pcapfex
RegRippy is a modern Python 3 alternative to RegRipper for extracting data from Windows registry hives.
Digital forensics for incident response. Uncover digital evidence to understand and resolve security breaches effectively.
RegRippy is a modern Python 3 alternative to RegRipper for extracting data from Windows registry hives.
A repository containing material from a talk on sub-domain enumeration techniques
Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.
A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.
dc3dd is a patch to the GNU dd program, tailored for forensic acquisition with features like hashing and file verification.
A Mac OS X computer forensics tool for analyzing system artifacts, user files, and logs with reputation verification and log aggregation capabilities.
Dump the contents of the location database files on iOS and macOS with output options like KML and CSV.
dc3dd is a patch to the GNU dd program, tailored for forensic acquisition with features like hashing and file verification.
A collection of tools for extracting and analyzing information from .git repositories
Customizable live OS constructor tool for remote forensics and incident response.
A network forensics tool for visualizing packet captures as network diagrams with detailed analysis.
A tool for extracting files from packet capture files with ease of use and extensibility for Python developers.
Forensic imaging program with full hash authentication and various acquisition options.
A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.
A shell script for basic forensic collection of various artefacts from UNIX systems.
A Forensic Framework for Skype with various investigative options.
Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.