
tscopy
Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Library and tools to access the Volume Shadow Snapshot (VSS) format

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

Undelete and recover accidentally erased files from ext3 and ext4 filesystems, using inode scanning and block recovery for forensic and data-loss…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Copies data from damaged or failing storage devices, handles read errors, and performs efficient rescue operations to recover as much data as…

Parser for $LogFile on NTFS

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

This is the development tree. Production downloads are at:


Collection of forensic tools

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Commandline low level file extractor for NTFS

Tool to extract the $UsnJrnl from an NTFS volume

Python script for carving Bitlocker VMK keys