
etl2pcapng
Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

A portable C# utility for enumerating local and remote windows sessions

Indicator of Compromise Scanner for CVE-2019-19781

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

An advanced memory forensics framework

Utility for recovering ES File Explorer encrypted files (.eslock)

Log what files are accessed by any Linux process

Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.

Zero-dependency Windows EDR utility that detects and mitigates unauthorized LSASS memory access, handle duplication, and LOLBin credential dumping in…

Indicator of Compromise Scanner for CVE-2019-19781

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

RAM imaging utility.

Bash-based scanner detecting indicators of compromise from CVE-2023-3519 exploitation on Citrix ADC appliances, supporting live and forensic image…