


This is the development tree. Production downloads are at:


Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Incident Response Forensic Framework

Acquires the EBS disks of an AWS AMI you can launch, streaming snapshots via EBS direct APIs to a private S3 bucket with sha256 manifests and…