
Judge-Jury-and-Executable
A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Distributed & real time digital forensics at the speed of the cloud

A tool for forensic file system reconstruction.

Forensic library and CLI toolkit for analyzing disk and file system images, recovering deleted data, generating timelines, and validating evidence…

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

FAT filesystems explore, extract, repair, and forensic tool

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

This repository serves as a place for community created Targets and Modules for use with KAPE.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…