
Incident-Response-Powershell
PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Library and tools to access the Windows New Technology File System (NTFS)

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

Library and tools to access the VMware Virtual Disk (VMDK) format

Library and tools to access the Virtual Hard Disk (VHD) image format

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

FAT filesystems explore, extract, repair, and forensic tool

Library and tools to access the Volume Shadow Snapshot (VSS) format

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.