

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux


This repository serves as a place for community created Targets and Modules for use with KAPE.

A tool for forensic file system reconstruction.

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Commandline low level file extractor for NTFS

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Python script for carving Bitlocker VMK keys

CLI tools for forensic investigation of Windows artifacts

A forensic evidence collection & analysis toolkit for OS X


analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.