DFIR Toolkit

Table of contents

Overview of timelining tools

Installation

bash cargo install dfir-toolkit

Tools

Command-Line Help for cleanhive

This document contains the help content for the cleanhive command-line program.

Command Overview:

cleanhive

merges logfiles into a hive file

Usage: cleanhive [OPTIONS] --output <DST_HIVE> <HIVE_FILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for es4forensics

This document contains the help content for the es4forensics command-line program.

Command Overview:

es4forensics

CLI tools for digital forensics and incident response

Usage: es4forensics [OPTIONS] --index <INDEX_NAME> --password <PASSWORD> <COMMAND>

Subcommands:
Options:

es4forensics create-index

Usage: es4forensics create-index

es4forensics import

Usage: es4forensics import [OPTIONS] [INPUT_FILE]

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for evtx2bodyfile

This document contains the help content for the evtx2bodyfile command-line program.

Command Overview:

evtx2bodyfile

CLI tools for digital forensics and incident response

Usage: evtx2bodyfile [OPTIONS] [EVTX_FILES]...

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for evtxanalyze

This document contains the help content for the evtxanalyze command-line program.

Command Overview:

evtxanalyze

CLI tools for digital forensics and incident response

Usage: evtxanalyze [OPTIONS] <COMMAND>

Subcommands:
Options:

evtxanalyze pstree

generate a process tree

Usage: evtxanalyze pstree [OPTIONS] <EVTX_FILE>

Arguments:
Options:

evtxanalyze sessions

display sessions

Usage: evtxanalyze sessions [OPTIONS] <EVTX_FILES_DIR>

Arguments:
Options:

evtxanalyze session

display one single session

Usage: evtxanalyze session <EVTX_FILES_DIR> <SESSION_ID>

Arguments:

This document was generated automatically by clap-markdown.

Command-Line Help for evtxcat

This document contains the help content for the evtxcat command-line program.

Command Overview:

evtxcat

CLI tools for digital forensics and incident response

Usage: evtxcat [OPTIONS] <EVTX_FILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for evtxls

This document contains the help content for the evtxls command-line program.

Command Overview:

evtxls

CLI tools for digital forensics and incident response

Usage: evtxls [OPTIONS] [EVTX_FILES]...

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for evtxscan

This document contains the help content for the evtxscan command-line program.

Command Overview:

evtxscan

CLI tools for digital forensics and incident response

Usage: evtxscan [OPTIONS] <EVTX_FILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for hivescan

This document contains the help content for the hivescan command-line program.

Command Overview:

hivescan

scans a registry hive file for deleted entries

Usage: hivescan [OPTIONS] <HIVE_FILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for ipgrep

This document contains the help content for the ipgrep command-line program.

Command Overview:

ipgrep

CLI tools for digital forensics and incident response

Usage: ipgrep [OPTIONS] [FILE]...

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for mactime2

This document contains the help content for the mactime2 command-line program.

Command Overview:

mactime2

CLI tools for digital forensics and incident response

Usage: mactime2 [OPTIONS]

Options:

This document was generated automatically by clap-markdown.

Command-Line Help for pol_export

This document contains the help content for the pol_export command-line program.

Command Overview:

pol_export

CLI tools for digital forensics and incident response

Usage: pol_export [OPTIONS] <POLFILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.

Command-Line Help for regdump

This document contains the help content for the regdump command-line program.

Command Overview:

regdump

CLI tools for digital forensics and incident response

Usage: regdump [OPTIONS] <HIVE_FILE>

Arguments:
Options:

This document was generated automatically by clap-markdown.