
walletool
Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.

Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

Indicator of Compromise Scanner for CVE-2019-19781

A portable C# utility for enumerating local and remote windows sessions

An advanced memory forensics framework

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Extract and repack Android ADB backups (ICS+). Supports encrypted archives, tar conversion, and standard I/O for forensic analysis or data recovery.

A free utility that finds malware, adware and other security threats

Utility for recovering ES File Explorer encrypted files (.eslock)

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…

Indicator of Compromise Scanner for CVE-2019-19781

Local steganography app for hiding text, images, or files inside carrier images with AES-256 encryption, EXIF editing, watermarking, and batch…

Log what files are accessed by any Linux process

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.


Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…