Skip to content
/ FACT Public

FACT is a cutting-edge forensic tool designed to revolutionize digital investigation and to help FORENSIC examiner to ACT Smartly

License

Notifications You must be signed in to change notification settings

IRB0T/FACT

Repository files navigation

FACT - Forensic Artifact Comprehensive Triage

FACT - Designed to help FORENSIC professionals to ACT smartly

FACT is designed to automate repetitive tasks and reduces the examiner efforts and expedite the investigation by extracting vital artifacts from a mounted device, and there after apply advanced intelligence to uncover details.

Features

  • It provides a wealth of essential details about the target device, including Host-name, IP-Address, Domain Accounts, Local Accounts, and many more.
  • One of its standout features is the ability to construct a comprehensive timeline by detecting crucial key events from Eventlogs, offering a crystal-clear chronology of activities performed on the target device.
  • Currently FACT Tool is focusing on key event pertaining to Account Logon Activities, Suspicious RDP connection, Activities related to New Account Creation/Deletion, Software Installation/Uninstallation Activity, Eventlog clearing, Windows Defender Event Analysis.

Tech

FACT uses number of tools/software which you may have previously utilized like: Arsenal Image Mounter, RegRipper, KAPE, CyLR, Eric Zimmerman tools, Flask Framework

Installation

Just Download FACT executable from following link: FACT and Run it as Administrator.
!that's all it required!

How To Use

Click to watch video
Watch the video

Development

Want to contribute? Reach out to us via email "developeronvacation@gmail.com"

License

MIT

** Free Software **

FACT : Forensic-Artifact-Comprehensive-Triage

About

FACT is a cutting-edge forensic tool designed to revolutionize digital investigation and to help FORENSIC examiner to ACT Smartly

Resources

License

Stars

Watchers

Forks

Packages

No packages published