


Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

OS X Auditor is a free Mac OS X computer forensics tool