forensics

classes

resources

tools

general

  • autopsy - digital forensics platform
  • bulkextractor - scans a disk image, a file, or a directory of files
  • dc3dd - a patched version of gnu dd with added features for computer forensics
  • dumpsterdiver - analyze big volumes of various file types in search of hardcoded secrets
  • entropy - ent is a small, fast command line utility, plotting various entropy related metrics of files or pipe/stdin streams
  • exiftool - read, write and edit exif metadata
  • foremost - restore files from their headers, footers and data structures
  • frida-extract - based runpe extraction tool
  • image-unshredding
  • kaitai - reverse engineer different formats of files
  • mocky - mocky is a script to generates polymocks.
  • pdfparser - a standalone php library, provides various tools to extract data from a pdf file
  • pdf object browser
  • peepdf - powerful python tool to analyze pdf documents
  • pdf decomposing tools
  • qpdf
    • decompress: qpdf --qdf --object-streams=disable orig.pdf uncompressed-qpdf.pdf
  • scalpel - scalpel is an open source data carving tool.
  • sstv decoder
  • volatility - volatile memory extraction utility framework
  • whatsapp-viewer - small tool to display chats from the android msgstore.db database
  • xortool - a tool to analyze multi-byte xor cipher
  • zwfp - zero-width fingerprinting

passwords

  • bewgor - bull's eye wordlist generator
  • bruteforce-wallet - try to find the password of an encrypted peercoin (or bitcoin, litecoin, etc…) wallet file
  • chntpw - utility to reset the password on windows
  • chromepass - view passwords stored by google chrome web browser
  • crowbar - brute forcing tool
  • cupp - common user passwords profiler
  • hashcat - advanced password recovery
    • hob0rules - password cracking rules for hashcat based on statistics and industry patterns
  • john the ripper - a fast password cracker
  • john tutorial
  • another john tutorial
  • kon-boot - wim/mac password breaker
  • lazagne - credentials recovery project
  • mimikatz - a little tool to play with windows security
  • passwordfox - extract the user names/passwords stored in firefox
  • rarcrack - crack .rar passwords
  • ssh-brute-forcer - a simple multi-threaded ssh brute forcer
  • thc-hydra - parallelized login cracker which supports numerous protocols to attack
  • wce - windows credentials editor

printing

steganography