
whatsapp-media-decrypt
Decrypt WhatsApp encrypted media files (images, videos, audio, documents) using media keys extracted from iOS ChatStorage.sqlite or Android…

Decrypt WhatsApp encrypted media files (images, videos, audio, documents) using media keys extracted from iOS ChatStorage.sqlite or Android…

GUI forensic tool for acquiring and analyzing Telegram data from Android devices. Parses messages, media, and metadata; generates integrity-verified…

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Extract WhatsApp private key from any non-rooted Android device (Android 7+ supported)

Bash script to extract data from a "chekcra1ned" iOS device

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

A robust digital forensics tool for extracting and analyzing Google Chrome artifacts from Android devices

Filesystem monitor tool for Linux/Android iOS/macOS


This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

WhatsApp Forensic Tool