libfvde is a library to access FileVault Drive Encryption (FVDE) (or FileVault2) encrypted volumes. It supports various Mac OS X versions and encryption volume types, including removable media volumes and system volumes. The library provides access to encrypted data on a storage media volume. The project is still experimental and has some unsupported Core Storage format features, such as multiple physical volumes. It also has some planned features, including Dokan support and partial encrypted volumes. libfvde is licensed under LGPLv3+ and has a wiki with documentation and building instructions.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Browse and analyze iPhone/iPad backups with detailed file properties and various viewers.
A recognition framework for identifying products, services, operating systems, and hardware by matching fingerprints against network probes.
A cybersecurity tool for collecting and analyzing forensic artifacts on live systems.
A tool that uses graph theory to reveal hidden relationships and attack paths in an Active Directory environment.
A Python-based engine for automatic creation of timelines in digital forensic analysis
DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.
A tool for triaging crash files with various output formats and debugging engine options.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.