
mvt
Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Commandline low level file extractor for NTFS

A list of cyber-chef recipes and curated links

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Python script for carving Bitlocker VMK keys

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…