
Judge-Jury-and-Executable
A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Free hands-on digital forensics labs for students and faculty

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

This is the development tree. Production downloads are at:

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Library and tools to access the Windows New Technology File System (NTFS)

Library and tools to access the VMware Virtual Disk (VMDK) format

Library and tools to access the Virtual Hard Disk (VHD) image format

Library and tools to access the Volume Shadow Snapshot (VSS) format

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Tool to extract the $UsnJrnl from an NTFS volume

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Distributed & real time digital forensics at the speed of the cloud

Acquires the EBS disks of an AWS AMI you can launch, streaming snapshots via EBS direct APIs to a private S3 bucket with sha256 manifests and…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…