diff --git a/README.md b/README.md index 819fd4a..490383c 100644 --- a/README.md +++ b/README.md @@ -916,6 +916,10 @@ My curated list of awesome links, resources and tools This is a GUI (for Windows 64 bit) for a procedure to virtualize your EWF(E01), DD(Raw), AFF disk image file without converting it, directly with VirtualBox, forensically proof. + + OSSEC + Open Source HIDS SECurity + williballenthin/INDXParse Tool suite for inspecting NTFS artifacts