
gocropalypse
CVE-2023-21036 detection in Go

CVE-2023-21036 detection in Go

Extracts cryptocurrency private keys and addresses from wallet.dat files for Bitcoin and Litecoin, enabling wallet recovery and forensic analysis.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

This repository serves as a place for community created Targets and Modules for use with KAPE.

Collection of forensic tools

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Incident Response Forensic Framework


Parser for $LogFile on NTFS

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

ParanoiDF - PDF Analysis Suite based on PeePDF by Jose Miguel Esparza (http://peepdf.eternal-todo.com/). Tools added: Password cracking, redaction…


It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.

POC experiments with Volume Shadow copy Service (VSS)

Event Trace Log file parser in pure Python

Pcap (capture file) Analysis Toolkit(v.1)

Native YARA scanner X-Tension for X-Ways Forensics, enabling in-snapshot file scanning with multi-threaded RVS support, report table output, and no…

Monitoring Registry and File Changes in Windows