
Disk-Arbitrator
A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

FAT filesystems explore, extract, repair, and forensic tool

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry


Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

This is the development tree. Production downloads are at:

This repository serves as a place for community created Targets and Modules for use with KAPE.

Collection of forensic tools

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Incident Response Forensic Framework

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…


PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads