
testdisk
Recovers lost partitions and repairs boot sectors; carves 480+ file formats from damaged disks and filesystems for data recovery and forensic use.

Recovers lost partitions and repairs boot sectors; carves 480+ file formats from damaged disks and filesystems for data recovery and forensic use.

OS X Auditor is a free Mac OS X computer forensics tool

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

This is the development tree. Production downloads are at:

A list of cyber-chef recipes and curated links

This repository serves as a place for community created Targets and Modules for use with KAPE.


A tool for forensic file system reconstruction.

Collection of forensic tools

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…