
osxcollector
A forensic evidence collection & analysis toolkit for OS X

A forensic evidence collection & analysis toolkit for OS X

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Python script for carving Bitlocker VMK keys


Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…


Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

A list of cyber-chef recipes and curated links

A tool for forensic file system reconstruction.

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)


Library and tools to access the Windows New Technology File System (NTFS)

Library and tools to access the Virtual Hard Disk (VHD) image format

Library and tools to access the Volume Shadow Snapshot (VSS) format

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Library and tools to access the QEMU Copy-On-Write (QCOW) image format

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.