
Archived
osxcollector
A forensic evidence collection & analysis toolkit for OS X
digital-forensicsdisk-forensicsforensics+3

A forensic evidence collection & analysis toolkit for OS X

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Collection of forensic tools

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads