
dfir-orc
Forensics artefact collection tool for systems running Microsoft Windows

Forensics artefact collection tool for systems running Microsoft Windows

An OSINT / digital forensics tool built in Python

Digital Forensics Intelligence Framework

Basic log analysis tool to detect impossible travel via IP address geographic information

A tool to use novel locations to extract metadata from Office documents.

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

Utility for recovering ES File Explorer encrypted files (.eslock)

Rust tool to detect cell site simulators on an orbic mobile hotspot


Tool to help guess a files 256 byte XOR key by using frequency analysis

This is the development tree. Production downloads are at:

A python tool that will extract exif data from picture with two methods



Manage BitLocker recovery keys, monitor drive encryption status, and unlock volumes through a portable interface for Windows.

Curated list of awesome projects and resources related to Rust and computer security

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

X-Ways Acropalypse extension detects CVE-2023-21036 in common images