
BSOD_bitlocker_recover
Python script for carving Bitlocker VMK keys
data-recoverydigital-forensicsdisk-forensics+3
26

Python script for carving Bitlocker VMK keys

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

A forensic evidence collection & analysis toolkit for OS X

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.