


This is the development tree. Production downloads are at:

Incident Response Forensic Framework

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…


Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Acquires the EBS disks of an AWS AMI you can launch, streaming snapshots via EBS direct APIs to a private S3 bucket with sha256 manifests and…