Skip to content

Latest commit

 

History

History
34 lines (26 loc) · 1.19 KB

README.md

File metadata and controls

34 lines (26 loc) · 1.19 KB

dfir

Collection of the most popular and widely used open-source forensic tools in a lightweight and fast docker image.

Overview

Focus what on what matters the most! Memory (volatility), registry (regripper), filesystem (sleuthkit).

Volatility comes with extra community plugins to speed up your investigations.

The Docker image is based on Alpine Linux, the most lightweight linux container distribution. Kudos to the SANS team, providing some of the tools

Install Docker

Wait! It's dangerous to go alone!

Make sure you have the Docker engine installed. Click here for detailed installation instructions.

Build from Docker registry (Recommended)

Just :

sudo docker pull nov3mb3r/dfir

Simple isn't it?

Run

To deploy a container from the created image :

sudo docker run -it nov3mb3r/dfir /bin/ash

Access your case files with a shared folder between your working directory and the container.

Make sure you don't spoil your evidence files, by granting read-only permissions to the container.
$ sudo docker run -it -v ~/cases:/cases:ro nov3mb3r/dfir /bin/ash