
foremost
File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Recovers lost partitions and repairs boot sectors; carves 480+ file formats from damaged disks and filesystems for data recovery and forensic use.

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

Tool to extract the $UsnJrnl from an NTFS volume

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Copies data from damaged or failing storage devices, handles read errors, and performs efficient rescue operations to recover as much data as…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Python script for carving Bitlocker VMK keys


Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…