
iLEAPP
Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Android Logs Events And Protobuf Parser

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

A cross platform parser for Apple UnifiedLogs!

Tool for reconstructing SPI flash images via logic analyzer captures

Extracts LSA secrets and DPAPI keys from Windows registry hives via existing or newly created VSS shadow copies, with an inline regf parser and…

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Intercepts and analyzes USB Mass Storage traffic at the block and file level, emulates USB devices, and supports custom Python stubs for security…

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Parser for $LogFile on NTFS

Event Trace Log file parser in pure Python

Post-Exploitation EVTX Analyzer for BloodHound Mapping


Active Directory NTDS database parser that dumps records to JSON, supports object filtering, and decrypts encrypted columns using SYSTEM hive or…