
Volumiser
CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…


analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Python script for carving Bitlocker VMK keys

Tool to extract the $UsnJrnl from an NTFS volume

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Recovers lost partitions and repairs boot sectors; carves 480+ file formats from damaged disks and filesystems for data recovery and forensic use.

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner…

Undelete and recover accidentally erased files from ext3 and ext4 filesystems, using inode scanning and block recovery for forensic and data-loss…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Copies data from damaged or failing storage devices, handles read errors, and performs efficient rescue operations to recover as much data as…