
RecoverPy
Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

C library and command-line toolkit for forensic EWF image handling: acquire, export, verify, recover, and mount evidence files in EnCase and SMART…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Undelete and recover accidentally erased files from ext3 and ext4 filesystems, using inode scanning and block recovery for forensic and data-loss…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Free hands-on digital forensics labs for students and faculty

This repository serves as a place for community created Targets and Modules for use with KAPE.

A tool for forensic file system reconstruction.

Commandline low level file extractor for NTFS