
RawHive
Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…


Python script for carving Bitlocker VMK keys

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.

Digital Forensics Intelligence Framework


CLI tools for forensic investigation of Windows artifacts

A forensic evidence collection & analysis toolkit for OS X