
Disk-Arbitrator
A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux


Forensic library and CLI toolkit for analyzing disk and file system images, recovering deleted data, generating timelines, and validating evidence…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

This repository serves as a place for community created Targets and Modules for use with KAPE.

A tool for forensic file system reconstruction.

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

C library and command-line toolkit for forensic EWF image handling: acquire, export, verify, recover, and mount evidence files in EnCase and SMART…

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Commandline low level file extractor for NTFS