

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

This is the development tree. Production downloads are at:

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

ATAboy is a user-friendly bridge that allows legacy CHS only style IDE (PATA) hard drives to be connected to a modern computer as a standard USB Mass…

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

After using the KeePass password dumper maybe some character parsed as ● is incorrect and you want to know the real character

Depix is a PoC for a technique to recover plaintext from pixelized screenshots.

Rip Raw is a small tool to analyse the memory of compromised Linux systems.


A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Parallel backup and restore solution for PostgreSQL with encryption, delta restore, and multi-cloud object store support for enterprise disaster…