
irflow-timeline
DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Free hands-on digital forensics labs for students and faculty

A tool for forensic file system reconstruction.

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

This repository serves as a place for community created Targets and Modules for use with KAPE.

Python script for carving Bitlocker VMK keys

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads


Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Commandline low level file extractor for NTFS