Linux Evidence Acquisition Framework
-
Updated
Sep 30, 2024 - Python
Linux Evidence Acquisition Framework
A memory forensics automation tool that wraps Volatility 3, runs plugins, detects suspicious activity (malicious processes, code injection, network anomalies), and generates professional reports from a single command. Supports Windows, Linux, and macOS.
Digital forensics and incident response (DFIR) reference: evidence handling, memory/disk forensics workflows, and chain-of-custody procedures for enterprise investigations
Evidence-preserving digital forensics primitives and composable workflows for analysts, automation systems, and autonomous agents.
Add a description, image, and links to the linux-forensics topic page so that developers can more easily learn about it.
To associate your repository with the linux-forensics topic, visit your repo's landing page and select "manage topics."