This is the Linux app named Live-Forensicator whose latest release can be downloaded as NewAdditionssourcecode.tar.gz. It can be run online in the free hosting provider OnWorks for workstations.
Download and run online this app named Live-Forensicator with OnWorks for free.
Follow these instructions in order to run this app:
- 1. Downloaded this application in your PC.
- 2. Enter in our file manager https://www.onworks.net/myfiles.php?username=XXXXX with the username that you want.
- 3. Upload this application in such filemanager.
- 4. Start the OnWorks Linux online or Windows online emulator or MACOS online emulator from this website.
- 5. From the OnWorks Linux OS you have just started, goto our file manager https://www.onworks.net/myfiles.php?username=XXXXX with the username that you want.
- 6. Download the application, install it and run it.
SCREENSHOTS
Ad
Live-Forensicator
DESCRIPTION
Live-Forensicator is a cross-platform suite of scripts designed to assist incident responders and forensic investigators in performing “live forensics” / “live incident response.” It collects a wide variety of system artifacts, indicators, logs, hashes, network info, and suspicious files on a running system (Windows, macOS, Linux) to help identify anomalous behavior, possible compromises, ransomware evidence, etc. It outputs its findings in readable formats (HTML, indexed reports) but doesn’t itself make decisions — investigators must analyze the outputs. It includes modules for detecting suspicious paths/files, analyzing event logs (on Windows), capturing network traffic, hashing files against known malicious hash databases, etc.
Features
- For Windows: PowerShell module that retrieves system info, event logs (looking for particular IDs), hashes of executables, PowerShell commands, browsing history, etcetera
- For Linux/macOS: Bash/shell scripts using native commands to gather similar forensic-relevant info, hunting for unusual files, collecting system config, logs etcetera
- Option to encrypt collected artifacts using AES with a randomly generated key (on Windows) to preserve confidentiality/integrity during transport etcetera
- Ability to capture network traffic (pcapng) for further analysis in tools like Wireshark
- HTML report output including an index file, so the collected artifacts are organized in working directory with easy navigation
- Ability to search through the system for files with certain extensions like known ransomware file types, looking for anomalies or possible malicious files etcetera
Programming Language
JavaScript
Categories
This is an application that can also be fetched from https://sourceforge.net/projects/live-forensicator.mirror/. It has been hosted in OnWorks in order to be run online in an easiest way from one of our free Operative Systems.