awesome-anti-forensic

Forensic evasion toolkit

A curated list of tools and packages used to counter forensic analysis and hide information from digital systems.

Tools and packages that are used for countering forensic activities, including encryption, steganography, and anything that modify attributes. This all includes tools to work with anything in general that makes changes to a system for the purposes of hiding information.

GitHub

795 stars
16 watching
90 forks
Language: HTML
last commit: almost 3 years ago
Linked from 2 awesome lists

anti-forensicanti-forensicsantiforensicsawesomeawesome-listcybersecurityforensic-analysissecurity

Awesome-anti-forensic / Tools / System/Digital Image

Afflib81over 2 years ago: An extensible open format for the storage of disk images and related forensic.information
Air-Imager: A GUI front-end to dd/dc3dd designed for easily creating forensic images
Bmap-tools231almost 2 years ago: Tool for copying largely sparse files using information from a block map file
dd: The dd command allows you to copy all or part of a disk

Awesome-anti-forensic / Tools / System/Digital Image / dd

Dc3dd: A patched version of dd that includes a number of features useful for computer forensics
Dcfldd: DCFL (DoD Computer Forensics Lab), a dd replacement with hashing

Awesome-anti-forensic / Tools / System/Digital Image

ddrescue: GNU data recovery tool
Dmg2img215over 5 years ago: A CLI tool to uncompress Apple's compressed DMG files to the HFS+ IMG format
Frida16,429almost 2 years ago: Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers

Awesome-anti-forensic / Tools / System/Digital Image / Frida

Fridump755about 2 years ago: A universal memory dumper using Frida

Awesome-anti-forensic / Tools / System/Digital Image

Imagemounter121over 3 years ago: Command line utility and Python package to ease the (un)mounting of forensic disk images

Awesome-anti-forensic / Tools / Recovering tool / Memory Extraction

Extundelete: Utility for recovering deleted files from ext2, ext3 or ext4 partitions by parsing the journal
Foremost320over 3 years ago: A console program to recover files based on their headers, footers, and internal data structures
MagicRescue8about 5 years ago: Find and recover deleted files on block devices
MemDump12over 8 years ago: Dumps system memory to stdout, skipping over holes in memory maps
MemFetch40over 8 years ago: Simple utility that can be used to dump process memory of any userspace process running on the system without affecting its execution
Mxtract582almost 5 years ago: Memory Extractor & Analyzer
Recoverjpeg77over 3 years ago: Recover jpegs from damaged devices
SafeCopy: A disk data recovery tool to extract data from damaged media
Scrounge-Ntfs11over 9 years ago: Data recovery program for NTFS file systems
TestDisk & PhotoRec1,702about 2 years ago: TestDisk checks the partition and boot sectors of your disks. It is very useful in recovering lost partitions. PhotoRec is file data recovery software designed to recover lost pictures from digital camera memory or even hard disks. It has been extended to search also for non audio/video headers

Awesome-anti-forensic / Tools / Analysis / Gathering tool (Know your ennemies)

Autopsy2,462over 1 year ago: The forensic browser. A GUI for the Sleuth Kit
Bulk-extractor1,129almost 2 years ago: Bulk Email and URL extraction tool
captipper714over 3 years ago: Malicious HTTP traffic explorer tool
Chromefreak69over 11 years ago: A Cross-Platform Forensic Framework for Google Chrome
SkypeFreak66over 9 years ago: A Cross Platform Forensic Framework for Skype
Dumpzilla130over 5 years ago: A forensic tool for firefox
Emldump2,051almost 2 years ago: Analyze MIME files
Galleta: Examine the contents of the IE's cookie files for forensic purposes
Guymager: A forensic imager for media acquisition
Indxparse215almost 3 years ago: A Tool suite for inspecting NTFS artifacts
IOSforensic63over 12 years ago: iOS forensic tool
IPBA2103over 12 years ago: IOS Backup Analyzer
Iphoneanalyzer7almost 11 years ago: Allows you to forensically examine or recover date from in iOS device
LiMEaide161about 6 years ago: Remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host
MboxGrep: A small, non-interactive utility that scans mail folders for messages matching regular expressions. It does matching against basic and extended POSIX regular expressions, and reads and writes a variety of mailbox formats
Mobiusft: An open-source forensic framework written in Python/GTK that manages cases and case items, providing an abstract interface for developing extensions
Naft: Network Appliance Forensic Toolkit. A Network Forensic Analysis Tool for advanced Network Traffic Analysis, sniffer and packet analyzer
Nfex: A tool for extracting files from the network in real-time or post-capture from an offline tcpdump pcap savefile
Ntdsxtract321over 4 years ago[windows]: Active Directory forensic framework
Pasco: Examines the contents of Internet Explorer's cache files for forensic purposes. |
PcapXray1,700over 4 years ago: Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight important communication and file extraction
ReplayProxy25over 4 years ago: Forensic tool to replay web-based attacks (and also general HTTP traffic) that were captured in a pcap file
Pdfbook-analyzer: Utility for facebook memory forensics
Pdfid2,051almost 2 years ago: Scan a file to look for certain PDF keywords
PdfResurrect81about 4 years ago: A tool aimed at analyzing PDF documents
Peepdf1,319about 2 years ago: A Python tool to explore PDF files in order to find out if the file can be harmful or not
Pev3over 3 years ago: Command line based tool for PE32/PE32+ file analysis
Rekall1,931almost 6 years ago: Memory Forensic Framework
Recuperabit549over 2 years ago: A tool for forensic file system reconstruction
Rifiuti2143over 2 years ago: A rewrite of rifiuti, a great tool from Foundstone folks for analyzing Windows Recycle Bin INFO2 file
Rkhunter: Checks machines for the presence of rootkits and other unwanted tools
Sleuthkit2,648almost 2 years ago: A library and collection of command line digital forensics tools that allow you to investigate volume and file system data
Swap-digger515about 5 years ago: A tool used to automate Linux swap analysis during post-exploitation or forensics
Vinetto: A forensics tool to examine Thumbs.db files
Volafox166about 10 years ago: macOS Memory Analysis Toolkit
Volatility7,412over 3 years ago: Advanced memory forensics framework
Xplico183about 6 years ago: Internet Traffic Decoder. Network Forensic Analysis Tool (NFAT)

Awesome-anti-forensic / Tools / Data tampering

Exiftool11,537over 2 years ago: Reader and rewriter of EXIF informations that supports raw files
Exiv2946over 1 year ago: Exif, Iptc and XMP metadata manipulation library and tools
nTimetools45about 5 years ago: Timestomper and Timestamp checker with nanosecond accuracy for NTFS volumes
Scalpel628over 2 years ago: An open source data carving tool
SetMace50almost 12 years ago: Manipulate timestamps on NTFS

Awesome-anti-forensic / Tools / Hiding process

Harness10about 7 years ago: Execute ELFs in memory
Unhide: A forensic tool to find processes hidden by rootkits, LKMs or by other techniques
Kaiser87almost 8 years ago: File-less persistence, attacks and anti-forensic capabilities (Windows 7 32-bit)
Papa Shango5about 7 years ago: Inject code into running processes with ptrace()
Saruman128over 8 years ago: ELF anti-forensics exec, for injecting full dynamic executables into process image (With thread injection)

Awesome-anti-forensic / Tools / Cleaner / Data Destruction / Wiping / FileSystem

BleachBit3,131almost 2 years ago: System cleaner for Windows and Linux
ChainSaw: ChainSaw automates the process of shredding log files and bash history from a system. It is a tool that cleans up the bloody mess you left behind when you went for a stroll behind enemy lines
Clear-EventLog: Powershell Command. Clears all entries from specified event logs on the local or remote computers
DBAN: Darik's Boot and Nuke ("DBAN") is a self-contained boot image that securely wipes the hard disks of most computers. DBAN is appropriate for bulk or emergency data destruction
delete-self-poc505about 2 years ago: A way to delete a locked file, or current running executable, on disk
Forensia736about 3 years ago: Anti Forensics Tool For Red Teamers, Used For Erasing Footprints In The Post Exploitation Phase
Hdparm: get/set hard disk parameters
LogKiller310over 5 years ago: Clear all your logs in linux/windows servers
Meterpreter > clearev1,758over 1 year ago: The meterpreter clearev command will clear the Application, System, and Security logs on a Windows system
NTFS-3G1,027over 2 years ago: NTFS-3G Safe Read/Write NTFS Driver
Nuke My LUKS45about 10 years ago: Network panic button designed to overwrite with random data the LUKS header of computers in a LAN
Permanent-Eraser22about 5 years ago: Secure file erasing utility for macOS
Shred: Overwrite a file to hide its contents, and optionally delete it
Silk-guardian679over 2 years ago: An anti-forensic kill-switch that waits for a change on your usb ports and then wipes your ram, deletes precious files, and turns off your computer
Srm: Srm is a command-line compatible rm which overwrites file contents before unlinking
Wipe48over 3 years ago: A Unix tool for secure deletion
Wipedicks129almost 7 years ago: Wipe files and drives securely with randoms ASCII dicks
wiper77over 3 years ago: Toolkit to perform secure destruction of sensitive virtual data, temporary files and swap memories

Awesome-anti-forensic / Tools / Password and Login

chntpw: Offline NT Password Editor - reset passwords in a Windows NT SAM user database file
lazagne9,661almost 2 years ago: An open source application used to retrieve lots of passwords stored on a local computer
Mimipenguin3,844over 3 years ago: A tool to dump the login password from the current linux user

Awesome-anti-forensic / Tools / Encryption / Obfuscation

BurnEye65over 14 years ago: ELF encryption program
cryptsetup: Utility used to conveniently set up disk encryption based on the DMCrypt kernel module

Awesome-anti-forensic / Tools / Encryption / Obfuscation / cryptsetup

cryptsetup-nuke-password: Configure a special "nuke password" that can be used to destroy the encryption keys required to unlock the encrypted partitions

Awesome-anti-forensic / Tools / Encryption / Obfuscation

ELFcrypt114about 6 years ago: ELF crypter
FreeOTFE: A free "on-the-fly" transparent disk encryption program for PC & PDAs
Midgetpack197about 12 years ago: Midgetpack is a multiplatform secure ELF packer
panic_bcast224almost 5 years ago: Decentralized opsec panic button operating over UDP broadcasts and HTTP. Provides automatic ejection of encrypted drives as a safe-measure against cold-boot attacks
Sherlocked104almost 12 years ago: Universal script packer-- transforms any type of script into a protected ELF executable, encrypted with anti-debugging

Awesome-anti-forensic / Tools / Encryption / Obfuscation / Sherlocked

suicideCrypt8almost 9 years ago: A toolset for creating cryptographically strong volumes that destroy themselves upon tampering (event) or via issued command

Awesome-anti-forensic / Tools / Encryption / Obfuscation

Tchunt-ng52almost 8 years ago: Reveal encrypted files stored on a filesystem
TrueHunter30over 5 years ago: Detect TrueCrypt containers using a fast and memory efficient approach

Awesome-anti-forensic / Tools / Policies / Logging (Event) / Monitoring

Auditpol: Displays information about and performs functions to manipulate audit policies in Windows
evtkit18over 10 years ago: Fix acquired .evt - Windows Event Log files (Forensics) [windows]
Grokevt10about 2 years ago: A collection of scripts built for reading Windows® NT/2K/XP/2K eventlog files. [windows]
Lfle27almost 11 years ago: Recover event log entries from an image by heurisitically looking for record structures
python-evtx732about 2 years ago: A tool to parse the Windows XML Event Log (EVTX) format
USBGuard: Software framework for implementing USB device authorization policies (what kind of USB devices are authorized) as well as method of use policies (how a USB device may interact with the system)
wecutil: Enables you to create and manage subscriptions to events that are forwarded from remote computers. The remote computer must support the WS-Management protocol. [windows]
Wevtutil: Enables you to retrieve information about event logs and publishers. You can also use this command to install and uninstall event manifests, to run queries, and to export, archive, and clear logs (windows server)

Awesome-anti-forensic / Tools / Steganography

AudioStego269over 3 years ago: Hides text or files inside audio files and retrieve them automatically
ChessSteg87about 5 years ago: Steganography in chess games
Cloakify1,566almost 6 years ago: Transforms any filetype into a list of harmless-looking strings. This lets you hide the file in plain sight, and transfer the file without triggering alerts
Jsteg616over 3 years ago: jsteg is a package for hiding data inside jpeg files
Mp3nema8about 13 years ago: A tool aimed at analyzing and capturing data that is hidden between frames in an MP3 file or stream, otherwise noted as "out of band" data
PacketWhisper624over 5 years ago: Stealthily exfiltrate data and defeat attribution using DNS queries and text-based steganography
steg86292almost 2 years ago: Format-agnostic steganographic tool for x86 and AMD64 binaries. You can use it to hide information in compiled programs, regardless of executable format (PE, ELF, Mach-O, raw, &c)
steganography1,000over 2 years ago: Simple C++ Image Steganography tool to encrypt and hide files insde images using Least-Significant-Bit encoding
Steganography581almost 2 years ago: Least Significant Bit Steganography for bitmap images (.bmp and .png), WAV sound files, and byte sequences
StegaStamp701almost 3 years ago: Invisible Hyperlinks in Physical Photographs
StegCloak3,329almost 2 years ago: Hide secrets with invisible characters in plain text securely using passwords
Stegdetect408almost 8 years ago: Automated tool for detecting steganographic content in images
StegFS26over 4 years ago: A FUSE based steganographic file system
Steghide: Steganography program that is able to hide data in various kinds of image- and audio-files
Stegify1,210over 3 years ago: Go tool for LSB steganography, capable of hiding any file within an image
Stego266over 4 years ago: stego is a steganographic swiss army knife

Awesome-anti-forensic / Tools / Steganography / Stego

StegoGAN312over 3 years ago: A tool for creating steganographic images using adversarial training

Awesome-anti-forensic / Tools / Steganography

stego-toolkit2,425almost 4 years ago: This project is a Docker image useful for solving Steganography challenges as those you can find at CTF platforms
StegoVeritas360about 3 years ago: Yet another Stego Tool
tweetable-polyglot-png2,554about 5 years ago: Pack up to 3MB of data into a tweetable PNG polyglot file

Awesome-anti-forensic / Tools / Malware / AV

Malheur369over 7 years ago: A tool for the automatic analyze of malware behavior
MalwareDetect1,210almost 3 years ago: Submits a file's SHA1 sum to VirusTotal to determine whether it is a known piece of malware

Awesome-anti-forensic / Tools / OS/VM

HiddenVM2,370about 2 years ago: Use any desktop OS without leaving a trace
Tails: portable operating system that protects against surveillance and censorship

Awesome-anti-forensic / Tools / Hardware

BusKill187almost 2 years ago: BusKill is an hardware and software project that uses a hardware tripwire/dead-man-switch to trigger a computer to lock or shutdown if the user is physically separated from their machine
Day Tripper3,679almost 3 years ago: Hide-My-Windows Laser Tripwire
DoNotDisturb296over 5 years ago: Security tool for macOS that aims to detect unauthorized physical access to your laptop
Silk Guardian679over 2 years ago: Anti-forensic kill-switch that waits for a change on your usb ports and then wipes your ram, deletes precious files, and turns off your computer
USB Kill4,458over 2 years ago: Anti-forensic kill-switch that waits for a change on your USB ports and then immediately shuts down your computer
USB Death126over 9 years ago: Anti-forensic tool that writes udev rules for known usb devices and do some things at unknown usb insertion or specific usb device removal
xxUSBSentinel65over 3 years ago: Windows anti-forensics USB monitoring tool

Awesome-anti-forensic / Tools / Android App

Lockup330about 2 years ago: A proof-of-concept Android application to detect and defeat some of the Cellebrite UFED forensic toolkit extraction techniques
Ripple235almost 2 years ago: A "panic button" app for triggering a "ripple effect" across apps that are set up to respond to panic events

Backlinks from these awesome lists:

More related projects: