libfsntfs
A tool that uses Plaso to parse forensic artifacts and disk images, creating custom reports for easier analysis.
Digital forensics for incident response. Uncover digital evidence to understand and resolve security breaches effectively.
A tool that uses Plaso to parse forensic artifacts and disk images, creating custom reports for easier analysis.
A repository containing material from a talk on sub-domain enumeration techniques
IE10Analyzer can parse and recover records from WebCacheV01.dat, providing detailed information and conversion capabilities.
Autopsy is a GUI-based digital forensics platform for analyzing hard drives and smart phones, with a plug-in architecture for custom modules.
Visually inspect regex matches in binary data/text with YARA and regular expressions, displaying matched bytes and surrounding context.
A comprehensive guide to incident response and computer forensics, covering the entire lifecycle of incident response and remediation.
Analyzing WiFiConfigStore.xml file for digital forensics on Android devices.
A Python 2.x tool for memory analysis on Mac OS X systems with support for various OS versions and memory image export capabilities.
OSXCollector is a forensic evidence collection & analysis toolkit for OSX.
A repository containing material from a talk on sub-domain enumeration techniques
Hindsight is a free tool for analyzing web artifacts from Google Chrome/Chromium browsers and presenting the data in a timeline for forensic analysis.
Comprehensive suite for advanced file analysis and software supply chain security.
A command-line utility to show and change EXIF information in JPEG files
Automated collection tool for incident response triage in Windows systems.
A collection of Mac OS X and iOS forensics resources with a focus on artifact collection and collaboration.
Python script to parse the NTFS USN Change Journal.