Digital forensic analysis tool that provides a user-friendly interface for investigating disk images.
-
Updated
Sep 1, 2026 - Python
Digital forensic analysis tool that provides a user-friendly interface for investigating disk images.
Rust DFIR tool that massively parses cross-platform evidence, even deleted logs, into a lateral movement timeline and graph database.
Digital Forensics Essentials (DFE)
Utility for recovering ES File Explorer encrypted files (.eslock)
Forensic Linux VM for Apple Silicon, ARM64 and x86-64 compatible platforms
Forensic snapshot tool. Generates browsable offline HTML reports from drives, folders, and E01 images. Features file hashing and keyword search.Forensic snapshot tool. Generates browsable offline HTML reports from drives, folders, and E01 images. Features file hashing and keyword search.
Python tool to quickly extract embedded JPEG images from pcap files. Perfect for image extraction, data recovery, and digital forensics with reliable error handling..
Telegram personal message, channel, and groups scraper for digital investigations.
A comprehensive Model Context Protocol (MCP) server for Android device forensic data acquisition using Android Debug Bridge (ADB).
PEInsight is a fast and efficient command-line tool for parsing Windows Portable Executable (PE) files, written in C.
Open-source ReFS forensics (Resilient File System v3.4-v3.14): file listing, super-timeline, USN + MLog journals, deleted-file recovery, snapshots plus a byte-level on-disk reference.
Tools to decrypt files from the apk Vault - Hide Pics, App Lock
Android RAM Parser
A MATLAB-based Digital Image Forensics Dashboard for detecting image tampering using ELA, Noise Analysis, JPEG Artifacts, and Copy-Move detection.
A native desktop workstation for forensic image analysis and enhancement — that tells you which parts of the result were measured and which were invented.
Run FTK Imager directly from a portable USB or WinFE environment to perform forensic imaging without installing software on the target system.
EvideX is a tamper-evident security evidence platform for log integrity monitoring, incident triage, completeness verification, compliance evidence, and SOC-style operational review. EvideX is designed as a strong production-style MVP for security operations, digital forensics, compliance demonstrations, and portfolio/capstone evaluation.
An offline, cross-platform forensic image examiner. No dependencies beyond the Python standard library.
Browser-based Mac Model Finder — A forensic reference tool for identifying Apple computer device models, T2 and Apple Silicon systems, and acquisition workflows. Created by Junaid Abid for demonstration and educational purposes.
Cross-platform Forensic Imaging Tool
To associate your repository with the digital-forensic-tool topic, visit your repo's landing page and select "manage topics."