
dumpzilla
Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Indicator of Compromise Scanner for CVE-2019-19781

A python script which allows you to parse GeoLocation data from your Image files stored in a dataset.It also produces output in CSV file and also in…

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

Indicator of Compromise Scanner for CVE-2019-19781

Full-node Bitcoin client that validates transactions and blocks on the peer-to-peer network, with integrated wallet, cryptographic security, and…

UNIX-like reverse engineering framework and command-line toolset.

Dshell is a network forensic analysis framework.

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

ThePhish: an automated phishing email analysis tool

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.