
LogFileParser
Parser for $LogFile on NTFS

Parser for $LogFile on NTFS

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Undelete and recover accidentally erased files from ext3 and ext4 filesystems, using inode scanning and block recovery for forensic and data-loss…

Python script for carving Bitlocker VMK keys

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

CLI tools for forensic investigation of Windows artifacts

A forensic evidence collection & analysis toolkit for OS X

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Free hands-on digital forensics labs for students and faculty


FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.


Collection of forensic tools

Incident Response Forensic Framework
