DFIR Toolkit

Table of contents

Overview of timelining tools

Installation

bash cargo install dfir-toolkit

Tools

Command-Line Help for cleanhive

This document contains the help content for the cleanhive command-line program.

Command Overview:

cleanhive

merges logfiles into a hive file

Usage: cleanhive [OPTIONS] --output <DST_HIVE> <HIVE_FILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for dfir-toolkit

This document contains the help content for the dfir-toolkit command-line program.

Command Overview:

dfir-toolkit

CLI tools for digital forensics and incident response

Usage: dfir-toolkit [OPTIONS] --index <INDEX_NAME> --password <PASSWORD> <COMMAND>

Subcommands:
Options:

dfir-toolkit create-index

Usage: dfir-toolkit create-index

dfir-toolkit import

Usage: dfir-toolkit import [OPTIONS] [INPUT_FILE]

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for dfir-toolkit

This document contains the help content for the dfir-toolkit command-line program.

Command Overview:

dfir-toolkit

CLI tools for digital forensics and incident response

Usage: dfir-toolkit [OPTIONS] [EVTX_FILES]...

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for dfir-toolkit

This document contains the help content for the dfir-toolkit command-line program.

Command Overview:

dfir-toolkit

Usage: dfir-toolkit [OPTIONS] <COMMAND>

Subcommands:
Options:

dfir-toolkit pstree

generate a process tree

Usage: dfir-toolkit pstree [OPTIONS] <EVTX_FILE>

Arguments:
Options:

dfir-toolkit sessions

display sessions

Usage: dfir-toolkit sessions [OPTIONS] <EVTX_FILES_DIR>

Arguments:
Options:

dfir-toolkit session

display one single session

Usage: dfir-toolkit session <EVTX_FILES_DIR> <SESSION_ID>

Arguments:

This document was generated automatically by clap-markdown.

Command-Line Help for evtxcat

This document contains the help content for the evtxcat command-line program.

Command Overview:

evtxcat

Display one or more events from an evtx file

Usage: evtxcat [OPTIONS] <EVTX_FILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for dfir-toolkit

This document contains the help content for the dfir-toolkit command-line program.

Command Overview:

dfir-toolkit

CLI tools for digital forensics and incident response

Usage: dfir-toolkit [OPTIONS] [EVTX_FILES]...

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for evtxscan

This document contains the help content for the evtxscan command-line program.

Command Overview:

evtxscan

Find time skews in an evtx file

Usage: evtxscan [OPTIONS] <EVTX_FILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for dfir-toolkit

This document contains the help content for the dfir-toolkit command-line program.

Command Overview:

dfir-toolkit

scans a registry hive file for deleted entries

Usage: dfir-toolkit [OPTIONS] <HIVE_FILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for dfir-toolkit

This document contains the help content for the dfir-toolkit command-line program.

Command Overview:

dfir-toolkit

CLI tools for digital forensics and incident response

Usage: dfir-toolkit [OPTIONS] [FILE]...

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for dfir-toolkit

This document contains the help content for the dfir-toolkit command-line program.

Command Overview:

dfir-toolkit

CLI tools for digital forensics and incident response

Usage: dfir-toolkit [OPTIONS]

Options:

This document was generated automatically by clap-markdown.

Command-Line Help for dfir-toolkit

This document contains the help content for the dfir-toolkit command-line program.

Command Overview:

dfir-toolkit

CLI tools for digital forensics and incident response

Usage: dfir-toolkit [OPTIONS] <POLFILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for regdump

This document contains the help content for the regdump command-line program.

Command Overview:

regdump

CLI tools for digital forensics and incident response

Usage: regdump [OPTIONS] <HIVE_FILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.