+
Skip to content
/ fact Public

A shell pipeline for extracting forensic artifacts from disk images in ECS format.

License

Notifications You must be signed in to change notification settings

cuhsat/fact

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 

Repository files navigation

Forensic Artifacts Collecting Toolkit

A shell pipeline for extracting forensic artifacts from disk images in ECS format. Important artifacts will be processed and provided for ingestion with Logstash.

# fmount disk.raw | ffind | flog -D logstash

Mount various disk images for forensic read-only processing.

Find forensic artifacts in mount points or the live system.

Log forensic artifacts as JSON in ECS format.

License

All released under the MIT License.

About

A shell pipeline for extracting forensic artifacts from disk images in ECS format.

Topics

Resources

License

Stars

Watchers

Forks

点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载