
scalpel
File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

Digital Forensics Intelligence Framework

This is the development tree. Production downloads are at:


analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

Python script for carving Bitlocker VMK keys

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

A tool for forensic file system reconstruction.

OS X Auditor is a free Mac OS X computer forensics tool

FAT filesystems explore, extract, repair, and forensic tool


Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.
