
dfirtriage
Digital forensic acquisition tool for Windows based incident response.

Digital forensic acquisition tool for Windows based incident response.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…

A small utility to translate NTDS.dit files to SQLite format.

GUI for Volatility forensics tool written in PyQT5

This is the development tree. Production downloads are at:

Decrypt WhatsApp encrypted media files (images, videos, audio, documents) using media keys extracted from iOS ChatStorage.sqlite or Android…

Windows passwords decryption from dump files

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Detection and sanitization for Acropalypse Now - CVE-2023-21036

Python script for carving Bitlocker VMK keys

Kalim backdooe Malware Report

Digital Forensics Intelligence Framework

X-Ways Acropalypse extension detects CVE-2023-21036 in common images

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal