
Volumiser
CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

This is the development tree. Production downloads are at:


Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.


Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.