
libvmdk
Library and tools to access the VMware Virtual Disk (VMDK) format

Library and tools to access the VMware Virtual Disk (VMDK) format

Digital forensics suite for DJI drones that parses telemetry files, extracts hidden data via steganography, visualizes flight paths, and detects…

Library and tools to access the Virtual Hard Disk (VHD) image format

Library and tools to access the Volume Shadow Snapshot (VSS) format

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Tool to securely and efficiently wipe devices and partiitions for Linux

ATAboy is a user-friendly bridge that allows legacy CHS only style IDE (PATA) hard drives to be connected to a modern computer as a standard USB Mass…

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Panic button for protection against cold boot attacks

Wipe, reinstall or restore your system from running GNU/Linux distribution. Via SSH, without rebooting.

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

ParanoiDF - PDF Analysis Suite based on PeePDF by Jose Miguel Esparza (http://peepdf.eternal-todo.com/). Tools added: Password cracking, redaction…

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Analyze and help extract older "hidden" versions of a pdf from the current pdf.

Detection and sanitization for Acropalypse Now - CVE-2023-21036

A python tool that will extract exif data from picture with two methods

Undelete and recover accidentally erased files from ext3 and ext4 filesystems, using inode scanning and block recovery for forensic and data-loss…