
FACT
Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

FAT filesystems explore, extract, repair, and forensic tool

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Python tool and library to help analyze files during malware triage and analysis.

This is the development tree. Production downloads are at:

OpenStego is a steganography application that provides two functionalities: a) Data Hiding: It can hide any data within an image file. b)…

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

A cryptographic research tool for analyzing signature vulnerabilities

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

Finding secrets in kernel and user memory

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files


Malicious HTTP traffic explorer

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

A tool for forensic file system reconstruction.