
mvt
Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

A forensic evidence collection & analysis toolkit for OS X


A list of cyber-chef recipes and curated links

A tool for forensic file system reconstruction.

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)


Library and tools to access the Windows New Technology File System (NTFS)

Library and tools to access the Virtual Hard Disk (VHD) image format

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Library and tools to access the Volume Shadow Snapshot (VSS) format

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

Python script for carving Bitlocker VMK keys

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.