
fridump
Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

Rust-based Windows forensic toolkit for real-time MFT monitoring, event log streaming, and channel enumeration, enabling live system analysis and…

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

OS X Auditor is a free Mac OS X computer forensics tool

Artifact collection tool for *nix systems

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Detection Script for MongoBleed Exploitation

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Forensics artefact collection tool for systems running Microsoft Windows


A lightweight eBPF program to monitor file creation and modification events on Linux. This tool leverages eBPF (Extended Berkeley Packet Filter) to…

An OSINT / digital forensics tool built in Python

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

A tool for forensic file system reconstruction.