Library to handle the files in zff format (file format to store and handle forensic acquisitions).
☆21Feb 9, 2026Updated 3 weeks ago
Alternatives and similar repositories for zff-rs
Users that are interested in zff-rs are comparing it to the libraries listed below
Sorting:
- $MFT Record Viewer☆24Nov 9, 2022Updated 3 years ago
- Wrapper for TSK (Sleuth Kit) Bindings☆12Jan 10, 2023Updated 3 years ago
- Small scripts and POCs related to digital forensics☆18Nov 1, 2022Updated 3 years ago
- Python library for parsing AccessData AD1 images☆33Jun 1, 2023Updated 2 years ago
- http://moaistory.blogspot.com/2016/08/ie10analyzer.html☆19Jul 20, 2024Updated last year
- extract and parse WEVT_TEMPLATEs from PE files☆18Dec 30, 2023Updated 2 years ago
- A GC link parser for both linkfiles and jumplists.☆18Oct 28, 2016Updated 9 years ago
- A DFVFS Backed Forensic Viewer☆42Apr 13, 2020Updated 5 years ago
- linux c++, fox-toolkit, multi-threaded forensic gui tool☆49Jul 19, 2024Updated last year
- Search datasets for Bitlocker recovery files and triage live systems for Bitlocker keys.☆51Jan 26, 2025Updated last year
- A tool for fetching DFIR and other GitHub tools.☆25Aug 2, 2025Updated 7 months ago
- Recover event log entries from an image by heurisitically looking for record structures.☆26Oct 9, 2015Updated 10 years ago
- Fix acquired .evt - Windows Event Log files (Forensics)☆18Mar 29, 2016Updated 9 years ago
- Manage Your Large Team of Consultants☆11Sep 18, 2025Updated 5 months ago
- Generate Volatility3 profiles from BTF.☆31Dec 21, 2024Updated last year
- Windows Registry binary files comparison Tool.☆26Nov 26, 2025Updated 3 months ago
- Discover USB device history for a specific user☆23Dec 28, 2015Updated 10 years ago
- macOS triage is a python script to collect various macOS logs, artifacts, and other data.☆25Mar 25, 2021Updated 4 years ago
- Tool to parse SRU database☆25Mar 1, 2018Updated 8 years ago
- Assorted classes and methods for indexing reports and retrieving information from an elastic index☆21Jul 5, 2016Updated 9 years ago
- Extract common Windows artifacts from source images and VSCs☆64May 10, 2021Updated 4 years ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆64Dec 18, 2024Updated last year
- A collaboration effort by the DFIR community to provide definitions (sometimes multiple) for common forensic terms!☆26Dec 1, 2022Updated 3 years ago
- ☆33Nov 21, 2024Updated last year
- DataContentViewer module for Autopsy 3.1 to preview dozens of file types☆30Oct 28, 2020Updated 5 years ago
- Automatically exported from code.google.com/p/mac-osx-forensics☆28Jan 12, 2016Updated 10 years ago
- My Year of Python Repository☆28Jun 13, 2020Updated 5 years ago
- System Center Cross Platform Provider for Operations Manager☆39Apr 29, 2025Updated 10 months ago
- Python Forensic and Log Analysis GUI☆27Dec 22, 2014Updated 11 years ago
- Forensic tool for acquisition, triage and analysis of remote block devices via iSCSI protocol.☆44Oct 25, 2024Updated last year
- Django with Data Science [Video], published by Packt☆12Dec 15, 2025Updated 2 months ago
- a GUI Interface for DFIR Open Source Tools☆10Jun 16, 2015Updated 10 years ago
- Backstage Parser☆33Jun 23, 2022Updated 3 years ago
- ☆35Oct 29, 2021Updated 4 years ago
- Windows 10 Live Information viewer☆38Jan 27, 2022Updated 4 years ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆38Jul 18, 2024Updated last year
- Volatility Symbol Generator for Linux Kernels☆37Nov 15, 2023Updated 2 years ago
- Windows Forensics Environment Builder☆180Dec 5, 2025Updated 3 months ago
- FIT is a modular suite of Python applications for digital forensic acquisition of online contents such as web pages, emails, social media…☆97Oct 27, 2025Updated 4 months ago