
dfir-toolkit
CLI tools for forensic investigation of Windows artifacts

CLI tools for forensic investigation of Windows artifacts

A forensic evidence collection & analysis toolkit for OS X


FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

OS X Auditor is a free Mac OS X computer forensics tool

This is the development tree. Production downloads are at:


Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Collection of forensic tools

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Incident Response Forensic Framework


Commandline low level file extractor for NTFS

Tool to extract the $UsnJrnl from an NTFS volume


Python script for carving Bitlocker VMK keys

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.