mem View mem
Windows event log fast forensics timeline generator and threat hunting tool.
Digital forensics for incident response. Uncover digital evidence to understand and resolve security breaches effectively.
Windows event log fast forensics timeline generator and threat hunting tool.
A tool for collecting and analyzing screenshots from remote desktop protocols, web applications, and VNC connections.
Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.
Second-order subdomain takeover scanner
A framework for orchestrating forensic collection, processing, and data export.
Collects and organizes Linux OS data for detailed analysis and incident response.
A DFVFS backed viewer project with a WxPython GUI, aiming to enhance file extraction and viewing capabilities.
Remote Acquisition Tool
An open source digital forensic tool for processing and analyzing digital evidence with high performance and multiplatform support.
Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.
AMExtractor is an Android Memory Extractor tool.
A cross-platform registry hive editor for forensic analysis with advanced features like hex viewer and reporting engine.
A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.
XMLStarlet offers a suite of command line utilities for manipulating and querying XML documents.
A binary analysis platform for analyzing binary programs
A tool for discovering, analyzing, and remedying sensitive data
A network forensics toolkit that transforms network traffic data into graph-based representations for interactive analysis and visualization through a web interface.
A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.
IE10Analyzer can parse and recover records from WebCacheV01.dat, providing detailed information and conversion capabilities.
Tool used for dumping memory from Android devices with root access requirement and forensic soundness considerations.
A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.
IE10Analyzer can parse and recover records from WebCacheV01.dat, providing detailed information and conversion capabilities.