


Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Distributed & real time digital forensics at the speed of the cloud

Forensic library and CLI toolkit for analyzing disk and file system images, recovering deleted data, generating timelines, and validating evidence…

A tool for forensic file system reconstruction.

Free hands-on digital forensics labs for students and faculty

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Digital Forensics Intelligence Framework

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Library and tools to access the Windows New Technology File System (NTFS)

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…