So I played around with/used for work #Dissect and it's truly a powerful #dfir tool.
Features that I especially like:
- works on a huge variety of file types
- all the tools needed in a single tool/terminal
- runs on multiple files in parallel
- analyse and explore (shell) images without mounting the fs
- can extract the most important artifacts of an image an generates a much smaller *.tar archive of it (perfect for quick triage and sending files)
- lots of options to filter results from the command line
I think it will be my goto tool for future analyses.
There is also the possibility to use it to create images, but atm, the open source version requires some additional tools/steps to make it work.
Code and doc:
https://docs.dissect.tools/en/stable/
https://github.com/fox-it/dissect
Introduction:
https://m.youtube.com/watch?v=zPii-YV_fe0&pp=ygUMRGlzc2VjdCBkZmly0gcJCYcKAYcqIYzv
#fox-it #opensource
