
PhaseDump
Python tool for decrypting W32/Phase modules

Python tool for decrypting W32/Phase modules

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Utility for recovering ES File Explorer encrypted files (.eslock)

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

Extract and repack Android ADB backups (ICS+). Supports encrypted archives, tar conversion, and standard I/O for forensic analysis or data recovery.

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.