#1Tools for analyzing hard drives, SSDs, and other storage media to recover data and artifacts.
Kitploit recommended

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…


Undelete and recover accidentally erased files from ext3 and ext4 filesystems, using inode scanning and block recovery for forensic and data-loss…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Forensic Scanner

Python script for carving Bitlocker VMK keys

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Digital Forensics Intelligence Framework

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

Copies data from damaged or failing storage devices, handles read errors, and performs efficient rescue operations to recover as much data as…

d

A forensic evidence collection & analysis toolkit for OS X