
RecoverPy
Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Commandline low level file extractor for NTFS

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Tool to extract the $UsnJrnl from an NTFS volume

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

After using the KeePass password dumper maybe some character parsed as ● is incorrect and you want to know the real character

Find your device and control it remotely. Works over SMS, instant messengers, or FMD Server's web interface. A secure open source alternative to…

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

ATAboy is a user-friendly bridge that allows legacy CHS only style IDE (PATA) hard drives to be connected to a modern computer as a standard USB Mass…

Tool to securely and efficiently wipe devices and partiitions for Linux

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices