
KapeFiles
This repository serves as a place for community created Targets and Modules for use with KAPE.

This repository serves as a place for community created Targets and Modules for use with KAPE.

A tool for forensic file system reconstruction.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Commandline low level file extractor for NTFS

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Python script for carving Bitlocker VMK keys

A forensic evidence collection & analysis toolkit for OS X

Incident Response Forensic Framework


PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry
