
SnipRecover-CLI
Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

ATAboy is a user-friendly bridge that allows legacy CHS only style IDE (PATA) hard drives to be connected to a modern computer as a standard USB Mass…

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Tool to extract the $UsnJrnl from an NTFS volume

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

Library to access the Windows Shell Item format

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Cellebrite Physical Analyzer python scripts to aid analysts with extended functionality

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

A tool for forensic file system reconstruction.