
Disk-Arbitrator
A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Library to access the Windows Shell Item format

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

This is the development tree. Production downloads are at:

Cross-platform hashing toolset for computing message digests (MD5, SHA-1, SHA-256, Tiger, Whirlpool) with recursive directory traversal and file…

Collection of forensic tools

A tool for forensic file system reconstruction.

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

FAT filesystems explore, extract, repair, and forensic tool

Commandline low level file extractor for NTFS

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

ATAboy is a user-friendly bridge that allows legacy CHS only style IDE (PATA) hard drives to be connected to a modern computer as a standard USB Mass…

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices