
DroneXtract
Digital forensics suite for DJI drones that parses telemetry files, extracts hidden data via steganography, visualizes flight paths, and detects…

Digital forensics suite for DJI drones that parses telemetry files, extracts hidden data via steganography, visualizes flight paths, and detects…

Library and tools to access the Virtual Hard Disk (VHD) image format

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

Library and tools to access the Volume Shadow Snapshot (VSS) format

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Binary and Directory tree comparison tool using Fuzzy Hashing

Library to access the Windows Shell Item format

Interrogate is a proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating system), first and…

Cellebrite Physical Analyzer python scripts to aid analysts with extended functionality

Intercepts and analyzes USB Mass Storage traffic at the block and file level, emulates USB devices, and supports custom Python stubs for security…

Proof-of-concept for CVE-2025-50422: demonstrates heap memory disclosure in Poppler's pdftocairo, allowing local attackers to recover clear-text PDF…

Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.

Disk partitioning suite for GPT and MBR disks, offering interactive and scriptable tools to create, modify, and repair partition tables, including…

Extract files from any kind of container formats

A multi-platform GUI for bit-based analysis, processing, and visualization

C library and command-line toolkit for forensic EWF image handling: acquire, export, verify, recover, and mount evidence files in EnCase and SMART…

Extracts and decrypts the 4-digit restriction passcode from iPhone backups on Windows machines, enabling recovery of device access controls.