Category: app-forensics
Search
-
app-forensics/analyzemft::pentoo
- Ebuilds: 1, Stable: 3.1.1, Testing: 3.1.1
Description: Analyze the MFT from a NTFS filesystem
Homepage: https://github.com/rowingdude/analyzeMFT
License: MIT
-
app-forensics/bulk_extractor::pentoo
- Ebuilds: 2, Stable: 2.1.1, Testing: 2.2.0
Description: Scans a disk image for regular expressions and other content
Homepage: https://github.com/simsong/bulk_extractor
License: GPL-2
-
app-forensics/dfvfs::pentoo
- Ebuilds: 2, Stable: 20251019, Testing: 20260731
Description: Digital Forensics Virtual File System (dfVFS)
Homepage: https://github.com/log2timeline/dfvfs
License: Apache-2.0
-
app-forensics/dfwinreg::pentoo
- Ebuilds: 1, Testing: 20260411
Description: Digital Forensics Windows Registry (dfWinReg)
Homepage: https://github.com/log2timeline/dfwinreg
License: Apache-2.0
-
app-forensics/inception::pentoo
- Ebuilds: 1, Testing: 0.4.2
Description: Firewire physical memory manipulation tool exploiting IEEE 1394 SBP-2 DMA
Homepage: http://www.breaknenter.org/projects/inception/
License: GPL-3
-
app-forensics/lazagne::pentoo
- Ebuilds: 2, Testing: 2.4.3, Snapshot: 9999
Description: Credentials recovery project
Homepage: https://github.com/AlessandroZ/LaZagne
License: LGPL-3 GPL-3 MIT
-
app-forensics/libbde::pentoo
- Ebuilds: 1, Stable: 20240502, Testing: 20240502
Virtual
Description: Library and tools to access BitLocker Drive Encryption (BDE) encrypted volumes
Homepage: https://github.com/libyal/libbde
License: LGPL-3
-
app-forensics/libbfio::pentoo
- Ebuilds: 1, Stable: 20260623, Testing: 20260623
Description: Library for providing a basic file input/output abstraction layer
Homepage: https://github.com/libyal/libbfio
License: LGPL-3
-
app-forensics/libesedb::pentoo
- Ebuilds: 2, Stable: 20220806, Testing: 20220806
Virtual
Description: Library and tools to access the Extensible Storage Engine Database File format.
Homepage: https://github.com/libyal/libesedb
License: LGPL-3
-
app-forensics/libevt::pentoo
- Ebuilds: 2, Stable: 20221022, Testing: 20221022
Virtual
Description: Library and tools to access the Windows Event Log (EVT) format
Homepage: https://github.com/libyal/libevt
License: LGPL-3
-
app-forensics/libevtx::pentoo
- Ebuilds: 2, Stable: 20221101, Testing: 20221101
Virtual
Description: Library and tools to access the Windows XML Event Log (EVTX) format
Homepage: https://github.com/libyal/libevtx
License: LGPL-3
-
app-forensics/libewf::pentoo
- Ebuilds: 1, Stable: 20240506, Testing: 20240506
Virtual
Description: Libewf is a library to access the Expert Witness Compression Format (EWF)
Homepage: https://github.com/libyal/libewf
License: LGPL-3
-
app-forensics/libexe::pentoo
- Ebuilds: 2, Stable: 20221023, Testing: 20221023
Virtual
Description: Library and tools to access the executable (EXE) format
Homepage: https://github.com/libyal/libexe
License: LGPL-3
-
app-forensics/libforensic1394::pentoo
- Ebuilds: 2, Testing: 0.2, Snapshot: 9999
Description: Library for carrying out memory forensics using firewire/ieee1394
Homepage: https://freddie.witherden.org/tools/libforensic1394/ https://github.com/FreddieWitherden/libforensic1394
License: LGPL-3
-
app-forensics/libfsapfs::pentoo
- Ebuilds: 1, Testing: 20240429
Virtual
Description: Library and tools to access the Apple File System (APFS)
Homepage: https://github.com/libyal/libfsapfs
License: LGPL-3
-
app-forensics/libfsclfs::pentoo
- Ebuilds: 1, Stable: 20170206, Testing: 20170206
Virtual
Description: Library and tools to access the Common Log File System (CLFS)
Homepage: https://github.com/libyal/libfsclfs
License: LGPL-3
-
app-forensics/libfsext::pentoo
- Ebuilds: 1, Stable: 20251107, Testing: 20251107
Virtual
Description: Library and tools to access the Extended File System
Homepage: https://github.com/libyal/libfsext
License: LGPL-3
-
app-forensics/libfsfat::pentoo
- Ebuilds: 1, Stable: 20260717, Testing: 20260717
Virtual
Description: Library and tools to access the File Allocation Table (FAT) file system
Homepage: https://github.com/libyal/libfsfat
License: LGPL-3
-
app-forensics/libfshfs::pentoo
- Ebuilds: 1, Stable: 20260802, Testing: 20260802
Virtual
Description: Library and tools to access the Mac OS Hierarchical File System (HFS)
Homepage: https://github.com/libyal/libfshfs
License: LGPL-3
-
app-forensics/libfsntfs::pentoo
- Ebuilds: 1, Stable: 20260727, Testing: 20260727
Virtual
Description: Library and tools to access the Windows New Technology File System (NTFS)
Homepage: https://github.com/libyal/libfsntfs
License: LGPL-3
-
app-forensics/libfsxfs::pentoo
- Ebuilds: 1, Stable: 20260703, Testing: 20260703
Virtual
Description: Library and tools to access the SGI X File System (XFS)
Homepage: https://github.com/libyal/libfsxfs
License: LGPL-3
-
app-forensics/libfvde::pentoo
- Ebuilds: 1, Stable: 20240502, Testing: 20240502
Virtual
Description: Library and tools to access FileVault Drive Encryption (FVDE) encrypted volumes
Homepage: https://github.com/libyal/libfvde
License: LGPL-3
-
app-forensics/liblnk::pentoo
- Ebuilds: 2, Stable: 20240423, Testing: 20240423
Virtual
Description: Library and tools to access the Windows Shortcut File (LNK) format
Homepage: https://github.com/libyal/liblnk
License: LGPL-3
-
app-forensics/libluksde::pentoo
- Ebuilds: 1, Stable: 20240503, Testing: 20240503
Virtual
Description: Library and tools to access LUKS Disk Encryption encrypted volumes
Homepage: https://github.com/libyal/libluksde
License: LGPL-3
-
app-forensics/libmodi::pentoo
- Ebuilds: 1, Stable: 20251121, Testing: 20251121
Virtual
Description: Library and tools to access the Mac OS disk image formats
Homepage: https://github.com/libyal/libmodi
License: LGPL-3
-
app-forensics/libmsiecf::pentoo
- Ebuilds: 2, Stable: 20221024, Testing: 20221024
Virtual
Description: Library and tools to access the Microsoft Internet Explorer (MSIE) Cache Files
Homepage: https://github.com/libyal/libmsiecf
License: LGPL-3
-
app-forensics/libnk2::pentoo
- Ebuilds: 2, Stable: 20170127, Testing: 20170127
Virtual
Description: Library and tools to access the Microsoft Outlook Nickfile (NK2) format
Homepage: https://github.com/libyal/libnk2
License: LGPL-3
-
app-forensics/libnsfdb::pentoo
- Ebuilds: 2, Stable: 20170128, Testing: 20170128
Virtual
Description: Library and tools to access the Notes Storage Facility (NSF) file format
Homepage: https://github.com/libyal/libnsfdb
License: LGPL-3
-
app-forensics/libodraw::pentoo
- Ebuilds: 1, Stable: 20240505, Testing: 20240505
Virtual
Description: Library and tools to access to optical disc (split) RAW image files
Homepage: https://github.com/libyal/libodraw
License: LGPL-3
-
app-forensics/libolecf::pentoo
- Ebuilds: 2, Stable: 20221024, Testing: 20221024
Virtual
Description: Library and tools to access the OLE 2 Compound File (OLECF) format
Homepage: https://github.com/libyal/libolecf
License: LGPL-3
-
app-forensics/libpff::pentoo
- Ebuilds: 2, Stable: 20211114, Testing: 20211114
Virtual
Description: Library and tools to access the Personal/Offline Folder File (PFF/OFF) format
Homepage: https://github.com/libyal/libpff
License: LGPL-3
-
app-forensics/libphdi::pentoo
- Ebuilds: 1, Stable: 20240508, Testing: 20240508
Virtual
Description: Library and tools to access the Parallels Hard Disk image format
Homepage: https://github.com/libyal/libphdi
License: LGPL-3
-
app-forensics/libqcow::pentoo
- Ebuilds: 2, Stable: 20260703, Testing: 20260703
Virtual
Description: Library and tools to access the QEMU Copy-On-Write (QCOW) image format
Homepage: https://github.com/libyal/libqcow
License: LGPL-3
-
app-forensics/libregf::pentoo
- Ebuilds: 1, Stable: 20260526, Testing: 20260526
Virtual
Description: Library and tools to access the Windows NT Registry File (REGF) format
Homepage: https://github.com/libyal/libregf
License: LGPL-3
-
app-forensics/libscca::pentoo
- Ebuilds: 2, Stable: 20221027, Testing: 20221027
Virtual
Description: Library and tools to access the Windows Prefetch File (SCCA) format.
Homepage: https://github.com/libyal/libscca
License: LGPL-3
-
app-forensics/libsmraw::pentoo
- Ebuilds: 1, Stable: 20240506, Testing: 20240506
Virtual
Description: Library and tools to access the (split) RAW image format
Homepage: https://github.com/libyal/libsmraw
License: LGPL-3
-
app-forensics/libvsgpt::pentoo
- Ebuilds: 1, Stable: 20240504, Testing: 20240504
Virtual
Description: Library and tools to access the GUID Partition Table (GPT) volume system format
Homepage: https://github.com/libyal/libvsgpt
License: LGPL-3
-
app-forensics/libvshadow::pentoo
- Ebuilds: 2, Stable: 20240504, Testing: 20240504
Virtual
Description: Library and tools to access the Volume Shadow Snapshot (VSS) format
Homepage: https://github.com/libyal/libvshadow
License: LGPL-3
-
app-forensics/libvslvm::pentoo
- Ebuilds: 1, Stable: 20240504, Testing: 20240504
Virtual
Description: Library and tools to access the Linux Logical Volume Manager (LVM) format
Homepage: https://github.com/libyal/libvslvm
License: LGPL-3
-
app-forensics/libvsmbr::pentoo
- Ebuilds: 2, Stable: 20180325, Testing: 20180325
Virtual
Description: Library and tools to access the Master Boot Record (MBR) volume system format
Homepage: https://github.com/libyal/libvsmbr
License: LGPL-3
-
app-forensics/libwtcdb::pentoo
- Ebuilds: 1, Stable: 20170201, Testing: 20170201
Description: Library and tools to access the Windows thumbnail cache (thumbcache.db)
Homepage: https://github.com/libyal/libwtcdb
License: LGPL-3
-
app-forensics/make-pdf::pentoo
- Ebuilds: 1, Stable: 0.1.7, Testing: 0.1.7
Description: This tool will embed javascript inside a PDF document
Homepage: https://blog.didierstevens.com/programs/pdf-tools/
License: public-domain
-
app-forensics/mxtract::pentoo
- Ebuilds: 1, Testing: 1.1
Description: A memory extractor & analyzer
Homepage: https://github.com/rek7/mXtract
License: MIT
-
app-forensics/mysql-magic::pentoo
- Ebuilds: 1, Snapshot: 9999
Description: dump mysql client password from memory
Homepage: https://github.com/hc0d3r/mysql-magic
License: MIT
-
app-forensics/oletools::pentoo
- Ebuilds: 1, Stable: 0.60.2, Testing: 0.60.2
Description: A python tools to analyze MS OLE2 files and MS Office documents
Homepage: https://github.com/decalage2/oletools
License: GPL-2 BSD-2 MIT
-
app-forensics/openscap::pentoo
- Ebuilds: 1, Stable: 1.4.3, Testing: 1.4.3
Description: Framework which enables integration with Security Content Automation Protocol
Homepage: https://www.open-scap.org/
License: LGPL-2.1+
-
app-forensics/origami-pdf::pentoo
- Ebuilds: 1, Testing: 2.1.0
Description: A Ruby framework designed to parse, analyze, and forge PDF documents
Homepage: https://github.com/gdelugre/origami
License: GPL-3
-
app-forensics/pcileech::pentoo
- Ebuilds: 2, Stable: 4.19, Testing: 4.19
Description: Direct Memory Access (DMA) Attack Software
Homepage: https://github.com/ufrisk/pcileech
License: Apache-2.0
-
app-forensics/pdf-parser::pentoo
- Ebuilds: 1, Testing: 0.7.8
Description: This tool will parse a PDF document to identify the fundamental elements used
Homepage: https://blog.didierstevens.com/programs/pdf-tools/
License: public-domain
-
app-forensics/pdfid::pentoo
- Ebuilds: 1, Stable: 0.2.8, Testing: 0.2.8
Description: This tool will scan a PDF document looking for certain keyword
Homepage: https://blog.didierstevens.com/programs/pdf-tools/
License: public-domain
-
app-forensics/pytsk::pentoo
- Ebuilds: 1, Stable: 20260715, Testing: 20260715
Description: Python bindings for The Sleuth Kit (libtsk)
Homepage: https://github.com/py4n6/pytsk/
License: Apache-2.0
-
app-forensics/reglookup::pentoo
- Ebuilds: 2, Snapshot: 9999
Description: An utility for reading and querying Windows NT/2K/XP registries
Homepage: http://projects.sentinelchicken.org/reglookup/
License: GPL-2
-
app-forensics/s3tk::pentoo
- Ebuilds: 2, Testing: 0.3.0, Snapshot: 9999
Description: A security toolkit for Amazon S3
Homepage: https://github.com/ankane/s3tk
License: MIT
-
app-forensics/samhain::pentoo
- Ebuilds: 2, Testing: 4.5.3
Description: Advanced file integrity and intrusion detection tool.
Homepage: http://la-samhna.de/samhain/
License: GPL-2
-
app-forensics/sleuthkit::pentoo
- Ebuilds: 1, Stable: 4.14.0, Testing: 4.14.0
Description: A collection of file system and media management forensic analysis tools
Homepage: https://www.sleuthkit.org/sleuthkit/
License: BSD CPL-1.0 GPL-2+ IBM java? ( Apache-2.0 )
-
app-forensics/stegoveritas::pentoo
- Ebuilds: 1, Testing: 1.11
Description: Automatic image steganography analysis tool
Homepage: https://github.com/bannsec/stegoVeritas
License: GPL-2
-
app-forensics/tcpxtract::pentoo
- Ebuilds: 1, Stable: 1.0.1
Description: Extracts files from network packet captures
Homepage: http://tcpxtract.sourceforge.net/
License: GPL-2
-
app-forensics/zsteg::pentoo
- Ebuilds: 1, Stable: 0.2.13
Description: Detect stegano-hidden data in PNG & BMP
Homepage: https://github.com/zed-0xff/zsteg
License: MIT