
foremost
File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

A list of cyber-chef recipes and curated links

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

Python script for carving Bitlocker VMK keys

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Commandline low level file extractor for NTFS

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…