Forensics
Ninguna herramienta coincide.
-
Compresses and extracts archives, including formats you meet when carving disks or unpacking drops.
ayuda
7-Zip 26.02 (x64) : Copyright (c) 1999-2026 Igor Pavlov : 2026-06-25 64-bit locale=en_US.UTF-8 Threads:4 OPEN_MAX:4096, ASM Usage: 7z <command> [<switches>...] <archive_name> [<file_names>...] [@listfile] Note: If <file_names> is not specified, 7z implicitly uses "." as <file_names>. This means recursively add/delete/extract files to/from <archive_name>. <Commands> a : Add files to archive b : Benchmark d : Delete files from archive e : Extract files from archive (without using directory names) h : Calculate hash values for files i : Show information about supported formats l : List contents of archive rn : Rename files in archive t : Test integrity of archive u : Update files to archive x : eXtract files with full paths <Switches> -- : Stop switches and @listfile parsing -ai[r[-|0]][m[-|2]][w[-]]{@listfile|!wildcard} : Include archives -ax[r[-|0]][m[-|2]][w[-]]{@listfile|!wildcard} : eXclude archives -ao{a|s|t|u} : set Overwrite mode -an : disable archive_name field -bb[0-3] : set output log level -bd : disable progress indicator -bs{o|e|p}{0|1|2} : set output stream for output/error/progress line -bt : show execution time statistics -i[r[-|0]][m[-|2]][w[-]]{@listfile|!wildcard} : Include filenames -m{Parameters} : set compression Method -mmt[N] : set number of CPU threads -mx[N] : set compression level: -mx1 (fastest) ... -mx9 (ultra) -o{Directory} : set Output directory -p{Password} : set Password -r[-|0] : Recurse subdirectories for name search -sa{a|e|s} : set Archive name mode -scc{UTF-8|WIN|DOS} : set charset for console input/output -scs{UTF-8|UTF-16LE|UTF-16BE|WIN|DOS|{id}} : set charset for list files -scrc[CRC32|CRC64|SHA256|SHA1|XXH64|*] : set hash function for x, e, h commands -sdel : delete files after compression -seml[.] : send archive by email … (25 more lines — see the tool's home page) -
afflib-toolsweb
Utilities for the Advanced Forensics Format: convert, verify, and inspect disk images without rewriting evidence.
-
autopsyweb
GUI digital forensics platform over disk images for timeline and file analysis practice.
ayuda
Invalid flag: --help usage: /usr/bin/autopsy [-c] [-C] [-d evid_locker] [-i device filesystem mnt] [-p port] [remoteaddr] -c: force a cookie in the URL -C: force NO cookie in the URL -d dir: specify the evidence locker directory -i device filesystem mnt: Specify info for live analysis -p port: specify the server port (default: 9999) remoteaddr: specify the host with the browser (default: localhost) -
Carves emails, URLs, and other features from disk or memory images without mounting the filesystem.
ayuda
bulk_extractor version 2.1.1: A high-performance flexible digital forensics program. Usage: bulk_extractor [OPTION...] image_name -A, --offset_add arg Offset added (in bytes) to feature locations (default: 0) -b, --banner_file arg Path of file whose contents are prepended to top of all feature files -C, --context_window arg Size of context window reported in bytes (default: 16) -d, --debug arg enable debugging (default: 1) -D, --debug_help help on debugging -E, --enable_exclusive arg disable all scanners except the one specified. Same as -x all -E scanner. -e, --enable arg enable a scanner (can be repeated) -x, --disable arg disable a scanner (can be repeated) -f, --find arg search for a pattern (can be repeated) -F, --find_file arg read patterns to search from a file (can be repeated) -G, --pagesize arg page size in bytes (default: 16777216) -g, --marginsize arg margin size in bytes (default: 4194304) -j, --threads arg number of threads (default: 4) -J, --no_threads read and process data in the primary thread -M, --max_depth arg max recursion depth (default: 12) --max_bad_alloc_errors arg max bad allocation errors (default: 3) --max_minute_wait arg maximum number of minutes to wait until all data are read (default: 60) --notify_main_thread Display notifications in the main thread after phase1 completes. Useful for running with ThreadSanitizer --notify_async Display notificaitons asynchronously (default) -o, --outdir arg output directory [REQUIRED] -P, --scanner_dir arg directories for scanner shared libraries (can be repeated). Default directories include /usr/local/lib/bulk_extractor, /usr/lib/bulk_extractor and any directories specified in the BE_PATH environment variable. -p, --path arg print the value of <path>[:length][/h][/r] with optional length, hex output, or raw output. -q, --quit no status or performance output -r, --alert_list arg file to read alert list from -R, --recurse treat image file as a directory to recursively explore -S, --set arg set a name=value option (can be repeated) … (102 more lines — see the tool's home page) -
cabextract
Unpacks Microsoft Cabinet archives you meet in installers and forensic artifacts.
-
chkrootkitweb
Looks for known rootkit signatures on a Unix host you administer.
-
dc3ddweb
Forensic-friendly dd with hashing and error handling while imaging disks you may seize.
-
dcflddweb
dd variant with on-the-fly hashing and split output for evidence-grade imaging practice.
-
dumpzillaweb
Extracts forensic artifacts from Mozilla browser profiles during workstation reviews.
-
exifprobeweb
Dumps EXIF and related metadata from image files during evidence triage.
-
exiv2web
Reads and writes image metadata; useful for scrubbing or inspecting photo evidence.
ayuda
Usage: exiv2 [ option [ arg ] ]+ [ action ] file ... Image metadata manipulation tool. Where file is one or more files, optionally containing a URL (http, https, ftp, sftp, data or file) or wildcard Actions: pr | print Print image metadata (default is a summary). This is the default action ad | adjust Adjust Exif timestamps by the given time. Requires at least one of -a, -Y, -O or -D rm | delete Deletes image metadata, use -d to choose type to delete (default is all) in | insert Insert metadata from .exv, .xmp, thumbnail or .icc file. Use option -S to change the suffix of the input files and -l to change the location ex | extract Extract metadata to .exv, .xmp, preview image, thumbnail, or ICC profile. Use option -S to change the suffix of the input files and -l to change the location mv | rename Rename files and/or set file timestamps according to the Exif timestamps. The filename format can be set with -r format, timestamp options are controlled with -t and -T mo | modify Apply commands to modify the Exif, IPTC and XMP metadata. Requires option -m or -M fi | fixiso Copy ISO setting from Canon and Nikon makernotes, to the standard Exif tag fc | fixcom Convert the Unicode Exif user comment to UCS-2. The current character encoding can be specified with the -n option Options: -h Display this help and exit -V Show the program version and exit -v Be verbose during the program run -q Silence warnings and error messages (quiet) -Q lvl Set log-level to d(ebug), i(nfo), w(arning), e(rror) or m(ute) -b Obsolete, reserved for use with the test suit -u Show unknown tags (e.g., Exif.SonyMisc3c.0x022b) -g str Only output where 'str' matches in output text (grep) Append /i to 'str' for case insensitive -K key Only output where 'key' exactly matches tag's key -n enc Character set to decode Exif Unicode user comments -k Preserve file timestamps when updating files (keep) -t Set the file timestamp from Exif metadata when renaming (overrides -k) -T Only set the file timestamp from Exif metadata ('rename' action) … (95 more lines — see the tool's home page) -
ext4magicweb
Recovers deleted files from ext4 filesystems during lab disk repair drills.
-
firmware-mod-kitweb
Unpacks and repacks firmware images when you study embedded device labs.
-
foremostweb
File carving from disk images based on headers and footers during forensics practice.
ayuda
foremost version 1.5.7 by Jesse Kornblum, Kris Kendall, and Nick Mikus. $ foremost [-v|-V|-h|-T|-Q|-q|-a|-w-d] [-t <type>] [-s <blocks>] [-k <size>] [-b <size>] [-c <file>] [-o <dir>] [-i <file] -V - display copyright information and exit -t - specify file type. (-t jpeg,pdf ...) -d - turn on indirect block detection (for UNIX file-systems) -i - specify input file (default is stdin) -a - Write all headers, perform no error detection (corrupted files) -w - Only write the audit file, do not write any detected files to the disk -o - set output directory (defaults to output) -c - set configuration file to use (defaults to foremost.conf) -q - enables quick mode. Search are performed on 512 byte boundaries. -Q - enables quiet mode. Suppress output messages. -v - verbose mode. Logs all messages to screen -
forensic-artifactsweb
Curated artifact definitions that tell collectors where OS evidence usually lives.
-
forensics-colorizeweb
Colourizes hexdumps so similar regions stand out during manual carving.
-
galletaweb
Parses Internet Explorer cookie files during Windows host forensics.
-
Debugger for native binaries when you are stepping through memory and crashes in a lab.
ayuda
Usage: /usr/bin/gcore [-h|--help] [-v|--version] [-a] [-o prefix] [-d data-directory] pid1 [pid2...pidN] Create a core file of a running program using GDB. -h, --help Print this message then exit. -v, --version Print version information then exit. -a Dump all memory mappings. -o prefix Use 'prefix.pid' as the core file name. The default prefix is 'core'. -d dir Pass '--data-directory dir' as an argument to GDB. -
gpartweb
Guesses lost PC partition tables from leftover signatures after someone wiped the table but not the data.
-
gpartedweb
Graphical partition editor for resizing and labeling disks in a forensic or lab workstation workflow.
ayuda
Error executing command as another user: No authentication agent found. -
grokevtweb
Parses Windows Event Log files offline so you can read what a captured host already recorded.
-
hashdeepweb
Walks trees computing hashes (and piecewise hashes) so you can compare corpora or prove a file set did not change.
ayuda
hashdeep version 4.4 by Jesse Kornblum and Simson Garfinkel. $ hashdeep [OPTION]... [FILES]... -c <alg1,[alg2]> - Compute hashes only. Defaults are MD5 and SHA-256 legal values: md5,sha1,sha256,tiger,whirlpool, -p <size> - piecewise mode. Files are broken into blocks for hashing -r - recursive mode. All subdirectories are traversed -d - output in DFXML (Digital Forensics XML) -k <file> - add a file of known hashes -a - audit mode. Validates FILES against known hashes. Requires -k -m - matching mode. Requires -k -x - negative matching mode. Requires -k -w - in -m mode, displays which known file was matched -M and -X act like -m and -x, but display hashes of matching files -e - compute estimated time remaining for each file -s - silent mode. Suppress all error messages -b - prints only the bare name of files; all path information is omitted -l - print relative paths for filenames -i/-I - only process files smaller than the given threshold -o - only process certain types of files. See README/manpage -v - verbose mode. Use again to be more verbose -d - output in DFXML; -W FILE - write to FILE. -j <num> - use num threads (default 4) -
inetsimweb
Simulates common Internet services locally so malware or clients under study think they reached the real net.
ayuda
INetSim 1.3.2 (2020-05-19) by Matthias Eckert & Thomas Hungenberg Usage: /usr/bin/inetsim [options] Available options: --help Print this help message. --version Show version information. --config=<filename> Configuration file to use. --log-dir=<directory> Directory logfiles are written to. --data-dir=<directory> Directory containing service data. --report-dir=<directory> Directory reports are written to. --bind-address=<IP address> Default IP address to bind services to. Overrides configuration option 'default_bind_address'. --max-childs=<num> Default maximum number of child processes per service. Overrides configuration option 'default_max_childs'. --user=<username> Default user to run services. Overrides configuration option 'default_run_as_user'. --faketime-init-delta=<secs> Initial faketime delta (seconds). Overrides configuration option 'faketime_init_delta'. --faketime-auto-delay=<secs> Delay for auto incrementing faketime (seconds). Overrides configuration option 'faketime_auto_delay'. --faketime-auto-incr=<secs> Delta for auto incrementing faketime (seconds). Overrides configuration option 'faketime_auto_increment'. --session=<id> Session id to use. Defaults to main process id. --pidfile=<filename> Pid file to use. Defaults to '/run/inetsim.pid'. -
libhivex-binweb
Command-line readers and writers for Windows Registry hive files you pulled from disk or memory.
-
Assembles and disassembles Android Dalvik bytecode (smali) when jadx is not enough.
ayuda
usage: baksmali [--version] [--help] [<command [<args>]] Options: --help,-h,-? - Show usage information --version,-v - Print the version of baksmali and then exit Commands: deodex(de,x) - Deodexes an odex/oat file disassemble(dis,d) - Disassembles a dex file. dump(du) - Prints an annotated hex dump for the given dex file help(h) - Shows usage information list(l) - Lists various objects in a dex file. See baksmali help <command> for more information about a specific command -
lvm2web
Linux Logical Volume Manager tools for assembling volume groups you encounter on seized or lab disks.
-
mac-robberweb
Collects allocated-file metadata from a mounted filesystem for timeline work without touching file contents.
-
Carves files by magic-byte signatures when the filesystem metadata is gone but the blocks remain.
ayuda
dupemap: invalid option -- 'h' Error parsing options. Usage: dupemap [OPTIONS] OPERATION PATH... Where OPERATION is one of the operations listed in the manpage. Options: -d DATABASE Read/write from a database on disk -I FILE Read input file names from this file ("-" for stdin) -m MINSIZE Exclude files below this size -M MAXSIZE Exclude files above this size -
Reads Microsoft Access MDB files so leaked databases become tables you can inspect offline.
ayuda
mdb-array is deprecated and will disappear in a future version of mdbtools. Please drop us a line if you have any use of it. See https://github.com/mdbtools/mdbtools/issues/197 Usage: mdb-array <file> <table> -
memdumpweb
Dumps process or system memory to stdout so you can feed later carving or string analysis.
-
metacamweb
Pulls EXIF and camera metadata from image files when provenance matters in a case or lab writeup.
-
missidentifyweb
Finds Win32 PE files that were renamed to look harmless; useful triage on mixed evidence trees.
-
nasmweb
General-purpose x86 assembler for shellcode labs, boot stubs, and reading what compilers emit.
ayuda
Usage: nasm [-@ response_file] [options...] [--] filename Options: -v (or --v) print the NASM version number and exit -@ file response file; one command line option per line -h list command line options and exit (also --help) -h -opt show additional help for option "-opt" -h all show all available command line help -h topics show list of help topics (also -h list) -o outfile write output to outfile --keep-all output files will not be removed even if an error happens -Xformat specify error reporting format (see -h -X) -s redirect messages to stdout -Zfile redirect messages to file --info[=lvl] display optional informational messages --debug[=lvl] display NASM internal debugging messages -M... generate Makefile dependencies (see -h -M) -f format select output file format (see -h -f) -g generate debugging information -F format select a debugging format (see -h -F) -gformat same as -g -F format -l listfile write listing to a list file -Lflags... add information to the list file (see -h -L) -Oflags... select optimization (see -h -O) -t assemble in limited SciTech TASM compatible mode -E (or -e) preprocess only (writes output to stdout by default) -a don't preprocess (assemble only) -Ipath add a pathname to the include file path -Pfile pre-include a file (also --include) -Dmacro[=str] pre-define a macro -Umacro undefine a macro -w+x enable warning x (see -h -w)(also -Wx) -w-x disable warning x (also -Wno-x) -w[+-]error promote all warnings to errors (also -Werror) -w[+-]error=x promote warning x to errors (also -Werror=x) --pragma str pre-executes a specific %pragma --before str add line (usually a preprocessor statement) before the input --bits nn set bits to nn (equivalent to --before "BITS nn") --no-line ignore %line directives in input --gprefix str prepend the given string to the names of all extern, common and global symbols (also --prefix) --gpostfix str append the given string to the names of all extern, common and global symbols (also --postfix) --lprefix str prepend the given string to local symbols --lpostfix str append the given string to local symbols --reproducible attempt to produce run-to-run identical output … (1 more lines — see the tool's home page) -
nastyweb
Helps recover a forgotten GnuPG passphrase with constrained guessing when you own the keyring.
-
partedweb
Scriptable disk partition manipulator for imaging workstations and rebuild labs.
ayuda
Usage: parted [OPTION]... [DEVICE [COMMAND [PARAMETERS]...]...] Apply COMMANDs with PARAMETERS to DEVICE. If no COMMAND(s) are given, run in interactive mode. OPTIONs: -h, --help displays this help message -l, --list lists partition layout on all block devices -m, --machine displays machine parseable output -j, --json displays JSON output -s, --script never prompts for user intervention -f, --fix in script mode, fix instead of abort when asked -v, --version displays the version -a, --align=[none|cyl|min|opt] alignment for new partitions COMMANDs: align-check TYPE N check partition N for TYPE(min|opt) alignment help [COMMAND] print general help, or help on COMMAND mklabel,mktable LABEL-TYPE create a new disklabel (partition table) mkpart PART-TYPE [FS-TYPE] START END make a partition name NUMBER NAME name partition NUMBER as NAME print [devices|free|list,all] display the partition table, or available devices, or free space, or all found partitions quit exit program rescue START END rescue a lost partition near START and END resizepart NUMBER END resize partition NUMBER rm NUMBER delete partition NUMBER select DEVICE choose the device to edit disk_set FLAG STATE change the FLAG on selected device disk_toggle [FLAG] toggle the state of FLAG on selected device set NUMBER FLAG STATE change the FLAG on partition NUMBER toggle [NUMBER [FLAG]] toggle the state of FLAG on partition NUMBER type NUMBER TYPE-ID or TYPE-UUID type set TYPE-ID or TYPE-UUID of partition NUMBER unit UNIT set the default unit to UNIT version display the version number and copyright information of GNU Parted Report bugs to bug-parted@gnu.org -
pascoweb
Parses Internet Explorer cache artifacts into a readable table for browser timeline work.
-
pdf-parserweb
Breaks a PDF into objects so you can see streams, filters, and suspicious actions without a GUI viewer.
ayuda
This program has not been tested with this version of Python (3.14.6) Should you encounter problems, please use Python version 3.13.9 Usage: pdf-parser [options] pdf-file|zip-file|url pdf-parser, use it to parse a PDF document Options: --version show program's version number and exit -h, --help show this help message and exit -m, --man Print manual -s SEARCH, --search=SEARCH string to search in indirect objects (except streams) -f, --filter pass stream object through filters (FlateDecode, ASCIIHexDecode, ASCII85Decode, LZWDecode and RunLengthDecode only) -o OBJECT, --object=OBJECT id(s) of indirect object(s) to select, use comma (,) to separate ids (version independent) -r REFERENCE, --reference=REFERENCE id of indirect object being referenced (version independent) -e ELEMENTS, --elements=ELEMENTS type of elements to select (cxtsi) -w, --raw raw output for data and filters -a, --stats display stats for pdf document -t TYPE, --type=TYPE type of indirect object to select -O, --objstm parse stream of /ObjStm objects -v, --verbose display malformed PDF elements -x EXTRACT, --extract=EXTRACT filename to extract malformed content to -H, --hash display hash of objects -n, --nocanonicalizedoutput do not canonicalize the output -d DUMP, --dump=DUMP filename to dump stream content to -D, --debug display debug info -c, --content display the content for objects without streams or with streams without filters --searchstream=SEARCHSTREAM string to search in streams --unfiltered search in unfiltered streams --casesensitive case sensitive search in streams --regex use regex to search in streams --overridingfilters=OVERRIDINGFILTERS override filters with given filters (use raw for the raw stream content) -g, --generate generate a Python program that creates the parsed PDF … (13 more lines — see the tool's home page) -
pdfidweb
Scans PDFs for keywords that often mark active content (JS, OpenAction) before you open the file.
ayuda
Usage: pdfid [options] [pdf-file|zip-file|url|@file] ... Tool to test a PDF file Arguments: pdf-file and zip-file can be a single file, several files, and/or @file @file: run PDFiD on each file listed in the text file specified wildcards are supported Source code put in the public domain by Didier Stevens, no Copyright Use at your own risk https://DidierStevens.com Options: --version show program's version number and exit -h, --help show this help message and exit -s, --scan scan the given directory -a, --all display all the names -e, --extra display extra data, like dates -f, --force force the scan of the file, even without proper %PDF header -d, --disarm disable JavaScript and auto launch -p PLUGINS, --plugins=PLUGINS plugins to load (separate plugins with a comma , ; @file supported) -c, --csv output csv data when using plugins -m MINIMUMSCORE, --minimumscore=MINIMUMSCORE minimum score for plugin results output -v, --verbose verbose (will also raise catched exceptions) -S SELECT, --select=SELECT selection expression -n, --nozero supress output for counts equal to zero -o OUTPUT, --output=OUTPUT output to log file --pluginoptions=PLUGINOPTIONS options for the plugin -l, --literalfilenames take filenames literally, no wildcard matching --recursedir Recurse directories (wildcards and here files (@...) allowed) -
plasoweb
Plaso metapackage for building super-timelines from many artifact parsers in one pipeline.
-
pst-utilsweb
Reads Microsoft Outlook PST mailboxes so you can export messages without Outlook itself.
-
python3-capstoneweb
Python bindings to Capstone for disassembling blobs inside your own analysis scripts.
-
python3-dfdatetimeweb
Digital-forensics date/time helpers so parsers agree on timestamps across artifacts.
-
python3-dfvfsweb
Virtual filesystem layer for opening disk images and volumes from Python forensic tooling.
-
python3-dfwinregweb
Python library for walking Windows Registry hives the same way dfvfs-based tools expect.
-
python3-distorm3web
Python bindings to diStorm for fast x86/AMD64 disassembly in custom scripts.
-
readpeweb
Inspects Windows PE headers, imports, and sections from the command line without a heavy GUI.
-
reglookupweb
Queries Windows Registry hives with SQL-like paths for targeted forensic answers.
-
regripperweb
Plugin-driven Windows Registry hive ripper that prints the high-signal keys first.
ayuda
Rip v.3.0 - CLI RegRipper tool Rip [-r Reg hive file] [-f profile] [-p plugin] [options] Parse Windows Registry files, using either a single module, or a profile. NOTE: This tool does NOT automatically process Registry transaction logs! The tool does check to see if the hive is dirty, but does not automatically process the transaction logs. If you need to incorporate transaction logs, please consider using yarp + registryFlush.py, or rla.exe from Eric Zimmerman. -r [hive] .........Registry hive file to parse -d ................Check to see if the hive is dirty -g ................Guess the hive file type -a ................Automatically run hive-specific plugins -aT ...............Automatically run hive-specific TLN plugins -f [profile].......use the profile -p [plugin]........use the plugin -l ................list all plugins -c ................Output plugin list in CSV format (use with -l) -s systemname......system name (TLN support) -u username........User name (TLN support) -uP ...............Update default profiles -h.................Help (print this information) Ex: C:\>rip -r c:\case\system -f system C:\>rip -r c:\case\ntuser.dat -p userassist C:\>rip -r c:\case\ntuser.dat -a C:\>rip -l -c All output goes to STDOUT; use redirection (ie, > or >>) to output to a file. copyright 2020 Quantum Analytics Research, LLC -
rephraseweb
Specialized GnuPG passphrase recovery helper when you remember parts of the phrase.
-
rifiutiweb
Parses legacy Windows Recycle Bin INFO2 artifacts for deleted-file names and times.
-
rifiuti2web
Modern replacement for rifiuti covering newer Recycle Bin formats on later Windows.
-
rkhunterweb
Rootkit hunter scanning for suspicious binaries and kernel module oddities.
-
rsakeyfindweb
Scans memory images for BER-encoded RSA private keys left behind by careless processes.
-
safecopyweb
Data recovery copier that retries and skips bad regions instead of aborting the whole image.
-
scalpelweb
Fast, filesystem-independent file carver driven by header/footer rules you configure.
ayuda
Scalpel version 1.60 Written by Golden G. Richard III, based on Foremost 0.69. Carves files from a disk image based on file headers and footers. Usage: scalpel [-b] [-c <config file>] [-d] [-h|V] [-i <file>] [-m blocksize] [-n] [-o <outputdir>] [-O num] [-q clustersize] [-r] [-s num] [-t <blockmap file>] [-u] [-v] <imgfile> [<imgfile>] ... -b Carve files even if defined footers aren't discovered within maximum carve size for file type [foremost 0.69 compat mode]. -c Choose configuration file. -d Generate header/footer database; will bypass certain optimizations and discover all footers, so performance suffers. Doesn't affect the set of files carved. **EXPERIMENTAL** -h Print this help message and exit. -i Read names of disk images from specified file. -m Generate/update carve coverage blockmap file. The first 32bit unsigned int in the file identifies the block size. Thereafter each 32bit unsigned int entry in the blockmap file corresponds to one block in the image file. Each entry counts how many carved files contain this block. Requires more memory and disk. **EXPERIMENTAL** -n Don't add extensions to extracted files. -o Set output directory for carved files. -O Don't organize carved files by type. Default is to organize carved files into subdirectories. -p Perform image file preview; audit log indicates which files would have been carved, but no files are actually carved. -q Carve only when header is cluster-aligned. -r Find only first of overlapping headers/footers [foremost 0.69 compat mode]. -s Skip n bytes in each disk image before carving. -t Set directory for coverage blockmap. **EXPERIMENTAL** -u Use carve coverage blockmap when carving. Carve only sections of the image whose entries in the blockmap are 0. These areas are treated as contiguous regions. **EXPERIMENTAL** -V Print copyright information and exit. -v Verbose mode. -
CLI forensics toolkit for file system analysis that powers many higher-level GUIs.
ayuda
blkcalc: invalid option -- 'h' Invalid argument: (null) usage: blkcalc [-dsu unit_addr] [-vV] [-f fstype] [-i imgtype] [-b dev_sector_size] [-o imgoffset] [-P pooltype] [-B pool_volume_block] image [images] Slowly calculates the opposite block number One of the following must be given: -d: The given address is from a 'dd' image -s: The given address is from a 'blkls -s' (slack) image -u: The given address is from a 'blkls' (unallocated) image -f fstype: The file system type (use '-f list' for supported types) -i imgtype: The format of the image file (use '-i list' for supported types) -b dev_sector_size: The size (in bytes) of the device sectors -o imgoffset: The offset of the file system in the image (in sectors) -P pooltype: Pool container type (use '-P list' for supported types) -B pool_volume_block: Starting block (for pool volumes only) -v: verbose output to stderr -V: Print version -
ssdeepweb
Computes fuzzy (piecewise) hashes so near-duplicate malware or docs still match.
-
tcpdumpweb
Command-line packet capture for quick filters when you do not need a full Wireshark session.
ayuda
tcpdump version 4.99.6 libpcap version 1.10.6 (64-bit time_t, with TPACKET_V3) OpenSSL 3.6.3 9 Jun 2026 64-bit build, 64-bit time_t Usage: tcpdump [-AbdDefghHIJKlLnNOpqStuUvxX#] [ -B size ] [ -c count ] [--count] [ -C file_size ] [ -E algo:secret ] [ -F file ] [ -G seconds ] [ -i interface ] [ --immediate-mode ] [ -j tstamptype ] [ -M secret ] [ --number ] [ --print ] [ -Q in|out|inout ] [ -r file ] [ -s snaplen ] [ -T type ] [ --version ] [ -V file ] [ -w file ] [ -W filecount ] [ -y datalinktype ] [ --time-stamp-precision precision ] [ --micro ] [ --nano ] [ -z postrotate-command ] [ -Z user ] [ expression ] -
tcpickweb
Sniffs and tracks TCP connections with a focus on reconstructing useful stream views.
ayuda
tcpick 0.2.1 is a sniffer tool written using libpcap. tcpick can keep track of tcp connection, sniff all tcp streams and store them to files, to show you what is happening on a network interface Usage: tcpick [ -a ] [ -n ] [ -C ] [ -i interface ] [ -yH ] [ -yP ] [ -yR ] [ -yU ] [ -yx ] [ -yX ] [ -bH ] [ -bP ] [ -bR ] [ -bU ] [ -bx ] [ -bX ] [ -wH ] [ -wP ] [ -wR ] [ -wU ] [ -v [ verbosity ]] [ -S ] [ -h ] [ --separator ] [ "filter" ] [ -r file ] [ --help ] [ --version ] Example: tcpick -i ppp0 -yP -C -h "not port 22" for an updated list of options see tcpick(1) manpage to see version and license information try `tcpick --version' or read the `COPYING' file, released with the package tcpick homepage: http://tcpick.sourceforge.net mailing-list address: <tcpick-project@lists.sourceforge.net> Archive: http://sourceforge.net/mailarchive/forum.php?forum=tcpick-project Subscribe: http://lists.sourceforge.net/lists/listinfo/tcpick-project thank you for using tcpick! -
unarweb
Extracts many archive formats you meet when unpacking drops or evidence bags.
-
unhideweb
Looks for hidden processes and ports that rootkits try to keep off ordinary listings.
-
Extracts RAR archives, including many of the passworded drops you see in malware kits.
ayuda
ERROR: Unknown option: h -
upx-uclweb
Packs or unpacks UPX-compressed executables so analysis can start from the real image.
ayuda
Ultimate Packer for eXecutables Copyright (C) 1996 - 2024 UPX 4.2.4 Markus Oberhumer, Laszlo Molnar & John Reiser May 9th 2024 Usage: upx-ucl [-123456789dlthVL] [-qvfk] [-o file] file.. Commands: -1 compress faster -9 compress better --best compress best (can be slow for big files) -d decompress -l list compressed file -t test compressed file -V display version number -h give this help -L display software license Options: -q be quiet -v be verbose -oFILE write output to 'FILE' -f force compression of suspicious files --no-color, --mono, --color, --no-progress change look Compression tuning options: --lzma try LZMA [slower but tighter than NRV] --brute try all available compression methods & filters [slow] --ultra-brute try even more compression variants [very slow] Backup options: -k, --backup keep backup files --no-backup no backup files [default] Overlay options: --overlay=copy copy any extra data attached to the file [default] --overlay=strip strip any extra data attached to the file [DANGEROUS] --overlay=skip don't compress a file with an overlay File system options: --force-overwrite force overwrite of output files --link preserve hard links (Unix only) [USE WITH CARE] --no-link do not preserve hard links but rename files [default] --no-mode do not preserve file mode (aka permissions) --no-owner do not preserve file ownership --no-time do not preserve file timestamp Options for djgpp2/coff: --coff produce COFF output [default: EXE] Options for dos/com: … (81 more lines — see the tool's home page) -
vinettoweb
Parses Windows Thumbs.db caches to recover thumbnail evidence of images that lived there.
-
wceweb
Windows Credentials Editor style helper for studying how plaintext and hash material appears in memory on lab Windows hosts.
ayuda
> wce ~ Windows Credentials Editor /usr/share/windows-resources/wce ├── getlsasrvaddr.exe ├── README ├── wce32.exe ├── wce64.exe └── wce-universal.exe = -
winregfsweb
Mounts Windows Registry hives as a FUSE filesystem so you can browse keys like directories.
-
xmountweb
Remounts disk images into other formats (raw, VMDK, and friends) without recopying the bytes.
-
xplicoweb
Network forensic analysis toolkit that turns pcaps into reconstructed protocols and objects.
-
yaraweb
Pattern-matching language and scanner for describing malware families and hunting them in files or memory.
Cuando hay un propósito escrito para esta ruta, se muestra primero. Si no, ves el resumen del paquete. La ayuda se captura en vivo desde un Kali cuando está disponible.