
SrHollow
Extracts LSA secrets and DPAPI keys from Windows registry hives via existing or newly created VSS shadow copies, with an inline regf parser and…

Extracts LSA secrets and DPAPI keys from Windows registry hives via existing or newly created VSS shadow copies, with an inline regf parser and…

Tool for reconstructing SPI flash images via logic analyzer captures

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Android Logs Events And Protobuf Parser

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

A cross platform parser for Apple UnifiedLogs!

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

A python library to parse OneNote (.one) files

A Windows kernel dump C++ parser library with Python 3 bindings.

Parser for $LogFile on NTFS

Active Directory NTDS database parser that dumps records to JSON, supports object filtering, and decrypts encrypted columns using SYSTEM hive or…

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.


A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Post-Exploitation EVTX Analyzer for BloodHound Mapping

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Intercepts and analyzes USB Mass Storage traffic at the block and file level, emulates USB devices, and supports custom Python stubs for security…