
awesome-incident-response
Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Free hands-on digital forensics labs for students and faculty

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

C library and command-line toolkit for forensic EWF image handling: acquire, export, verify, recover, and mount evidence files in EnCase and SMART…

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

A tool for forensic file system reconstruction.

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

This repository serves as a place for community created Targets and Modules for use with KAPE.

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)


PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Commandline low level file extractor for NTFS