbfio (available in: app-forensics/libbfio::pentoo , app-forensics/libbfio::pkalin )
- Ebuilds: 2, Stable: 20260623 , Testing: 20260623
Description: Library for providing a basic file input/output abstraction layer
Homepage: https://github.com/libyal/libbfio
License: LGPL-3
libesedb (available in: app-forensics/libesedb::pentoo , app-forensics/libesedb::pkalin )
- Ebuilds: 3, Stable: 20240420 , Testing: 20240420
Virtual
Description: Library and tools to access the Extensible Storage Engine Database File format.
Homepage: https://github.com/libyal/libesedb
License: LGPL-3
app-forensics/libevt::pentoo
- Ebuilds: 2, Stable: 20221022 , Testing: 20221022
Virtual
Description: Library and tools to access the Windows Event Log (EVT) format
Homepage: https://github.com/libyal/libevt
License: LGPL-3
libevtx (available in: app-forensics/libevtx::pentoo , app-forensics/libevtx::pkalin )
- Ebuilds: 3, Stable: 20240504 , Testing: 20240504
Virtual
Description: Library and tools to access the Windows XML Event Log (EVTX) format
Homepage: https://github.com/libyal/libevtx
License: LGPL-3
libewf (available in: app-forensics/libewf::canutethegreat-overlay , app-forensics/libewf::pentoo )
- Ebuilds: 3, Stable: 20240506 , Testing: 20240506
Virtual
Description: Implementation of the EWF (SMART and EnCase) image format
Homepage: https://github.com/libyal/libewf
License: BSD
libexe (available in: app-forensics/libexe::pentoo , app-forensics/libexe::pkalin )
- Ebuilds: 3, Stable: 20240420 , Testing: 20240420
Virtual
Description: Library and tools to access the executable (EXE) format
Homepage: https://github.com/libyal/libexe
License: LGPL-3
app-forensics/libforensic1394::pentoo
- Ebuilds: 2, Testing: 0.2 , Snapshot: 9999
Description: Library for carrying out memory forensics using firewire/ieee1394
Homepage: https://freddie.witherden.org/tools/libforensic1394/ https://github.com/FreddieWitherden/libforensic1394
License: LGPL-3
app-forensics/libfsapfs::pentoo
- Ebuilds: 1, Testing: 20240429
Virtual
Description: Library and tools to access the Apple File System (APFS)
Homepage: https://github.com/libyal/libfsapfs
License: LGPL-3
app-forensics/libfsclfs::pentoo
- Ebuilds: 1, Stable: 20170206 , Testing: 20170206
Virtual
Description: Library and tools to access the Common Log File System (CLFS)
Homepage: https://github.com/libyal/libfsclfs
License: LGPL-3
app-forensics/libfsext::pentoo
- Ebuilds: 1, Stable: 20251107 , Testing: 20251107
Virtual
Description: Library and tools to access the Extended File System
Homepage: https://github.com/libyal/libfsext
License: LGPL-3
app-forensics/libfsfat::pentoo
- Ebuilds: 1, Stable: 20260717 , Testing: 20260717
Virtual
Description: Library and tools to access the File Allocation Table (FAT) file system
Homepage: https://github.com/libyal/libfsfat
License: LGPL-3
app-forensics/libfshfs::pentoo
- Ebuilds: 1, Stable: 20260802 , Testing: 20260802
Virtual
Description: Library and tools to access the Mac OS Hierarchical File System (HFS)
Homepage: https://github.com/libyal/libfshfs
License: LGPL-3
app-forensics/libfsntfs::pentoo
- Ebuilds: 1, Stable: 20260727 , Testing: 20260727
Virtual
Description: Library and tools to access the Windows New Technology File System (NTFS)
Homepage: https://github.com/libyal/libfsntfs
License: LGPL-3
app-forensics/libfsxfs::pentoo
- Ebuilds: 1, Stable: 20260703 , Testing: 20260703
Virtual
Description: Library and tools to access the SGI X File System (XFS)
Homepage: https://github.com/libyal/libfsxfs
License: LGPL-3
app-forensics/libfvde::pentoo
- Ebuilds: 1, Stable: 20240502 , Testing: 20240502
Virtual
Description: Library and tools to access FileVault Drive Encryption (FVDE) encrypted volumes
Homepage: https://github.com/libyal/libfvde
License: LGPL-3
app-forensics/libklel::pkalin
- Ebuilds: 1, Testing: 1.2.0
Description: A system baselining and evidence collection tool
Homepage: https://github.com/KoreLogicSecurity/libklel
License: BSD
liblnk (available in: app-forensics/liblnk::pentoo , app-forensics/liblnk::pkalin )
- Ebuilds: 4, Stable: 20240423 , Testing: 20240423
Virtual
Description: Library and tools to access the Windows Shortcut File (LNK) format
Homepage: https://github.com/libyal/liblnk
License: LGPL-3
app-forensics/libluksde::pentoo
- Ebuilds: 1, Stable: 20240503 , Testing: 20240503
Virtual
Description: Library and tools to access LUKS Disk Encryption encrypted volumes
Homepage: https://github.com/libyal/libluksde
License: LGPL-3
app-forensics/libmodi::pentoo
- Ebuilds: 1, Stable: 20251121 , Testing: 20251121
Virtual
Description: Library and tools to access the Mac OS disk image formats
Homepage: https://github.com/libyal/libmodi
License: LGPL-3
app-forensics/libmsiecf::pentoo
- Ebuilds: 2, Stable: 20221024 , Testing: 20221024
Virtual
Description: Library and tools to access the Microsoft Internet Explorer (MSIE) Cache Files
Homepage: https://github.com/libyal/libmsiecf
License: LGPL-3
app-forensics/libnk2::pentoo
- Ebuilds: 2, Stable: 20170127 , Testing: 20170127
Virtual
Description: Library and tools to access the Microsoft Outlook Nickfile (NK2) format
Homepage: https://github.com/libyal/libnk2
License: LGPL-3
app-forensics/libnsfdb::pentoo
- Ebuilds: 2, Stable: 20170128 , Testing: 20170128
Virtual
Description: Library and tools to access the Notes Storage Facility (NSF) file format
Homepage: https://github.com/libyal/libnsfdb
License: LGPL-3
app-forensics/libodraw::pentoo
- Ebuilds: 1, Stable: 20240505 , Testing: 20240505
Virtual
Description: Library and tools to access to optical disc (split) RAW image files
Homepage: https://github.com/libyal/libodraw
License: LGPL-3
app-forensics/libolecf::pentoo
- Ebuilds: 2, Stable: 20221024 , Testing: 20221024
Virtual
Description: Library and tools to access the OLE 2 Compound File (OLECF) format
Homepage: https://github.com/libyal/libolecf
License: LGPL-3
app-forensics/libpff::pentoo
- Ebuilds: 2, Stable: 20211114 , Testing: 20211114
Virtual
Description: Library and tools to access the Personal/Offline Folder File (PFF/OFF) format
Homepage: https://github.com/libyal/libpff
License: LGPL-3
app-forensics/libphdi::pentoo
- Ebuilds: 1, Stable: 20240508 , Testing: 20240508
Virtual
Description: Library and tools to access the Parallels Hard Disk image format
Homepage: https://github.com/libyal/libphdi
License: LGPL-3
app-forensics/libqcow::pentoo
- Ebuilds: 2, Stable: 20260703 , Testing: 20260703
Virtual
Description: Library and tools to access the QEMU Copy-On-Write (QCOW) image format
Homepage: https://github.com/libyal/libqcow
License: LGPL-3
app-forensics/libregf::pentoo
- Ebuilds: 1, Stable: 20260526 , Testing: 20260526
Virtual
Description: Library and tools to access the Windows NT Registry File (REGF) format
Homepage: https://github.com/libyal/libregf
License: LGPL-3
libscca (available in: app-forensics/libscca::pentoo , app-forensics/libscca::pkalin )
- Ebuilds: 3, Stable: 20240427 , Testing: 20240427
Virtual
Description: Library and tools to access the Windows Prefetch File (SCCA) format.
Homepage: https://github.com/libyal/libscca
License: LGPL-3
app-forensics/libsmraw::pentoo
- Ebuilds: 1, Stable: 20240506 , Testing: 20240506
Virtual
Description: Library and tools to access the (split) RAW image format
Homepage: https://github.com/libyal/libsmraw
License: LGPL-3
app-forensics/libvsapm::pkalin
- Ebuilds: 1, Stable: 20240503
Description: Library and tools to access the Apple Partition Map (APM) volume system format
Homepage: https://github.com/libyal/libvsapm
License: LGPL-3
app-forensics/libvsgpt::pentoo
- Ebuilds: 1, Stable: 20240504 , Testing: 20240504
Virtual
Description: Library and tools to access the GUID Partition Table (GPT) volume system format
Homepage: https://github.com/libyal/libvsgpt
License: LGPL-3
app-forensics/libvshadow::pentoo
- Ebuilds: 2, Stable: 20240504 , Testing: 20240504
Virtual
Description: Library and tools to access the Volume Shadow Snapshot (VSS) format
Homepage: https://github.com/libyal/libvshadow
License: LGPL-3
app-forensics/libvslvm::pentoo
- Ebuilds: 1, Stable: 20240504 , Testing: 20240504
Virtual
Description: Library and tools to access the Linux Logical Volume Manager (LVM) format
Homepage: https://github.com/libyal/libvslvm
License: LGPL-3
app-forensics/libvsmbr::pentoo
- Ebuilds: 2, Stable: 20180325 , Testing: 20180325
Virtual
Description: Library and tools to access the Master Boot Record (MBR) volume system format
Homepage: https://github.com/libyal/libvsmbr
License: LGPL-3
app-forensics/libwtcdb::pentoo
- Ebuilds: 1, Stable: 20170201 , Testing: 20170201
Description: Library and tools to access the Windows thumbnail cache (thumbcache.db)
Homepage: https://github.com/libyal/libwtcdb
License: LGPL-3
app-forensics/log2timeline::pkalin
- Ebuilds: 1, Testing: 0.66
Description: Create forensic supertimelines in Perl
Homepage: https://github.com/thinrope/log2timeline
License: GPL-3
app-forensics/lynis::gentoo
- Ebuilds: 1, Testing: 3.1.7
Description: Security and system auditing tool
Homepage: https://cisofy.com/lynis/
License: GPL-3
app-forensics/mac-robber::gentoo
- Ebuilds: 1, Stable: 1.02 , Testing: 1.02
Description:
mac-robber is a digital forensics and incident response tool that collects data from allocated files in a mounted file system.
The data can be used by the mactime tool in The Sleuth Kit to make a timeline of file activity. The mac-robber tool is based on
the grave-robber tool from TCT and is written in C instead of Perl.
mac-robber requires that the file system be mounted by the operating system, unlike the tools in The Sleuth Kit that process the
file system themselves. Therefore, mac-robber will not collect data from deleted files or files that have been hidden by
rootkits. mac-robber will also modify the Access times on directories that are mounted with write permissions.
"What is mac-robber good for then", you ask? mac-robber is useful when dealing with a file system that is not supported by The
Sleuth Kit or other forensic tools. mac-robber is very basic C and should compile on any UNIX system. Therefore, you can run
mac-robber on an obscure, suspect UNIX file system that has been mounted read-only on a trusted system. I have also used
mac-robber during investigations of common UNIX systems such as AIX.
Homepage: http://www.sleuthkit.org/mac-robber/index.php
License: GPL-2
app-forensics/magicrescue::gentoo
- Ebuilds: 1, Stable: 1.1.10 , Testing: 1.1.10
Description:
Magic Rescue scans a block device for file types it knows how to recover and calls an external program to extract them. It looks
at "magic bytes" in file contents, so it can be used both as an undelete utility and for recovering a corrupted drive or
partition. As long as the file data is there, it will find it.
It works on any file system, but on very fragmented file systems it can only recover the first chunk of each file. Practical
experience (this program was not written for fun) shows, however, that chunks of 30-50MB are not uncommon.
Homepage: https://github.com/jbj/magicrescue
License: GPL-2+
app-forensics/make-pdf::pentoo
- Ebuilds: 1, Stable: 0.1.7 , Testing: 0.1.7
Description: This tool will embed javascript inside a PDF document
Homepage: https://blog.didierstevens.com/programs/pdf-tools/
License: public-domain
app-forensics/memdump::gentoo
- Ebuilds: 1, Stable: 1.01
Description: Simple memory dumper for UNIX-Like systems
Homepage: http://www.porcupine.org/forensics
License: IBM
app-forensics/mxtract::pentoo
- Ebuilds: 1, Testing: 1.1
Description: A memory extractor & analyzer
Homepage: https://github.com/rek7/mXtract
License: MIT
app-forensics/mysql-magic::pentoo
- Ebuilds: 1, Snapshot: 9999
Description: dump mysql client password from memory
Homepage: https://github.com/hc0d3r/mysql-magic
License: MIT
app-forensics/nrich::graaff
- Ebuilds: 1, Testing: 0.1.1
Description: Enrich IPs with information about their open ports/ vulnerabilities/ software.
Homepage: https://gitlab.com/shodan-public/nrich
License: Apache-2.0 BSD Boost-1.0 GPL-3+ MIT MPL-2.0 Unlicense ZLIB
app-forensics/oletools::pentoo
- Ebuilds: 1, Stable: 0.60.2 , Testing: 0.60.2
Description: A python tools to analyze MS OLE2 files and MS Office documents
Homepage: https://github.com/decalage2/oletools
License: GPL-2 BSD-2 MIT
app-forensics/openscap::pentoo
- Ebuilds: 1, Stable: 1.4.3 , Testing: 1.4.3
Description: Framework which enables integration with Security Content Automation Protocol
Homepage: https://www.open-scap.org/
License: LGPL-2.1+
app-forensics/openscap-daemon::blshkv
- Ebuilds: 1, Testing: 0.1.10
Description: Manages continuous scans of your infrastructure
Homepage: https://www.open-scap.org/tools/openscap-daemon
License: LGPL-2.1
app-forensics/origami-pdf::pentoo
- Ebuilds: 1, Testing: 2.1.0
Description: A Ruby framework designed to parse, analyze, and forge PDF documents
Homepage: https://github.com/gdelugre/origami
License: GPL-3
app-forensics/pasco::gentoo
- Ebuilds: 1, Stable: 20040505_p1 , Testing: 20040505_p1
Description: IE Activity Parser
Homepage: https://sourceforge.net/projects/odessa/
License: BSD
app-forensics/pcileech::pentoo
- Ebuilds: 2, Stable: 4.19 , Testing: 4.19
Description: Direct Memory Access (DMA) Attack Software
Homepage: https://github.com/ufrisk/pcileech
License: Apache-2.0
app-forensics/pdf-parser::pentoo
- Ebuilds: 1, Testing: 0.7.8
Description: This tool will parse a PDF document to identify the fundamental elements used
Homepage: https://blog.didierstevens.com/programs/pdf-tools/
License: public-domain
app-forensics/pdfid::pentoo
- Ebuilds: 1, Stable: 0.2.8 , Testing: 0.2.8
Description: This tool will scan a PDF document looking for certain keyword
Homepage: https://blog.didierstevens.com/programs/pdf-tools/
License: public-domain
app-forensics/peepdf::pkalin
- Ebuilds: 1, Testing: 0.4.3
Description: Python tool to explore PDF files (fork of)
Homepage: http://eternal-todo.com/
License: GPL-3
app-forensics/plaso::pkalin
- Ebuilds: 2, Testing: 20251119
Description: Plaso (log2timeline) is a framework to create super timelines.
Homepage: https://github.com/log2timeline/plaso
License: Apache-2.0
app-forensics/precizer::precizer
- Ebuilds: 3, Stable: 0.17.0
Description:
Precizer is a lightweight, high-performance CLI tool written in pure C.
It is designed for file integrity verification and comparison, making it
especially useful for validating synchronization results. The program
walks directory trees and builds a database of files and their checksums
for fast, repeatable comparisons.
Homepage: https://precizer.github.io/
License: GPL-3
app-forensics/pytsk::pentoo
- Ebuilds: 1, Stable: 20260715 , Testing: 20260715
Description: Python bindings for The Sleuth Kit (libtsk)
Homepage: https://github.com/py4n6/pytsk/
License: Apache-2.0
app-forensics/radamsa::gentoo
- Ebuilds: 2, Testing: 0.7
Description: A general-purpose fuzzer
Homepage: https://gitlab.com/akihe/radamsa
License: MIT
readpe (available in: app-forensics/readpe::bobwya , app-forensics/readpe::myov )
- Ebuilds: 3, Testing: 0.85.1 , Snapshot: 9999
Description: The PE file analysis toolkit
Homepage:
https://pev.sourceforge.net/
https://github.com/mentebinaria/readpe
License: GPL-2+
app-forensics/reglookup::pentoo
- Ebuilds: 2, Snapshot: 9999
Description: An utility for reading and querying Windows NT/2K/XP registries
Homepage: http://projects.sentinelchicken.org/reglookup/
License: GPL-2
app-forensics/regviewer::ssnb
- Ebuilds: 1, Stable: 0.1
Description: RegViewer is GTK 2.2 based GUI Windows registry file navigator. It is platform independent allowing
for examination of Windows registry files from any platform. Particularly useful when conducting forensics of Windows
files from *nix systems.
Homepage: http://sourceforge.net/projects/regviewer/
License: GPL-2
app-forensics/rifiuti::gentoo
- Ebuilds: 1, Stable: 20040505_p1 , Testing: 20040505_p1
Description: Recycle Bin Analyzer
Homepage: https://sourceforge.net/projects/odessa/
License: BSD
app-forensics/rkhunter::gentoo
- Ebuilds: 1, Stable: 1.4.6 , Testing: 1.4.6
Description: Rootkit Hunter scans for known and unknown rootkits, backdoors, and sniffers
Homepage: https://rkhunter.sf.net/
License: GPL-2+
app-forensics/s3tk::pentoo
- Ebuilds: 2, Testing: 0.3.0 , Snapshot: 9999
Description: A security toolkit for Amazon S3
Homepage: https://github.com/ankane/s3tk
License: MIT
app-forensics/samhain::pentoo
- Ebuilds: 2, Testing: 4.5.3
Description: Advanced file integrity and intrusion detection tool.
Homepage: http://la-samhna.de/samhain/
License: GPL-2
app-forensics/scalpel::gentoo
- Ebuilds: 1, Testing: 2.1_pre20210326
Description:
Scalpel is a fast file carver that reads a database of header and footer
definitions and extracts matching files or data fragments from a set of image
files or raw device files. Scalpel is filesystem-independent and will carve
files from FATx, NTFS, ext2/3, HFS+, or raw partitions. It is useful for both
digital forensics investigation and file recovery.
Homepage: https://github.com/sleuthkit/scalpel
License: Apache-2.0
sleuthkit (available in: app-forensics/sleuthkit::gentoo , app-forensics/sleuthkit::pentoo , app-forensics/sleuthkit::pkalin )
- Ebuilds: 3, Stable: 4.14.0 , Testing: 4.14.0
Description: A collection of file system and media management forensic analysis tools
Homepage: https://www.sleuthkit.org/sleuthkit/
License: BSD CPL-1.0 GPL-2+ IBM java? ( Apache-2.0 )
app-forensics/stegoveritas::pentoo
- Ebuilds: 1, Testing: 1.11
Description: Automatic image steganography analysis tool
Homepage: https://github.com/bannsec/stegoVeritas
License: GPL-2
tcpxtract (available in: app-forensics/tcpxtract::mva , app-forensics/tcpxtract::pentoo )
- Ebuilds: 2, Stable: 1.0.1 , Testing: 1.0.1
Description: Extracts files from network packet captures
Homepage: https://tcpxtract.sourceforge.net/
License: GPL-2
app-forensics/unhide::gentoo
- Ebuilds: 1, Testing: 20220611
Description: Forensic tool to find hidden processes and TCP/UDP ports by rootkits/LKMs
Homepage: https://www.unhide-forensics.info
License: GPL-3+
app-forensics/volatility3::gentoo
- Ebuilds: 2, Stable: 2.28.0
Description:
Volatility is the world's most widely used framework for extracting
digital artifacts from volatile memory (RAM) samples. The extraction
techniques are performed completely independent of the system being
investigated but offer visibility into the runtime state of the system.
Homepage: https://github.com/volatilityfoundation/volatility3/ https://www.volatilityfoundation.org/
License: Volatility-1.0
app-forensics/whispers::nest
- Ebuilds: 2, Testing: 2.4.0 , Snapshot: 9999
Description:
Whispers is a static code analysis tool designed for parsing
various common data formats in search of hardcoded credentials
and dangerous functions. Whispers can run in the CLI or you can
integrate it in your CI/CD pipeline.
Homepage: https://github.com/adeptex/whispers
License: GPL-3
app-forensics/xmount::pkalin
- Ebuilds: 1, Testing: 1.1.1
Description: Convert on-the-fly between multiple input and output harddisk image types
Homepage: https://www.sits.lu/xmount
License: GPL-3
app-forensics/yara::gentoo
- Ebuilds: 3, Stable: 4.5.8 , Testing: 4.5.8 , Snapshot: 9999
Description:
YARA is a tool aimed at (but not limited to) helping malware
researchers to identify and classify malware samples. With YARA you can
create descriptions of malware families (or whatever you want to
describe) based on textual or binary patterns.
Homepage: https://virustotal.github.io/yara/
License: Apache-2.0
app-forensics/yara-x::gentoo
- Ebuilds: 2, Stable: 1.18.0 , Testing: 1.19.0
Description:
YARA is a tool aimed at (but not limited to) helping malware
researchers to identify and classify malware samples. With YARA you can
create descriptions of malware families (or whatever you want to
describe) based on textual or binary patterns.
YARA-X is a re-incarnation of YARA rewritten in Rust, eventually
replacing YARA.
Homepage: https://virustotal.github.io/yara-x/
License: BSD
Apache-2.0 Apache-2.0-with-LLVM-exceptions BSD CC0-1.0 EPL-2.0 ISC
MIT MPL-2.0 Unicode-3.0 Unicode-DFS-2016 WTFPL-2 ZLIB
app-forensics/zsteg::pentoo
- Ebuilds: 1, Stable: 0.2.13
Description: Detect stegano-hidden data in PNG & BMP
Homepage: https://github.com/zed-0xff/zsteg
License: MIT
app-forensics/zzuf::gentoo
- Ebuilds: 2, Testing: 0.15_p20220529
Description: Transparent application input fuzzer
Homepage: http://caca.zoy.org/wiki/zzuf
License: WTFPL-2