
capa
Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Read-only, forensically sound Android device acquisition tool with lockscreen cracking (pattern, PIN, password), app data decoding, WhatsApp crypt…

Python-based forensic tool for extracting and analyzing WhatsApp databases, logs, and multimedia files, including recovery of deleted messages, with…

Android forensic data extraction tool that retrieves call logs, contacts, SMS, and MMS from devices for digital investigation and evidence collection.

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Decrypt WhatsApp encrypted media files (images, videos, audio, documents) using media keys extracted from iOS ChatStorage.sqlite or Android…

Command-line and GUI tool for decompiling Android Dex and APK files into readable Java source code, with resource decoding, deobfuscation, and Smali…

A tool for reverse engineering Android apk files

A free, open-source, and cross-platform iDevice management tool

Filesystem monitor tool for Linux/Android iOS/macOS

Portable forensic acquisition tool for Android devices that extracts SMS, APKs, system logs, and process lists to identify spyware and compromise…

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

Forensic tool to extract and analyze SQLite databases from rooted Android devices, generating structured XML reports for digital investigations.

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

Forensic tool that maps Android network connections to their originating processes via ADB, without root, and enriches external IPs with geolocation,…

GUI forensic tool for acquiring and analyzing Telegram data from Android devices. Parses messages, media, and metadata; generates integrity-verified…

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

A robust digital forensics tool for extracting and analyzing Google Chrome artifacts from Android devices