
guasap-whatsapp-foresincs-tool
WhatsApp Forensic Tool

WhatsApp Forensic Tool

A Repository to Track Anti-Forensic Techniques

Python implementation of the CaRT library for (un)inerting files.

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Tracking the family of unrelated IoT botnets sharing CVE-2021-35394 as a delivery vector — findings, relationships, methodology.

Cortex: a Powerful Observable Analysis and Active Response Engine

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…


Utility for recovering ES File Explorer encrypted files (.eslock)

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note…