
ntfstool
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Android Logs Events And Protobuf Parser

A Fast (and safe) parser for the Windows XML Event Log (EVTX) format


Scan files or process memory for CobaltStrike beacons and parse their configuration

A cross platform parser for Apple UnifiedLogs!

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Digital forensics suite for DJI drones that parses telemetry files, extracts hidden data via steganography, visualizes flight paths, and detects…

Active Directory NTDS database parser that dumps records to JSON, supports object filtering, and decrypts encrypted columns using SYSTEM hive or…

Parser for $LogFile on NTFS

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

A Windows kernel dump C++ parser library with Python 3 bindings.

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

A python library to parse OneNote (.one) files

Event Trace Log file parser in pure Python

A python script which allows you to parse GeoLocation data from your Image files stored in a dataset.It also produces output in CSV file and also in…