
RecuperaBit
A tool for forensic file system reconstruction.

A tool for forensic file system reconstruction.

Utility for recovering ES File Explorer encrypted files (.eslock)

Tool to extract the $UsnJrnl from an NTFS volume

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Offline, open-source web app for passkey-based file encryption and sharing. AES-256-GCM/HPKE, no cloud, no accounts; encrypt to recipients with…

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

Tool to securely and efficiently wipe devices and partiitions for Linux

A tool to recover from ESXiArgs ransomware

Rip Raw is a small tool to analyse the memory of compromised Linux systems.


GUI forensic tool for acquiring and analyzing Telegram data from Android devices. Parses messages, media, and metadata; generates integrity-verified…

Windows memory forensics tool for dumping files from process memory regions, searching byte patterns (PDF, JPG, SWF), and performing live process…

Crack ios Restriction PassCode in Python

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

FAT filesystems explore, extract, repair, and forensic tool

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303