diff --git a/forensics/index.md b/forensics/index.md index b25d6fb..2e71ecc 100644 --- a/forensics/index.md +++ b/forensics/index.md @@ -1,3 +1,142 @@ -# Placeholder +# Forensics -This is just a placeholder. Feel free to contribute :) +Anti-Virus Forensics Tools +------------ + + * [chkrootkit](../tools/chkrootkit.md) + +Digital Anti-Forensics +------------ + + * [chkrootkit](../tools/chkrootkit.md) + +Digital Forensics +------------ + + * [autopsy](../tools/autopsy.md) + * [binwalk](../tools/binwalk.md) + * [bulk_extractor](../tools/bulk_extractor.md) + * [chkrootkit](../tools/chkrootkit.md) + * [dc3dd](../tools/dc3dd.md) + * [dcfldd](../tools/dcfldd.md) + * [extundelete](../tools/extundelete.md) + * [foremost](../tools/foremost.md) + * [fsstat](../tools/fsstat.md) + * [galleta](../tools/galleta.md) + * [tsk_comparedir](../tools/tsk_comparedir.md) + * [tsk_loaddb](../tools/tsk_loaddb.md) + +Forensic Analysis Tools +------------ + + * [affcompare](../tools/affcompare.md) + * [affcopy](../tools/affcopy.md) + * [affcrypto](../tools/affcrypto.md) + * [affdiskprint](../tools/affdiskprint.md) + * [affinfo](../tools/affinfo.md) + * [affsign](../tools/affsign.md) + * [affstats](../tools/affstats.md) + * [affuse](../tools/affuse.md) + * [affverify](../tools/affverify.md) + * [affxml](../tools/affxml.md) + * [autopsy](../tools/autopsy.md) + * [binwalk](../tools/binwalk.md) + * [blkcalc](../tools/blkcalc.md) + * [blkcat](../tools/blkcat.md) + * [blkstat](../tools/blkstat.md) + * [bulk_extractor](../tools/bulk_extractor.md) + * [ffind](../tools/ffind.md) + * [fls](../tools/fls.md) + * [foremost](../tools/foremost.md) + * [galleta](../tools/galleta.md) + * [hfind](../tools/hfind.md) + * [icat-sleuthkit](../tools/icat-sleuthkit.md) + * [istat](../tools/istat.md) + * [jcat](../tools/jcat.md) + * [mactime-sleuthkit](../tools/mactime-sleuthkit.md) + * [missidentify](../tools/missidentify.md) + * [mmcat](../tools/mmcat.md) + * [pdgmail](../tools/pdgmail.md) + * [readpst](../tools/readpst.md) + * [reglookup](../tools/reglookup.md) + * [regripper](../tools/regripper.md) + * [sigfind](../tools/sigfind.md) + * [sorter](../tools/sorter.md) + * [srch_strings](../tools/srch_strings.md) + * [tsk_recover](../tools/tsk_recover.md) + * [vinetto](../tools/vinetto.md) + +Forensic Carving Tools +------------ + + * [binwalk](../tools/binwalk.md) + * [bulk_extractor](../tools/bulk_extractor.md) + * [foremost](../tools/foremost.md) + * [jls](../tools/jls.md) + * [magicrescue](../tools/magicrescue.md) + * [pasco](../tools/pasco.md) + * [pev](../tools/pev.md) + * [recoverjpeg](../tools/recoverjpeg.md) + * [rifiuti](../tools/rifiuti.md) + * [rifiuti2](../tools/rifiuti2.md) + * [safecopy](../tools/safecopy.md) + * [scalpel](../tools/scalpel.md) + * [scrounge-ntfs](../tools/scrounge-ntfs.md) + +Forensic Hashing Tools +------------ + + * [md5deep](../tools/md5deep.md) + * [rahash2](../tools/rahash2.md) + +Forensic Imaging Tools +------------ + + * [affcat](../tools/affcat.md) + * [affconvert](../tools/affconvert.md) + * [blkls](../tools/blkls.md) + * [dc3dd](../tools/dc3dd.md) + * [dcfldd](../tools/dcfldd.md) + * [ddrescue](../tools/ddrescue.md) + * [ewfacquire](../tools/ewfacquire.md) + * [ewfacquirestream](../tools/ewfacquirestream.md) + * [ewfexport](../tools/ewfexport.md) + * [ewfinfo](../tools/ewfinfo.md) + * [ewfverify](../tools/ewfverify.md) + * [fsstat](../tools/fsstat.md) + * [guymager](../tools/guymager.md) + * [img_cat](../tools/img_cat.md) + * [img_stat](../tools/img_stat.md) + * [mmls](../tools/mmls.md) <------ I STOPPED HERE !!! + * [mmstat](../tools/mmstat.md) + * [tsk_gettimes](../tools/tsk_gettimes.md) + + +Forensic Suites +------------ + + * [autopsy](../tools/autopsy.md) + * [dff](../tools/dff.md) + * [dff-gui](../tools/dff-gui.md) + +Network Forensics +------------ + + * [p0f](../tools/p0f.md) + +Password Forensics Tools +------------ + + * [chntpw](../tools/chntpw.md) + +PDF Forensics Tools +------------ + + * [pdf-parser](../tools/pdf-parser.md) + * [peepdf](../tools/peepdf.md) + +RAM Forensics Tools +------------ + + * [volafox](../tools/volafox.md) + * [volatility](../tools/volatility.md)