
libvmdk
Library and tools to access the VMware Virtual Disk (VMDK) format

Library and tools to access the VMware Virtual Disk (VMDK) format

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.