
bulk_extractor
This is the development tree. Production downloads are at:

This is the development tree. Production downloads are at:

Decrypt WhatsApp encrypted media files (images, videos, audio, documents) using media keys extracted from iOS ChatStorage.sqlite or Android…

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

Bash script to extract data from a "chekcra1ned" iOS device


Android Connections Forensics

Cellebrite Physical Analyzer python scripts to aid analysts with extended functionality

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Linux Distro for Mobile Security, Malware Analysis, and Forensics

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

Curated reference for Android forensic artifacts and log paths, with links to CTF writeups, research papers, and mobile device analysis tooling.

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

Utility for recovering ES File Explorer encrypted files (.eslock)

A robust digital forensics tool for extracting and analyzing Google Chrome artifacts from Android devices