
filekey
Offline, open-source web app for passkey-based file encryption and sharing. AES-256-GCM/HPKE, no cloud, no accounts; encrypt to recipients with…

Offline, open-source web app for passkey-based file encryption and sharing. AES-256-GCM/HPKE, no cloud, no accounts; encrypt to recipients with…

bad stuffs by bad guys

Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

Hive v5 file decryption algorithm

Library to access the Windows Shell Item format

Utility for recovering ES File Explorer encrypted files (.eslock)

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.


android location service cache dumper

This is the development tree. Production downloads are at:

A python tool that will extract exif data from picture with two methods

Cellebrite Physical Analyzer python scripts to aid analysts with extended functionality

Panic button for protection against cold boot attacks

Manage BitLocker recovery keys, monitor drive encryption status, and unlock volumes through a portable interface for Windows.

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.