
UnderlayCopy
PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

Bash script to extract data from a "chekcra1ned" iOS device

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

Collection of materials relating to FORCEDENTRY

Active Directory NTDS database parser that dumps records to JSON, supports object filtering, and decrypts encrypted columns using SYSTEM hive or…

Monitoring Registry and File Changes in Windows

Digital Forensics Intelligence Framework

Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Provides supplemental files and Debian package sources for a specialized Linux distro focused on malware analysis, reverse engineering, and digital…

Linux Distro for Mobile Security, Malware Analysis, and Forensics

Exploit for Joomla CVE-2015-8562 combined with Linux forensic analysis capabilities for post-exploitation investigation and evidence collection.

Incident Response collection and processing scripts with automated reporting scripts

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

Collects comprehensive triage data from macOS for incident response, including system logs, file listings, browser data, shell history, and…

IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE…