
ForensiX
Digital Forensics Intelligence Framework

Digital Forensics Intelligence Framework

Hands-on digital forensics lab curriculum with case studies in disk, memory, network, and mobile forensics, plus AI-powered investigation modules and…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Open-source digital forensic platform for processing and analyzing seized evidence. Supports disk images, file carving, hash analysis, OCR, audio…

Open-source digital forensics platform for disk image analysis, file recovery, timeline creation, and detailed artifact extraction.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Curated collection of recipes for DFIR, malware deobfuscation, and data transformation, with regex patterns, decoding workflows, and incident…

This repository serves as a place for community created Targets and Modules for use with KAPE.

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Unified digital forensics & incident response framework for parsing disk images, file systems, and OS artifacts across Windows, Linux, and ESXi…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Python tool to parse and analyze NTFS Master File Table (MFT) data, extracting file metadata, timestamps, and attributes for digital forensics and…

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

FAT filesystems explore, extract, repair, and forensic tool