
magic-extractor
Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

F*ck file system - cli file search tool that bypasses OS kernel and reads your disc directlry

OS X Auditor is a free Mac OS X computer forensics tool


ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

A forensic evidence collection & analysis toolkit for OS X


This is the development tree. Production downloads are at:

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.


Tool to extract the $UsnJrnl from an NTFS volume

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Digital Forensics Intelligence Framework

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…