AChoir Windows Live Artifacts Acquisition Scripting Framework
Second-order subdomain takeover scanner
Digital forensics for incident response. Uncover digital evidence to understand and resolve security breaches effectively.
Second-order subdomain takeover scanner
A digital artifact extraction framework for extracting data from volatile memory (RAM) samples, providing visibility into the runtime state of a system.
Open Source computer forensics platform with modular design for easy automation and scripting.
Python tool for remote memory acquisition
A software utility with forensic tools for smartphones, offering powerful data extraction and decoding capabilities.
Recover event log entries from an image by heuristically looking for record structures.
CyLR is a Live Response Collection tool for quickly and securely collecting forensic artifacts from hosts with NTFS file systems.
A console program for file recovery through data carving.
Windows event log fast forensics timeline generator and threat hunting tool.
A Windows Registry hive extraction library that reads and writes Windows Registry 'hive' binary files.
MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.
Web interface for the Volatility Memory Analysis framework with advanced features.
A forensics tool for tracking USB device artifacts on Linux machines.
A comprehensive guide to incident response and computer forensics, covering the entire lifecycle of incident response and remediation.
A tool for triaging crash files with various output formats and debugging engine options.
Exiv2 is a C++ library and command-line utility for image metadata manipulation.
Dissect is a digital forensics & incident response framework that simplifies the analysis of forensic artefacts from various disk and file formats.
A library to access and read QEMU Copy-On-Write (QCOW) image file formats with support for zlib compression and AES-CBC encryption.
A next-generation crawling and spidering framework for extracting data from websites
A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.