
libvshadow
Library and tools to access the Volume Shadow Snapshot (VSS) format

Library and tools to access the Volume Shadow Snapshot (VSS) format

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

Library and tools to access the Virtual Hard Disk (VHD) image format

Library and tools to access the Windows New Technology File System (NTFS)

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

A list of cyber-chef recipes and curated links

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.


Python script for carving Bitlocker VMK keys

A tool for forensic file system reconstruction.

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.



Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…