
ntfstool
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Digital forensics suite for DJI drones that parses telemetry files, extracts hidden data via steganography, visualizes flight paths, and detects…

Parser for $LogFile on NTFS

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.

GUI forensic tool for acquiring and analyzing Telegram data from Android devices. Parses messages, media, and metadata; generates integrity-verified…

Asclepius validates backup integrity by restoring files and actively testing their recoverability. Instead of trusting metadata, it attempts to parse…

After using the KeePass password dumper maybe some character parsed as ● is incorrect and you want to know the real character

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…