
MESH
Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

This is the development tree. Production downloads are at:

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

An OSINT / digital forensics tool built in Python

Forensics artefact collection tool for systems running Microsoft Windows

A tool for forensic file system reconstruction.

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.