
btrfs_fixes
Custom BTRFS repair tools for severe extent tree corruption where btrfs check --repair fails (segfault, loop, or deadlock)

Custom BTRFS repair tools for severe extent tree corruption where btrfs check --repair fails (segfault, loop, or deadlock)

A tool for forensic file system reconstruction.

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

Hash database builder and reverse lookup tool — SHA256, RIPEMD160, Keccak256, BLAKE3 and more

Search and extract blob files on the Ethereum Blockchain network

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Depix is a PoC for a technique to recover plaintext from pixelized screenshots.

This is the development tree. Production downloads are at:

Panic button for protection against cold boot attacks

Detection and sanitization for Acropalypse Now - CVE-2023-21036

Hive v5 file decryption algorithm

Python script for carving Bitlocker VMK keys

Manage BitLocker recovery keys, monitor drive encryption status, and unlock volumes through a portable interface for Windows.

X-Ways Acropalypse extension detects CVE-2023-21036 in common images

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal