
andriller
📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

A small utility to translate NTDS.dit files to SQLite format.

A portable C# utility for enumerating local and remote windows sessions

A utility for extracting cryptocurrency wallet data from wallet.dat files.

Utility for recovering ES File Explorer encrypted files (.eslock)

Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.

RAM imaging utility.

Log what files are accessed by any Linux process

Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

convert ELF/DWARF symbol and type information into vol3's intermediate JSON

Indicator of Compromise Scanner for CVE-2019-19781


Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303