A toolset to make a system look as if it was the victim of an APT attack
A better strings utility!
PowerShell script to collect memory and (triage) disk forensics
iOS Photos.sqlite queries that may help with decoding data stored in Photos.sqlite. These queries are based on testing, research and some community published research. These queries were written to work for the Photos.sqlite database stored at: iOS: /private/var/mobile/media/PhotoData/Photos.Sqlite Mac OS: /Users//Pictures/PhotosLibrary.photoslibrary/database/Photos.sqlite
Automatic and Custom Destinations jump list parser with Windows 10 support
Resources provided by the community that can serve to be useful for Law Enforcement worldwide
Lnk Explorer Command line edition!!
Parses $MFT from NTFS file systems
Public tools, scripts or code snippets that can help when working with our products
A collaboration to develop robust policies and procedures for DFIR labs
THOR Scanner User Manual