
ntfsDump
Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

GUI forensic tool for acquiring and analyzing Telegram data from Android devices. Parses messages, media, and metadata; generates integrity-verified…

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Extract files from any kind of container formats

Remove visible and invisible AI watermarks and provenance metadata from images and video. Python library and CLI for SynthID, C2PA, EXIF, IPTC, XMP,…

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…

Turn any collection of documents into a knowledge graph. Extract entities and relationships via LLM, deduplicate with your approval. Map domains,…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Ransomware decryption and script deobfuscation utilities from a threat intelligence team, designed for incident responders and malware analysts.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Wipe, reinstall or restore your system from running GNU/Linux distribution. Via SSH, without rebooting.

Tool to extract the $UsnJrnl from an NTFS volume

Analyze and help extract older "hidden" versions of a pdf from the current pdf.

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

A python tool that will extract exif data from picture with two methods