
RecuperaBit
A tool for forensic file system reconstruction.

A tool for forensic file system reconstruction.

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Python script for carving Bitlocker VMK keys

A forensic evidence collection & analysis toolkit for OS X


Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

A list of cyber-chef recipes and curated links

It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.
