dfir.nix (910B)
1 # modules/features/pentest/dfir.nix — forensics and incident response. 2 # Off by default: not CPTS material. `daemon.pentest.dfir.enable = true;` 3 { lib, ... }: 4 (import ./_sets.nix { inherit lib; }) { 5 name = "dfir"; 6 description = "memory, disk, log and artefact forensics"; 7 default = false; 8 9 packages = pkgs: with pkgs; [ 10 volatility3 # `vol`, `volshell` 11 sleuthkit # fls, icat, blkls, fsstat, … 12 yara 13 capa 14 chainsaw # Windows event log hunting 15 hayabusa # Sigma over EVTX 16 exiftool 17 foremost 18 testdisk # testdisk, photorec 19 chntpw # offline SAM / registry editing 20 binwalk 21 steghide stegseek zsteg # stego: jpg/wav, steghide brute force, png/bmp 22 ]; 23 24 expectedBins = [ 25 "vol" "volshell" "fls" "icat" "fsstat" "yara" "capa" 26 "chainsaw" "hayabusa" "exiftool" "foremost" "testdisk" "photorec" 27 "chntpw" "binwalk" 28 "steghide" "stegseek" "zsteg" 29 ]; 30 }