# Forensics

# Blockchain

  • Orbit - Blockchain Transactions Investigation Tool. last-commit

# Browser

  • Hindsight - Web browser forensics for Google Chrome/Chromium. last-commit

# Disk Images

  • AFFLIBv3 - AFF is an open and extensible file format to store disk images and associated metadata. last-commit
  • Autopsy - A digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools.
  • DMG2IMG - DMG2IMG is a tool which allows converting Apple compressed dmg archives to standard (hfsplus) image disk files. last-commit

# Images/Documents

  • Disk Drill - Recover deleted files for Mac and Windows.
  • Exfiltool - Tool for reading, writing and editing meta information.
  • FOCA - Tool to find metadata and hidden information in the documents. last-commit

# Mobile

  • Andriller - Performs read-only, forensically sound, non-destructive acquisition from Android devices. last-commit

# Scripts

# SQL

  • DFIR SQL Query - Download/setup script for malware analysis/software reverse engineering. last-commit -

# Tools

  • Beagle - Digital forensics tool which transforms security logs and data into graphs. last-commit

# Windows

  • AmcacheParser - Parses amcache.hve files, but with a twist. - last-commit
  • AppCompatCacheParser - AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10. - last-commit
  • Auditpol - Displays information about and performs functions to manipulate audit policies.
  • EvtxECmd - C# based evtx parser with lots of extras. - last-commit
  • ExtensionBlocks - Extension blocks as found in ShellBags and other places in the Registry. - last-commit
  • iisGeolocate - geolocate ip addresses in IIS logs. - last-commit
  • JLECmd - Automatic and Custom Destinations jump list parser with Windows 10 support. - last-commit
  • KAPE Files - This repository serves as a place for community created Targets and Modules for use with KAPE. - last-commit
  • LECmd - Lnk Explorer Command line edition! last-commit
  • Lnk - Lnk file parser. last-commit
  • MFT - MFT parser. last-commit
  • MFTECmd - Parses $MFT from NTFS file systems. last-commit
  • OleCF - Library to process OLE compound file format. last-commit
  • PECmd - Prefetch Explorer Command Line. last-commit
  • Prefetch - Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10. - last-commit -
  • RBCmd - Recycle bin artifact parser. last-commit
  • Registry - Full featured, offline Registry parser in C#. last-commit
  • Registry Explorer Bookmarks - Registry Explorer bookmark definitions. - last-commit
  • SDB - Parse Microsoft shim databases. last-commit
  • SQLECmd - This repo that contains all the Maps used by Eric Zimmerman's SQLECmd. - last-commit
  • SrumECmd - SRUM parser. last-commit
  • SumECmd - Process Microsoft User Access Log. last-commit
  • TLEFilePlugins - Plugins for parsing CSV files in Timeline Explorer. - last-commit
  • USBDevices - Get USB Devices from Registry hives. last-commit
  • VSCMount - Mount VSCs with ease! last-commit
  • WinSearchDBAnalyzer - Parse normal records and recover deleted records in Windows.edb. last-commit
  • WtTCmd - Parser for the Windows 10 Timeline feature database. last-commit