{"id":20822025,"url":"https://github.com/mikehorn-git/docker-forensic-toolbox","last_synced_at":"2025-05-11T21:31:00.720Z","repository":{"id":181460564,"uuid":"666811734","full_name":"MikeHorn-git/docker-forensic-toolbox","owner":"MikeHorn-git","description":"A docker CLI toolbox for forensics investigations.","archived":true,"fork":false,"pushed_at":"2024-03-19T22:12:46.000Z","size":64,"stargazers_count":0,"open_issues_count":0,"forks_count":1,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-03-12T06:30:24.779Z","etag":null,"topics":["cli","docker","forensics","investigations"],"latest_commit_sha":null,"homepage":"https://hub.docker.com/r/mikehorn/dft","language":"Dockerfile","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/MikeHorn-git.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-07-15T16:50:37.000Z","updated_at":"2024-06-14T21:10:20.000Z","dependencies_parsed_at":"2024-02-04T19:23:11.496Z","dependency_job_id":"fa775fc7-a302-4435-b526-9e61310a7e88","html_url":"https://github.com/MikeHorn-git/docker-forensic-toolbox","commit_stats":null,"previous_names":["mikehorn-git/docker-forensic-toolbox"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/MikeHorn-git%2Fdocker-forensic-toolbox","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/MikeHorn-git%2Fdocker-forensic-toolbox/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/MikeHorn-git%2Fdocker-forensic-toolbox/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/MikeHorn-git%2Fdocker-forensic-toolbox/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/MikeHorn-git","download_url":"https://codeload.github.com/MikeHorn-git/docker-forensic-toolbox/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":253638843,"owners_count":21940433,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cli","docker","forensics","investigations"],"created_at":"2024-11-17T22:13:45.464Z","updated_at":"2025-05-11T21:31:00.461Z","avatar_url":"https://github.com/MikeHorn-git.png","language":"Dockerfile","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Docker Forensic Toolbox\n\n![Whale](https://github.com/MikeHorn-git/docker-forensic-toolbox/assets/123373126/b6897176-b7dd-4cec-ae55-9bcdc93c6e12)\n\n# Informations\n* Credential : forensic:forensic\n* From : Debian Bookworm Slim.\n* Size : Around 900MB.\n* Time : Few minutes to build. Depending on your system.\n* Trivy : 0 unfixed vulnerabilities.\n\n# Installation\n## Docker Hub\n```bash\nsudo docker pull mikehorn/dft:latest\n```\n\n## Build Yourself\n```bash\ngit clone https://github.com/MikeHorn-git/docker-forensic-toolbox.git\ncd docker-forensic-toolbox\n```\n\n### Docker Compose\n```bash\nsudo docker-compose up -d\n```\n\n### Dockerfile\n```bash\nsudo docker build -t \"dft\" .\n```\n\n# Tools\n* [aLEAPP](https://github.com/abrignoni/ALEAPP)                       - Android Logs Events And Protobuf Parser.\n* [Binwalk](https://github.com/ReFirmLabs/binwalk)                    - Firmware Analysis Tool.\n* [Exiftool](https://github.com/exiftool/exiftool)                    - ExifTool meta information reader/writer.\n* [Ewf-tools](https://github.com/libyal/libewf)                       - Library to access the Expert Witness Compression Format.\n* [Foremost](https://github.com/korczis/foremost)                     - File carving.\n* [File](https://packages.debian.org/bookworm/file)                   - Recognize the type of data in a file using \"magic\" numbers.\n* [Hindsights](https://github.com/obsidianforensics/hindsight)        - Web browser forensics for Google Chrome/Chromium.\n* [iLEAPP](https://github.com/abrignoni/iLEAPP)                       - IOS Logs, Events, And Plist Parser.\n* [Loki](https://github.com/Neo23x0/Loki)                             - Simple IOC and YARA Scanner.\n* [Mac-robber](https://www.kali.org/tools/mac-robber/)                - Collects data from allocated files in a mounted file system.\n* [Mvtt](https://github.com/mvt-project/mvt)                           - Conducting forensics of mobile devices in order to find signs of a potential compromise.\n* [Nano](https://www.nano-editor.org/)                                - Small, friendly text editor inspired by Pico.\n* [Ntfs-3g](https://github.com/tuxera/ntfs-3g)                        - Safe Read/Write NTFS Driver.\n* [Parted](https://wiki.archlinux.org/title/Parted)                   - A program for creating, destroying, resizing, checking and copying partitions.\n* [Python-evt](https://github.com/williballenthin/python-evt)         - Pure Python parser for classic Windows Event Log files (.evt).\n* [Python-ntfs](https://github.com/williballenthin/python-ntfs)       - Open source Python library for NTFS analysis.\n* [Recuperabit](https://github.com/Lazza/RecuperaBit)                 - A tool for forensic file system reconstruction.\n* [Regripper](https://github.com/keydet89/RegRipper3.0)               - RegRipper is an open source forensic software used as a Windows Registry data extraction tool.\n* [Sleuthkit](https://github.com/sleuthkit/sleuthkit)                 - Library and collection of command line digital forensics tools.\n* [Stegoveritas](https://github.com/bannsec/stegoVeritas)             - Yet another Stego Tool.\n* [Tshark](https://www.wireshark.org/docs/man-pages/tshark.html)      - Dump and analyze network traffic.\n* [Vim](https://www.vim.org/)                                         - Vi Improved, a highly configurable, improved version of the vi text editor.\n* [Volatility3](https://github.com/volatilityfoundation/volatility3)  - Advanced memory forensics framework.\n* [Xmount](https://www.pinguin.lu/xmount)                             - Tool to crossmount between multiple input and output harddisk image files.\n* [Yara](https://github.com/VirusTotal/yara)                          - The pattern matching swiss knife.\n\n# Security\n* The forensic Docker image is scanned with [trivy](https://github.com/aquasecurity/trivy) to improve security.\n* Install [docker-bench-security](https://github.com/docker/docker-bench-security) for hardening your host.\n\n# Versions 1.2\n* Add docker-compose.yml.\n\n# Versions 1.1\n* Add new tools (iLEAPP, python-evt, python-ntfs).\n* Add security sections and update protobof version for patch vulns [CVE-2021-22570 and CVE-2022-1941] detected with trivy.\n* Delete tools.txt.\n* Remove miscellaneous tools (htop, john, ssdeep) for a lighter image.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmikehorn-git%2Fdocker-forensic-toolbox","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmikehorn-git%2Fdocker-forensic-toolbox","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmikehorn-git%2Fdocker-forensic-toolbox/lists"}