
RecuperaBit
A tool for forensic file system reconstruction.

A tool for forensic file system reconstruction.

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Python script for carving Bitlocker VMK keys

A forensic evidence collection & analysis toolkit for OS X



Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

A list of cyber-chef recipes and curated links

Library and tools to access the Windows New Technology File System (NTFS)

Library and tools to access the Virtual Hard Disk (VHD) image format

Library and tools to access the Volume Shadow Snapshot (VSS) format

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.
