Hunt for SQLite files used by various applications
☆30Mar 1, 2026Updated 2 weeks ago
Alternatives and similar repositories for SQLiteHunter
Users that are interested in SQLiteHunter are comparing it to the libraries listed below
Sorting:
- Quick ESXi Log Parser☆30Oct 20, 2025Updated 5 months ago
- This is to edit a training forensic image file (raw/dd) and zero out all the unnecessary files.☆11Jun 21, 2025Updated 9 months ago
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated last year
- StickyParser - Sticky Notes Forensic. A Windows Sticky Notes Praser (snt and plum.sqlite supported). Additional Feature: SQLite Recovery …☆21Jul 18, 2023Updated 2 years ago
- A series of python scripts to extract information from Dark Web Applications☆14Mar 26, 2025Updated 11 months ago
- Get the call stack of every thread in the target process☆13Jun 17, 2022Updated 3 years ago
- ☆13Oct 21, 2023Updated 2 years ago
- Search datasets for Bitlocker recovery files and triage live systems for Bitlocker keys.☆52Jan 26, 2025Updated last year
- Parser for Sdba memory pool tags☆21Jul 16, 2021Updated 4 years ago
- VMDK Forensic Artifact Extractor (VFAE) is windows based tool written in C++ that extracts files with a known location from VMDK images r…☆17Aug 7, 2015Updated 10 years ago
- misp-guard is a mitmproxy addon that inspects and blocks outgoing events to external MISP instances via sync mechanisms (pull/push) based…☆20Jan 9, 2026Updated 2 months ago
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight,…☆40Oct 24, 2025Updated 4 months ago
- Entra ID (Azure AD) error codes as JSON☆16Oct 30, 2025Updated 4 months ago
- Vault of Windows Registry forensic artifacts☆28Nov 12, 2025Updated 4 months ago
- /ˈhäjˌpäj/ "a confused mixture."☆13Mar 5, 2026Updated 2 weeks ago
- MS Word (DOCx) Parsing Tool☆25Mar 14, 2026Updated last week
- Windows Forensics Salt States☆21Mar 11, 2026Updated last week
- Scripts to extract compound bplists in the iOS -> KnowledgeC.db -> structuredmetadata table.☆27May 12, 2019Updated 6 years ago
- Python web app for previewing data in a Chrome Profile Folder☆24Jul 1, 2024Updated last year
- Module(s) related to reading SEGB (fka "Biome") data from iOS, mascOS, etc.☆29Sep 9, 2025Updated 6 months ago
- A small util to brute-force prefetch hashes☆77Jun 24, 2022Updated 3 years ago
- The ultimate streamline for Volatility 3. Speed up process of memory artifacts extraction phase☆14Dec 19, 2024Updated last year
- Search Index Database Reporter☆131Oct 28, 2025Updated 4 months ago
- Some dfir stuff☆31Jan 12, 2022Updated 4 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆44Jul 18, 2022Updated 3 years ago
- Web app built to allow digital forensic professionals to search for the forensic tools that will parse artifacts from various apps.☆18Apr 30, 2025Updated 10 months ago
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆22Apr 16, 2021Updated 4 years ago
- A simple python script to generate nested folders based on user input. The script will also name and place a template report document and…☆11Jun 19, 2025Updated 9 months ago
- mister-skinnylegs is an open plugin framework for parsing website/webapp artifacts in browser data. It currently provides a command line …☆19Nov 14, 2025Updated 4 months ago
- Google Filestream Forensic Tool☆22Mar 10, 2022Updated 4 years ago
- ☆22Aug 29, 2024Updated last year
- PyVelociraptor contains the python bindings for the Velociraptor API.☆21Feb 11, 2026Updated last month
- ☆24Mar 12, 2025Updated last year
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆117Jan 26, 2022Updated 4 years ago
- Tools for macOS Forensic Bootable media☆16May 20, 2020Updated 5 years ago
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with built-in process inspect…☆213Updated this week
- Artifact collection tool for *nix systems☆213Mar 20, 2024Updated 2 years ago
- Quick and dirty script to parse bplists with Ruby☆14Oct 29, 2020Updated 5 years ago