Workshop: Forensic Analysis of eBPF based Linux Rootkits
-
Updated
Jul 9, 2026 - C
Workshop: Forensic Analysis of eBPF based Linux Rootkits
Useful tools for (not only) digital forensics
Run FTK Imager directly from a portable USB or WinFE environment to perform forensic imaging without installing software on the target system.
ForensicTools automatise l’acquisition forensique multi-plateforme (Windows, Linux, macOS) : collecte d’artefacts volatils et persistants, capture mémoire, copie bit-à-bit des disques, chaîne de custody, gestion des dossiers d’enquête et orchestration d’outils d’analyse (Volatility3, Plaso, YARA, Sleuth Kit).
ForenScope‑IR‑Platform is an enterprise‑grade, modular digital forensics and incident response solution for rapid evidence collection, IOC extraction, YARA scanning, and AI‑driven anomaly detection.
To associate your repository with the live-forensics topic, visit your repo's landing page and select "manage topics."