
RdpCacheStitcher
RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

Find and redact secrets in AI coding agent histories (Claude Code, and more).

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

ATAboy is a user-friendly bridge that allows legacy CHS only style IDE (PATA) hard drives to be connected to a modern computer as a standard USB Mass…

Library to access the Windows Shell Item format

Tool to extract the $UsnJrnl from an NTFS volume

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

Extract a slice of your production database to reproduce bugs locally. Point dbslice at a record, it follows foreign keys and gives you a complete,…

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

A gigabyte-per-second, multi-threaded file encryption engine. Achieves extreme throughput using a lock-free, triple-buffered io_uring pipeline, Rayon…

Analyze and help extract older "hidden" versions of a pdf from the current pdf.

A python tool that will extract exif data from picture with two methods

RP2040 firmware that bridges a Toshiba MK4001MTD 0.85" SDIO microdrive as a USB mass storage device, implementing the full SDIO-ATA protocol stack…


bad stuffs by bad guys

Steganographic storage & File encryption tool

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…