
UnderlayCopy
PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

OS X Auditor is a free Mac OS X computer forensics tool

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

FAT filesystems explore, extract, repair, and forensic tool

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Tool to extract the $UsnJrnl from an NTFS volume

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.
