
CyberPipe
An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…


A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.


Python script for carving Bitlocker VMK keys

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Digital Forensics Intelligence Framework


Distributed & real time digital forensics at the speed of the cloud

A forensic evidence collection & analysis toolkit for OS X