
imago-forensics
Imago is a python tool that extract digital evidences from images.

Imago is a python tool that extract digital evidences from images.

A python tool that will extract exif data from picture with two methods

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

Python tool and library to help analyze files during malware triage and analysis.

Python tool for decrypting W32/Phase modules


Malicious HTTP traffic explorer

Total Commander FTP Password Recovery Tool for Python allows you to decrypt the FTP account password information for all Total Commander versions…

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Python script for carving Bitlocker VMK keys

An OSINT / digital forensics tool built in Python


Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Binary and Directory tree comparison tool using Fuzzy Hashing

Chepy is a python lib/cli equivalent of the awesome CyberChef tool.

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

A scanner that files with compromised or untrusted code signing certificates written in python.