
dfir-toolkit
CLI tools for forensic investigation of Windows artifacts

CLI tools for forensic investigation of Windows artifacts

A forensic evidence collection & analysis toolkit for OS X


FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

OS X Auditor is a free Mac OS X computer forensics tool

This is the development tree. Production downloads are at:


Collection of forensic tools

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Incident Response Forensic Framework

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.


Commandline low level file extractor for NTFS

Tool to extract the $UsnJrnl from an NTFS volume


Python script for carving Bitlocker VMK keys

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.