


Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.


Python script for carving Bitlocker VMK keys

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…


A forensic evidence collection & analysis toolkit for OS X

Distributed & real time digital forensics at the speed of the cloud