
whatfiles
Log what files are accessed by any Linux process

Log what files are accessed by any Linux process

Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.

Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Utility for recovering ES File Explorer encrypted files (.eslock)

A portable C# utility for enumerating local and remote windows sessions

A utility for extracting cryptocurrency wallet data from wallet.dat files.

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

An advanced memory forensics framework

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

A small utility to translate NTDS.dit files to SQLite format.

Bash-based scanner detecting indicators of compromise from CVE-2023-3519 exploitation on Citrix ADC appliances, supporting live and forensic image…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

A tool for finding and analyzing private (and public) key files, including support for Android APK files.

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…