Skip to main content
Avatar for Fox-IT from gravatar.com

Fox-IT

Username    fox-it
Date joined   Joined

59 projects

flow.record

Last released

A library for defining and creating structured data (called records) that can be streamed to disk or piped to other tools that use flow.record

dissect.target

Last released

This module ties all other Dissect modules together, it provides a programming API and command line tools which allow easy access to various data sources inside disk images or file collections (a.k.a. targets)

acquire

Last released

A tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container

dissect.database

Last released

A Dissect module implementing parsers for various database formats, including Berkeley DB, Microsofts Extensible Storage Engine (ESE) and SQLite3

dissect.cstruct

Last released

A Dissect module implementing a parser for C-like structures: structure parsing in Python made easy

dissect.eventlog

Last released

A Dissect module implementing parsers for the Windows EVT, EVTX and WEVT log file formats

dissect.hypervisor

Last released

A Dissect module implementing parsers for various hypervisor disk, backup and configuration files

dissect.util

Last released

A Dissect module implementing various utility functions for the other Dissect modules

dissect.volume

Last released

A Dissect module implementing a parser for different disk volume and partition systems, for example LVM2, GPT and MBR

dissect.qnxfs

Last released

A Dissect module implementing a parser for the QNX4 and QNX6 file systems, commonly used in the QNX RTOS.

dissect.apfs

Last released

A Dissect module implementing a parser for the APFS file system, a commonly used Apple file system

dissect.shellitem

Last released

A Dissect module implementing a parser for the Shellitem structures, commonly used by Microsoft Windows

dissect.regf

Last released

A Dissect module implementing a parser for Windows registry file format, used to store application and OS configuration on Windows operating systems

dissect.ntfs

Last released

A Dissect module implementing a parser for the NTFS file system, used by the Windows operating system

dissect.squashfs

Last released

A Dissect module implementing a parser for the SquashFS file system, commonly used in appliance or device firmware

dissect.thumbcache

Last released

A Dissect module implementing parsers for the thumbcache of Windows systems.

dissect.ole

Last released

A Dissect module implementing a parser for the Object Linking & Embedding (OLE) format, commonly used by document editors on Windows operating systems

dissect.fve

Last released

A Dissect module implementing a parsers for full volume encryption implementations, currently Linux Unified Key Setup (LUKS1 and LUKS2) and Microsoft's Bitlocker Disk Encryption

dissect.xfs

Last released

A Dissect module implementing a parser for the XFS file system, commonly used by RedHat Linux distributions

dissect.jffs

Last released

A Dissect module implementing a parser for the JFFS2 file system, commonly used by router operating systems

dissect.evidence

Last released

A Dissect module implementing a parsers for various forensic evidence file containers, currently: AD1, ASDF and EWF

dissect.executable

Last released

A Dissect module implementing a parsers for various executable formats such as PE, ELF and Macho-O

dissect.fat

Last released

A Dissect module implementing parsers for the FAT and exFAT file systems, commonly used on flash memory based storage devices and UEFI partitions

dissect.ffs

Last released

A Dissect module implementing a parser for the FFS file system, commonly used by BSD operating systems

dissect.extfs

Last released

A Dissect module implementing a parser for the ExtFS file system, the native filesystem for Linux operating systems

dissect.vmfs

Last released

A Dissect module implementing a parser for the VMFS file system, used by VMware virtualization software

dissect.etl

Last released

A Dissect module implementing a parser for Event Trace Log (ETL) files, used by the Windows operating system to log kernel events

dissect.cramfs

Last released

A Dissect module implementing a parser for the Cram file system, commonly used in appliance or device firmware

dissect.clfs

Last released

A Dissect module implementing a parser for the CLFS (Common Log File System) file system of Windows

dissect.archive

Last released

A Dissect module implementing parsers for various archive and backup formats

dissect.cim

Last released

A Dissect module implementing a parser for the Windows Common Information Model (CIM) database, used in the Windows operating system

dissect.btrfs

Last released

A Dissect module implementing a parser for the Btrfs file system, a commonly used Linux filesystem.

dissect

Last released

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (part of NCC Group)

dissect.esedb

Last released

Superseded by dissect.database. A Dissect module implementing a parser for Microsofts Extensible Storage Engine Database (ESEDB), used for example in Active Directory, Exchange and Windows Update

dissect.sql

Last released

Superseded by dissect.database. A Dissect module implementing a parsers for the SQLite database file format, commonly used by applications to store configuration data

flow.transport

Last released

A library for easily creating communication transports over various links

dissect.cobaltstrike

Last released

a Python library for dissecting Cobalt Strike related data

dissect.contrib

Last released

This project is a meta package: it reserves the namespace for Dissect packages made by external contributors

skrapa

Last released

Minimal Python memory scraper with memory attributes support

foxhound

Last released

Placeholder for future Dissect project

dissect.disc

Last released

Placeholder for future Dissect project

dissect.f2fs

Last released

Placeholder for future Dissect project

dissect.ubifs

Last released

Placeholder for future Dissect project

dissect.bsddb

Last released

Placeholder for future Dissect project

dissect.fs

Last released

Placeholder for future Dissect project

flow.remoting

Last released

Placeholder for future Dissect project

flow.ioc

Last released

Placeholder for future Dissect project

flow.broker

Last released

Placeholder for future Dissect project

dissect.zfs

Last released

Placeholder for future Dissect project

dissect.yaffs

Last released

Placeholder for future Dissect project

dissect.refs

Last released

Placeholder for future Dissect project

dissect.raid

Last released

Placeholder for future Dissect project

dissect.network

Last released

Placeholder for future Dissect project

dissect.memory

Last released

Placeholder for future Dissect project

dissect.container

Last released

Placeholder for future Dissect project

dissect.binary

Last released

Placeholder for future Dissect project

dissect.aufs

Last released

Placeholder for future Dissect project

dissect.agent

Last released

Placeholder for future Dissect project

mkYARA

Last released

Generating YARA rules based on binary code

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page