
dissect
Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

OS X Auditor is a free Mac OS X computer forensics tool

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Python script for carving Bitlocker VMK keys


IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Library and tools to access the Windows New Technology File System (NTFS)

Library and tools to access the VMware Virtual Disk (VMDK) format

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

Library and tools to access the Virtual Hard Disk (VHD) image format

Tool to extract the $UsnJrnl from an NTFS volume