Open-source digital forensics (DFIR) toolkit with a desktop GUI: analyse E01, AFF4, raw/dd and VMDK disk images, recover deleted files by file carving, build timelines, search evidence and run YARA/Sigma rules. Windows, macOS, Linux.
-
Updated
Oct 7, 2026 - Python