
ForensiX
Digital Forensics Intelligence Framework

Digital Forensics Intelligence Framework
OS X Auditor is a free Mac OS X computer forensics tool

FAT filesystems explore, extract, repair, and forensic tool

Live Windows forensic acquisition tool that collects system artefacts (registry, memory, disk, files) into CSV/JSON for early compromise detection…

A tool for forensic file system reconstruction.

Windows toolkit that installs and configures a comprehensive suite of digital forensics and incident response tools, integrating them into the system…

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

eBPF-based machine-history debugger for Linux that records process, file, network, memory, and block I/O metadata into SQLite for timeline, diff, and…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Forensic library and CLI toolkit for analyzing disk and file system images, recovering deleted data, generating timelines, and validating evidence…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

This repository serves as a place for community created Targets and Modules for use with KAPE.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Asynchronous forensic data ingestion and analysis framework with Elasticsearch backend, supporting Mandiant Redline and FireEye HX audits, timeline…