
bulk_extractor
This is the development tree. Production downloads are at:

This is the development tree. Production downloads are at:

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Incident Response Forensic Framework

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…


Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.


IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

A forensic evidence collection & analysis toolkit for OS X