MFTMactime
MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.
BAP is a suite of utilities and libraries that enables analysis of binary programs. It supports various architectures and includes various analyses, a standard interpreter, microexecution interpreter, and a symbolic executor. It also features its own domain-specific language, Primus Lisp, for implementing analyses and specifying verification conditions.
MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.
A high-performance digital forensics exploitation tool for extracting structured information from various inputs without parsing file system structures.
Web interface for the Volatility Memory Forensics Framework
A tool for fixing acquired .evt Windows Event Log files in digital forensics.
Educational CTF-styled challenges for Memory Forensics.
DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.