

A forensic evidence collection & analysis toolkit for OS X

CLI tools for forensic investigation of Windows artifacts


FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

OS X Auditor is a free Mac OS X computer forensics tool


This is the development tree. Production downloads are at:

Collection of forensic tools

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Incident Response Forensic Framework


A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Commandline low level file extractor for NTFS

Tool to extract the $UsnJrnl from an NTFS volume


It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.

Python script for carving Bitlocker VMK keys