
imago-forensics
Imago is a python tool that extract digital evidences from images.

Imago is a python tool that extract digital evidences from images.

A python tool that will extract exif data from picture with two methods

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Python tool and library to help analyze files during malware triage and analysis.


Malicious HTTP traffic explorer

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Python script for carving Bitlocker VMK keys

An OSINT / digital forensics tool built in Python


Binary and Directory tree comparison tool using Fuzzy Hashing

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

WhatsApp Forensic Tool

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

ThePhish: an automated phishing email analysis tool

SSH-based Linux incident response tool that executes diagnostic commands to collect network configs, logs, user accounts, and processes, then…