
DFIR-LABS
Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Library and tools to access the Windows New Technology File System (NTFS)

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Library and tools to access the VMware Virtual Disk (VMDK) format

Library and tools to access the Virtual Hard Disk (VHD) image format

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

FAT filesystems explore, extract, repair, and forensic tool

Library and tools to access the Volume Shadow Snapshot (VSS) format

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Tool to extract the $UsnJrnl from an NTFS volume

Library and tools to access the QEMU Copy-On-Write (QCOW) image format


It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.

Digital Forensics Intelligence Framework

Copies data from damaged or failing storage devices, handles read errors, and performs efficient rescue operations to recover as much data as…