
whatfiles
Log what files are accessed by any Linux process

Log what files are accessed by any Linux process

Local steganography app for hiding text, images, or files inside carrier images with AES-256 encryption, EXIF editing, watermarking, and batch…

Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.


Lua-based Wireshark postdissector that decrypts and parses Ubiquiti AirMAX/RouterBoard 802.11 vendor IEs into filterable fields.

Extract and repack Android ADB backups (ICS+). Supports encrypted archives, tar conversion, and standard I/O for forensic analysis or data recovery.

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

A free utility that finds malware, adware and other security threats

Utility for recovering ES File Explorer encrypted files (.eslock)

the ps utility, with an eBPF twist and container context

A portable C# utility for enumerating local and remote windows sessions

A utility for extracting cryptocurrency wallet data from wallet.dat files.

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

A utility for playing with cryptography, geared towards ransomware analysis.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

An advanced memory forensics framework

Detection and restoration of Windows Snipping Tool PNG captures vulnerable to CVE-2023-28303

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…