
ExtractUsnJrnl
Tool to extract the $UsnJrnl from an NTFS volume

Tool to extract the $UsnJrnl from an NTFS volume

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A tool to use novel locations to extract metadata from Office documents.

A tool to parse Firefox and Chrome HSTS databases into forensic artifacts!

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Python tool and library to help analyze files during malware triage and analysis.

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

A GUI and CLI tool for removing bloat from executables

Script to remove homoglyphs and zero-width characters to allow for safe distribution of documents from anonymous sources.

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…


Malicious HTTP traffic explorer

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…