
libfsntfs
Library and tools to access the Windows New Technology File System (NTFS)

Library and tools to access the Windows New Technology File System (NTFS)

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

Library and tools to access the VMware Virtual Disk (VMDK) format

Library and tools to access the Virtual Hard Disk (VHD) image format

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Commandline low level file extractor for NTFS

Library and tools to access the Volume Shadow Snapshot (VSS) format

Parser for $LogFile on NTFS

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Undelete and recover accidentally erased files from ext3 and ext4 filesystems, using inode scanning and block recovery for forensic and data-loss…

Python script for carving Bitlocker VMK keys

A forensic evidence collection & analysis toolkit for OS X


FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.