
scalpel
File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

Hive v5 file decryption algorithm

Analyze and help extract older "hidden" versions of a pdf from the current pdf.

Utility for recovering ES File Explorer encrypted files (.eslock)

Binary and Directory tree comparison tool using Fuzzy Hashing

This is the development tree. Production downloads are at:

A python tool that will extract exif data from picture with two methods


Extracts and decrypts the 4-digit restriction passcode from iPhone backups on Windows machines, enabling recovery of device access controls.

Python SDK for removing hidden metadata from files (PDF, Office, images) to protect privacy and prevent data leakage via automated cleaning workflows.

Panic button for protection against cold boot attacks

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

Portable binary distribution of xz-utils 5.8.3 with CVE-2024-3094 verification. Provides static builds for Linux, macOS, and Windows for compression…

ParanoiDF - PDF Analysis Suite based on PeePDF by Jose Miguel Esparza (http://peepdf.eternal-todo.com/). Tools added: Password cracking, redaction…

Manage BitLocker recovery keys, monitor drive encryption status, and unlock volumes through a portable interface for Windows.

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.