<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://xn--e-br-noa.de/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://xn--e-br-noa.de/feed.php">
        <title>E-Bärs Xopedia - soc:irt:linux:tools</title>
        <description></description>
        <link>https://xn--e-br-noa.de/</link>
        <image rdf:resource="https://xn--e-br-noa.de/lib/exe/fetch.php?media=wiki:dokuwiki.svg" />
       <dc:date>2026-06-11T23:19:46+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://xn--e-br-noa.de/doku.php?id=soc:irt:linux:tools:dissect&amp;rev=1781187001&amp;do=diff"/>
                <rdf:li rdf:resource="https://xn--e-br-noa.de/doku.php?id=soc:irt:linux:tools:start&amp;rev=1781187098&amp;do=diff"/>
                <rdf:li rdf:resource="https://xn--e-br-noa.de/doku.php?id=soc:irt:linux:tools:uac&amp;rev=1781186466&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://xn--e-br-noa.de/lib/exe/fetch.php?media=wiki:dokuwiki.svg">
        <title>E-Bärs Xopedia</title>
        <link>https://xn--e-br-noa.de/</link>
        <url>https://xn--e-br-noa.de/lib/exe/fetch.php?media=wiki:dokuwiki.svg</url>
    </image>
    <item rdf:about="https://xn--e-br-noa.de/doku.php?id=soc:irt:linux:tools:dissect&amp;rev=1781187001&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-11T14:10:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Dissect</title>
        <link>https://xn--e-br-noa.de/doku.php?id=soc:irt:linux:tools:dissect&amp;rev=1781187001&amp;do=diff</link>
        <description>Dissect



    dissect.apfs
    dissect.archive
    dissect.btrfs
    dissect.cim
    dissect.clfs
    dissect.cramfs
    dissect.cstruct
    dissect.database
    dissect.etl
    dissect.eventlog
    dissect.evidence
    dissect.executable
    dissect.extfs
    dissect.fat
    dissect.ffs
    dissect.fve
    dissect.hypervisor
    dissect.jffs
    dissect.ntfs
    dissect.ole
    dissect.qnxfs
    dissect.regf
    dissect.shellitem
    dissect.squashfs
    dissect.target
    dissect.thumbcache
 …</description>
    </item>
    <item rdf:about="https://xn--e-br-noa.de/doku.php?id=soc:irt:linux:tools:start&amp;rev=1781187098&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-11T14:11:38+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Tools (Linux IRT)</title>
        <link>https://xn--e-br-noa.de/doku.php?id=soc:irt:linux:tools:start&amp;rev=1781187098&amp;do=diff</link>
        <description>Tools (Linux IRT)

	*  Unix Artefacts Collector
	*  Visidata
	*  Dissect
		*  &lt;https://github.com/fox-it/dissect&gt;
		*  quick access and analysis of various disk and file formats

	*  ryoshi
			*  &lt;https://github.com/fkie-cad/ryoshi&gt;
			*  Detec hidden files (hidden by rootkits)</description>
    </item>
    <item rdf:about="https://xn--e-br-noa.de/doku.php?id=soc:irt:linux:tools:uac&amp;rev=1781186466&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-11T14:01:06+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Unix Artefacts Collector</title>
        <link>https://xn--e-br-noa.de/doku.php?id=soc:irt:linux:tools:uac&amp;rev=1781186466&amp;do=diff</link>
        <description>Unix Artefacts Collector

&lt;https://github.com/tclahr/uac&gt;
&lt;https://tclahr.github.io/uac-docs/&gt;


Collect all artifacts based on the ir_triage profile, and save the output file to /tmp.

./uac -p ir_triage /tmp

Collect all artifacts located in the artifacts/live_response directory, and save the output file to /tmp.

./uac -a ./artifacts/live_response/\* /tmp

Collect all artifacts based on the ir_triage profile, along with all artifacts located in the /my_custom_artifacts directory, and save the…</description>
    </item>
</rdf:RDF>
