![](/assets/headers/header-logo.png)

![](https://img.shields.io/badge/Tools%20%26%20Resources%20Available-39-757575?style=for-the-badge)

### Blockchain

* [Orbit](https://github.com/s0md3v/Orbit) - Blockchain Transactions Investigation Tool. ![last-commit](https://img.shields.io/github/last-commit/s0md3v/Orbit?style=flat) 

### Browser

* [Hindsight](https://github.com/obsidianforensics/hindsight) - Web browser forensics for Google Chrome/Chromium. ![last-commit](https://img.shields.io/github/last-commit/obsidianforensics/hindsight?style=flat)

### Disk Images

* [AFFLIBv3](https://github.com/sshock/AFFLIBv3) - AFF is an open and extensible file format to store disk images and associated metadata. ![last-commit](https://img.shields.io/github/last-commit/sshock/AFFLIBv3?style=flat)
* [Autopsy](https://www.sleuthkit.org/autopsy/) - A digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools.
* [DMG2IMG](https://github.com/Lekensteyn/dmg2img) - DMG2IMG is a tool which allows converting Apple compressed dmg archives to standard (hfsplus) image disk files. ![last-commit](https://img.shields.io/github/last-commit/Lekensteyn/dmg2img?style=flat)

### Images/Documents

* [Disk Drill](https://www.disk-drill.com) - Recover deleted files for Mac and Windows.
* [Exfiltool](https://exiftool.org/) - Tool for reading, writing and editing meta information.
* [FOCA](https://github.com/ElevenPaths/FOCA) -  Tool to find metadata and hidden information in the documents. ![last-commit](https://img.shields.io/github/last-commit/ElevenPaths/FOCA?style=flat)

### Mobile

* [Andriller](https://github.com/den4uk/andriller) - Performs read-only, forensically sound, non-destructive acquisition from Android devices. ![last-commit](https://img.shields.io/github/last-commit/den4uk/andriller?style=flat)

### Scripts

* [DissectingMalwa.re Lab](https://github.com/f0wl/MalwareLab_VM-Setup) - Download/setup script for malware analysis/software reverse engineering. ![last-commit](https://img.shields.io/github/last-commit/f0wl/MalwareLab_VM-Setup?style=flat)

### SQL

* [DFIR SQL Query](https://github.com/abrignoni/DFIR-SQL-Query-Repo) - Download/setup script for malware analysis/software reverse engineering. ![last-commit](https://img.shields.io/github/last-commit/abrignoni/DFIR-SQL-Query-Repo?style=flat)  -

### Tools

* [Beagle](https://github.com/yampelo/beagle) - Digital forensics tool which transforms security logs and data into graphs. ![last-commit](https://img.shields.io/github/last-commit/yampelo/beagle?style=flat)

### Windows 

* [AmcacheParser](https://github.com/EricZimmerman/AmcacheParser) - Parses amcache.hve files, but with a twist. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/AmcacheParser?style=flat)
* [AppCompatCacheParser](https://github.com/EricZimmerman/AppCompatCacheParser) - AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/AppCompatCacheParser?style=flat)
* [Auditpol](https://docs.microsoft.com/en-gb/windows-server/administration/windows-commands/auditpol) - Displays information about and performs functions to manipulate audit policies.
* [EvtxECmd](https://github.com/EricZimmerman/evtx) - C# based evtx parser with lots of extras. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/evtx?style=flat)
* [ExtensionBlocks](https://github.com/EricZimmerman/ExtensionBlocks) - Extension blocks as found in ShellBags and other places in the Registry. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/ExtensionBlocks?style=flat)
* [iisGeolocate](https://github.com/EricZimmerman/iisGeolocate) - geolocate ip addresses in IIS logs. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/iisGeolocate?style=flat)
* [JLECmd](https://github.com/EricZimmerman/JLECmd) - Automatic and Custom Destinations jump list parser with Windows 10 support. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/JLECmd?style=flat)
* [KAPE Files](https://github.com/EricZimmerman/KapeFiles) - This repository serves as a place for community created Targets and Modules for use with KAPE. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/KapeFiles?style=flat)
* [LECmd](https://github.com/EricZimmerman/LECmd) - Lnk Explorer Command line edition! ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/LECmd?style=flat)
* [Lnk](https://github.com/EricZimmerman/Lnk) - Lnk file parser. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/Lnk?style=flat)
* [MFT](https://github.com/EricZimmerman/MFT) - MFT parser. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/MFT?style=flat)
* [MFTECmd](https://github.com/EricZimmerman/MFTECmd) - Parses $MFT from NTFS file systems. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/MFTECmd?style=flat)
* [OleCF](https://github.com/EricZimmerman/OleCf) - Library to process OLE compound file format. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/OleCf?style=flat)
* [PECmd](https://github.com/EricZimmerman/PECmd) - Prefetch Explorer Command Line. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/PECmd?style=flat)
* [Prefetch](https://github.com/EricZimmerman/Prefetch) - Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/Prefetch?style=flat)  -
* [RBCmd](https://github.com/EricZimmerman/RBCmd) - Recycle bin artifact parser. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/RBCmd?style=flat)
* [Registry](https://github.com/EricZimmerman/Registry) - Full featured, offline Registry parser in C#. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/Registry?style=flat)
* [Registry Explorer Bookmarks](https://github.com/EricZimmerman/RegistryExplorerBookmarks) - Registry Explorer bookmark definitions. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/RegistryExplorerBookmarks?style=flat)
* [SDB](https://github.com/EricZimmerman/SDB) - Parse Microsoft shim databases. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/SDB?style=flat)
* [SQLECmd](https://github.com/EricZimmerman/SQLECmd) - This repo that contains all the Maps used by Eric Zimmerman's SQLECmd. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/SQLECmd?style=flat)
* [SrumECmd](https://github.com/EricZimmerman/Srum) - SRUM parser. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/Srum?style=flat)
* [SumECmd](https://github.com/EricZimmerman/Sum) - Process Microsoft User Access Log. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/Sum?style=flat)
* [TLEFilePlugins](https://github.com/EricZimmerman/TLEFilePlugins) - Plugins for parsing CSV files in Timeline Explorer. - ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/TLEFilePlugins?style=flat)
* [USBDevices](https://github.com/EricZimmerman/USBDevices) - Get USB Devices from Registry hives. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/USBDevices?style=flat)
* [VSCMount](https://github.com/EricZimmerman/VSCMount) - Mount VSCs with ease! ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/VSCMount?style=flat)
* [WinSearchDBAnalyzer](https://github.com/EricZimmerman/WinSearchDBAnalyzer) - Parse normal records and recover deleted records in Windows.edb. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/WinSearchDBAnalyzer?style=flat)
* [WtTCmd](https://github.com/EricZimmerman/WxTCmd) - Parser for the Windows 10 Timeline feature database. ![last-commit](https://img.shields.io/github/last-commit/EricZimmerman/WxTCmd?style=flat)
