
etl2pcapng
Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Rust-based Windows forensic toolkit for real-time MFT monitoring, event log streaming, and channel enumeration, enabling live system analysis and…

OS X Auditor is a free Mac OS X computer forensics tool

Forensics artefact collection tool for systems running Microsoft Windows

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Python script for carving Bitlocker VMK keys

Detection and sanitization for Acropalypse Now - CVE-2023-21036

Tool to extract the $UsnJrnl from an NTFS volume

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A tool to use novel locations to extract metadata from Office documents.

A tool to parse Firefox and Chrome HSTS databases into forensic artifacts!

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065