


File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.