
mvt
Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…


Library and tools to access the Volume Shadow Snapshot (VSS) format

Library and tools to access the Virtual Hard Disk (VHD) image format

Library and tools to access the Windows New Technology File System (NTFS)

A tool for forensic file system reconstruction.

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Python script for carving Bitlocker VMK keys

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.


Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

A list of cyber-chef recipes and curated links


Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

A forensic evidence collection & analysis toolkit for OS X