
RecuperaBit
A tool for forensic file system reconstruction.

A tool for forensic file system reconstruction.

Library and tools to access the Windows New Technology File System (NTFS)

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Commandline low level file extractor for NTFS

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Tool to extract the $UsnJrnl from an NTFS volume

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

A forensic evidence collection & analysis toolkit for OS X


Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

OS X Auditor is a free Mac OS X computer forensics tool