foremost
Foremost is a console program to recover files based on their headers, footers, and internal data structures. This process is commonly referred to as data carving. Foremost can work on image files, such as those generated by dd, Safeback, Encase, etc, or directly on a drive. The headers and footers can be specified by a configuration file or you can use command line switches to specify built-in file types. These built-in types look at the data structures of a given file format allowing for a more reliable and faster recovery. Originally developed by the United States Air Force Office of Special Investigations and The Center for Information Systems Security Studies and Research , foremost has been opened to the general public. We welcome any comments, suggestions, patches, or feedback you have on this program. Please direct all correspondence to [email protected]. (by korczis)
binwalk
Firmware Analysis Tool (by ReFirmLabs)
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
foremost
Posts with mentions or reviews of foremost.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2021-04-24.
-
PSA: steganography and FNAF: Help Wanted's Hidden Images
Just so you know, I threw just about everything I could think of at those images and came up with zilch. Yes, including that. And that. (Don't forget, steghide doesn't work on PNGs anyway.) No, there isn't any interesting metadata in any of the files as far as I can tell. No hidden alpha layers. I even tried stacking the only four images that are all the same size -- numbers 1, 2, 12, and 15, for the record -- on top of each other and messed around with the opacity to see if they'd add up to anything. Nada.
binwalk
Posts with mentions or reviews of binwalk.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2023-11-09.
- HTB - Pilgrimage Writeup
-
Is it possible to extract firmware through a USB-C cable
https://github.com/ReFirmLabs/binwalk/wiki/Quick-Start-Guide here's how to extract firmware
-
Mounting 20-year-old OpenBSD drive under macOS?
If you can get them attached to something, I wouldn’t bother trying to mount then, just dump the contents and use something inker binwalk to figure things out and see if it can extract things.
-
Sketchy USB Update
With that said, I'll repeat what i said last post, run binwalker on the image. Nothing that anyone is saying here is probably going to work because that doesn't have any features of an FS image
-
Unknown USB Files - How to view?
Op, run binwalk. Don't just run it though an hex editor, you won't understand anything. It's a forensics tool to analyze unknown binary blobs (much better than gitbash that someone mentioned). It can also unpack these files automatically, there's no better universal tool for it
-
Trying to find hex in bin file
Not sure if it would be easier or not, but you could also use binwalk to find a binary string in a file.
- An unidentified filesystem while analyzing a firmware
- Caffè Italia * 05/02/23
-
Security Advisory: Remote Command Execution in binwalk
Not true, it's still not patched. See https://github.com/ReFirmLabs/binwalk/pull/617
-
Show HN: Unblob – extraction suite for 30+ file formats
Looks nice! Kind of reminds me of binwalk: https://github.com/ReFirmLabs/binwalk
What are some alternatives?
When comparing foremost and binwalk you can also consider the following projects:
unblob - Extract files from any kind of container formats
osx-dictionary - CLI for OSX Dictionary.app
Wireshark - Read-only mirror of Wireshark's Git repository at https://gitlab.com/wireshark/wireshark. ⚠️ GitHub won't let us disable pull requests. ⚠️ THEY WILL BE IGNORED HERE ⚠️ Upload them at GitLab instead.
ghidra - Ghidra is a software reverse engineering (SRE) framework
chipsec - Platform Security Assessment Framework
pfSense - Main repository for pfSense
dictionary-api
icu - The home of the ICU project source code.
tcpdump - the TCPdump network dissector
dtrx - Do The Right Extraction
declensions - Russian Declension-o-matic - search for declension tables on Wiktionary