Documentation
¶
Overview ¶
Package dfirgen writes a deterministic synthetic Windows triage tree: event logs, registry hives, prefetch files, IIS logs and PowerShell history. Sizes scale with a total budget, content comes from a seeded RNG so runs are reproducible, and a known subset of text files carries the IOCMarker string so a grep pass has an exact expected hit count. Test data only; no file here is a real forensic artifact.
Index ¶
Constants ¶
View Source
const IOCMarker = "KD-DFIR-IOC"
IOCMarker is the string a triage grep hunts for. Clearly synthetic on purpose: the tests need an exact count, not realism.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
Click to show internal directories.
Click to hide internal directories.