DriveFS Sleuth is a Python tool that automates investigating Google Drive File Stream disk artifacts, the tool has been developed based on research that has been performed by mounting different scenarios and noting down the changes in the Google Drive File Stream disk artifacts.
☆87Oct 3, 2026Updated last week
Alternatives and similar repositories for DriveFS-Sleuth
Users that are interested in DriveFS-Sleuth are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Google Filestream Forensic Tool☆22Mar 10, 2022Updated 4 years ago
- ☆24Mar 12, 2025Updated last year
- mister-skinnylegs is an open plugin framework for parsing website/webapp artifacts in browser data. It currently provides a command line …☆22Jul 20, 2026Updated 2 months ago
- Python web app for previewing data in a Chrome Profile Folder☆28Jul 1, 2024Updated 2 years ago
- A repository of output using KAPE (!EZParser Module) for various publicly available forensic images!☆17Aug 31, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A hex viewer for the sleuths!☆20Nov 7, 2025Updated 11 months ago
- Parses RecentFileCacheParser.bcf files☆31Apr 30, 2026Updated 5 months ago
- Search datasets for Bitlocker recovery files and triage live systems for Bitlocker keys.☆60Jan 26, 2025Updated last year
- Automatic, fast parsing of browser artifacts☆17Jan 4, 2025Updated last year
- A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. P…☆27Jan 2, 2023Updated 3 years ago
- Fork this repo! Do a Pull Request! As many times as you want! Learn the ins and outs of how to contribute to GitHub! Make your mistakes h…☆15Jun 21, 2024Updated 2 years ago
- USN Journal full path builder☆69Apr 16, 2026Updated 5 months ago
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆246Sep 15, 2026Updated 3 weeks ago
- PowerShell scripts to aid investigators when utilizing O365 and Magnet Axiom.☆13Aug 26, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Forensic cheatsheets for use with cheat☆16Dec 2, 2021Updated 4 years ago
- ☆61Apr 28, 2026Updated 5 months ago
- Windows Event Log "Microsoft-Windows-Partition%4Diagnostic.evtx" parser and devices' VSNs extractor.☆20Nov 28, 2023Updated 2 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆197Feb 16, 2023Updated 3 years ago
- A tool for fetching DFIR and other GitHub tools.☆30Sep 17, 2026Updated 3 weeks ago
- Windows.EDB Browser☆63Mar 6, 2023Updated 3 years ago
- Forensic tool for extracting and analyzing Google DriveFS cached files and metadata.☆23May 9, 2025Updated last year
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆43Jul 18, 2022Updated 4 years ago
- Search Index Database Reporter☆145Oct 28, 2025Updated 11 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- This is to edit a training forensic image file (raw/dd) and zero out all the unnecessary files.☆11Jun 21, 2025Updated last year
- Parse Microsoft shim databases☆32Apr 26, 2026Updated 5 months ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 10 years ago
- Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indi…☆113Jun 16, 2026Updated 3 months ago
- StickyParser - Sticky Notes Forensic. A Windows Sticky Notes Praser (snt and plum.sqlite supported). Additional Feature: SQLite Recovery …☆23Jul 18, 2023Updated 3 years ago
- A simple python script to generate nested folders based on user input. The script will also name and place a template report document and…☆12May 6, 2026Updated 5 months ago
- Automate forensic traige package collection and evidence parsing with KAPE and Crowdstrike☆15Mar 5, 2022Updated 4 years ago
- A forensic open-source parser module for Autopsy that allows extracting the messages, comments, posts, contacts, calendar entries and rea…☆123Aug 4, 2026Updated 2 months ago
- Slack Parser is a script to parse slack database and extract user-data, chat history, workspace information☆16Feb 21, 2021Updated 5 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- FileSigExtractor is a python based tool which extracts the file signatures of all files within a directory and writes the output to a CSV…☆10Jul 15, 2023Updated 3 years ago
- My own diary notes. Adding the commands, tools, techniques, and resources that I will not memorize.☆16Jul 5, 2023Updated 3 years ago
- Forensic Artifact Collection Tool for macOS☆121Jul 28, 2025Updated last year
- Collection of SQL query templates for digital forensics use by platform and application.☆119Apr 17, 2021Updated 5 years ago
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆13Jun 27, 2023Updated 3 years ago
- DFIQ is a collection of investigative questions and the approaches for answering them☆316Mar 10, 2026Updated 7 months ago
- OneDrive log .ODL reader☆175Nov 3, 2024Updated last year