737 B

Forensics

Disk Forensics

dd

strings

$ strings /tmp/mem.dump | grep BOOT_
$ BOOT_IMAGE=/vmlinuz-3.5.0-23-generic

scalpel

TrID

binwalk

foremost

ExifTool

Hex editors

dff

CAINE

The Sleuth Kit


Memory Forensics

memdump

Volatility: Analysing Dumps


Scripts

PDFs

Tools to test a PDF file:

  • pdfid
  • pdf-parser

References