YARA Capability
The yara plugin scans files inside a forensic target using local rule files. Files above the configured maximum size are skipped; rule checking and decompression are configurable.
An independent tool index
for incident response teams
Digital forensics EU-developed
Opens forensic images and file collections for cross-platform artifact analysis through a modular Python framework and command-line investigation tools.
By Fox-IT · Netherlands
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
Upstream identifies Dutch Fox-IT's Dissect Team as developer.
Fox-IT is part of UK-based NCC Group; Dutch development does not imply EU ownership or hosting. Count the suite once, not its parser modules.
identity / origin / capabilities / deployment
README credits Fox-IT's Dissect Team and documents installation, artifact analysis and target-query/target-shell CLI.
Read sourcelicense
Actual license text is GNU Affero General Public License version 3.
Read sourcecountry / maintenance
Verified developer organization states Netherlands, NCC Group affiliation and a repository update on 9 October 2026.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
The yara plugin scans files inside a forensic target using local rule files. Files above the configured maximum size are skipped; rule checking and decompression are configurable.
Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.
A digital forensics triage and evidence workflow