
KapeFiles
This repository serves as a place for community created Targets and Modules for use with KAPE.

This repository serves as a place for community created Targets and Modules for use with KAPE.

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads


F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

Python script for carving Bitlocker VMK keys

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

A tool for forensic file system reconstruction.

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Free hands-on digital forensics labs for students and faculty

Commandline low level file extractor for NTFS

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…