Skip to content
Change the repository type filter

All

    Repositories list

    • Recordization library
      Python
      13968Updated Aug 20, 2025Aug 20, 2025
    • acquire

      Public
      acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container.
      Python
      35109309Updated Aug 20, 2025Aug 20, 2025
    • The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy access to various data sources inside disk images or file collections (a.k.a. targets).
      Python
      677115231Updated Aug 19, 2025Aug 19, 2025
    • Dissect module implementing a parser for the VMFS file system, used by VMware virtualization software.
      Python
      2420Updated Aug 19, 2025Aug 19, 2025
    • A Dissect module implementing parsers for various hypervisor disk, backup and configuration files.
      Python
      7670Updated Aug 18, 2025Aug 18, 2025
    • Dissect triage script for Citrix NetScaler devices
      Python
      123500Updated Aug 16, 2025Aug 16, 2025
    • A Dissect module implementing a parser for Event Trace Log (ETL) files, used by the Windows operating system to log kernel events.
      Python
      3430Updated Aug 15, 2025Aug 15, 2025
    • Browser demo for Dissect
      1001Updated Aug 14, 2025Aug 14, 2025
    • A Dissect module implementing various utility functions for the other Dissect modules.
      Python
      73137Updated Aug 13, 2025Aug 13, 2025
    • Dissect documentation project
      7832Updated Aug 1, 2025Aug 1, 2025
    • A Dissect module implementing a parser for C-like structures.
      Python
      2053132Updated Jul 31, 2025Jul 31, 2025
    • A Dissect module implementing a parser for Microsofts Extensible Storage Engine Database (ESEDB), used for example in Active Directory, Exchange and Windows Update.
      Python
      102110Updated Jul 31, 2025Jul 31, 2025
    • A Dissect module implementing parsers for various executable formats such as PE, ELF and Macho-O.
      Python
      4253Updated Jul 31, 2025Jul 31, 2025
    • A Dissect module implementing a parsers for the SQLite database file format, commonly used by applications to store configuration data.
      Python
      6620Updated Jul 31, 2025Jul 31, 2025
    • A Dissect module implementing a parsers for full volume encryption implementations, currently Microsoft's Bitlocker Disk Encryption (BDE) and Linux Unified Key Setup (LUKS1 and LUKS2).
      Python
      2422Updated Jul 22, 2025Jul 22, 2025
    • dissect

      Public
      Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (part of NCC Group).
      741k51Updated Jul 17, 2025Jul 17, 2025
    • A Dissect module implementing a parser for the SquashFS file system.
      Python
      2071Updated Jun 26, 2025Jun 26, 2025
    • A Dissect module implementing a parser for the btrfs file system.
      Python
      2131Updated Jun 26, 2025Jun 26, 2025
    • Workflow templates for the dissect projects
      3200Updated Jun 26, 2025Jun 26, 2025
    • A Dissect module implementing parsers for various archive and backup formats.
      Python
      4052Updated Jun 24, 2025Jun 24, 2025
    • Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles
      Python
      2417400Updated Jun 23, 2025Jun 23, 2025
    • A Dissect module implementing a parser for the ExtFS file system, the native filesystem for Linux operating systems.
      Python
      2150Updated Jun 20, 2025Jun 20, 2025
    • A Dissect module implementing a parser for the Shellitem structures, commonly used by Microsoft Windows.
      Python
      3310Updated Jun 20, 2025Jun 20, 2025
    • A Dissect module implementing a parser for different disk volume and partition systems, for example LVM2, GPT and MBR.
      Python
      3321Updated Jun 20, 2025Jun 20, 2025
    • PCAP-over-IP server written in Golang
      Go
      32400Updated Jun 2, 2025Jun 2, 2025
    • Dev Container templates for use in the Dissect projects
      0000Updated May 22, 2025May 22, 2025
    • A Dissect module implementing a parser for Windows registry file format, used to store application and OS configuration on Windows operating systems.
      Python
      3300Updated May 20, 2025May 20, 2025
    • A Dissect module implementing a parser for the Object Linking & Embedding (OLE) format, commonly used by document editors on Windows operating systems.
      Python
      2420Updated May 20, 2025May 20, 2025
    • This project is a meta package. It reserves the namespace for Dissect packages made by external contributors.
      Python
      2000Updated May 20, 2025May 20, 2025
    • A Dissect module implementing a parser for the Windows Common Information Model (CIM) database, used in the Windows operating system.
      Python
      5520Updated May 20, 2025May 20, 2025