
foremost
File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

File carving utility that recovers deleted files from disk images and raw drives by matching headers, footers, and internal structures via…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Rapidly Search and Hunt through Windows Forensic Artefacts

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

A collection of malware samples caught by several honeypots i manage

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

A repository hosting example goodware evtx logs containing sample software installation and basic user interaction


Enumerate various traits from Windows processes as an aid to threat hunting


Public repository of Sigma and YARA rules created by Synacktiv

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Utility for recovering ES File Explorer encrypted files (.eslock)

Release of the sandy framework.

Tool to help guess a files 256 byte XOR key by using frequency analysis

ParanoiDF - PDF Analysis Suite based on PeePDF by Jose Miguel Esparza (http://peepdf.eternal-todo.com/). Tools added: Password cracking, redaction…

Python Decoders for Common Remote Access Trojans