Artifact Analysis Registry/Event Analysis NTFS Analysis Network Utilities PE Utilities Miscellaneous
Artifact Analysis (top)
Windows Prefetch Parser (pf)
32-bit Version | 64-bit Version | |||
Windows: | pf32.v.1.37.win.zip | pf64.v.1.37.win.zip | md5/sha1 | |
Linux: | pf32.v.1.36.lin.tar.gz* | pf64.v.1.36.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | pf.v.1.36.dmg | md5/sha1 | |
Windows 'index.dat' Parser (id)
32-bit Version | 64-bit Version | |||
Windows: | id32.v.0.90.win.zip | id64.v.0.90.win.zip | md5/sha1 | |
Linux: | id32.v.0.89.lin.tar.gz* | id64.v.0.89.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | id.v.0.89.dmg | md5/sha1 | |
Windows LNK Parsing Utility (lp)
32-bit Version | 64-bit Version | |||
Windows: | lp32.v.1.05.win.zip | lp64.v.1.05.win.zip | md5/sha1 | |
Linux: | lp32.v.1.04.lin.tar.gz* | lp64.v.1.04.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | lp.v.1.04.dmg | md5/sha1 | |
Windows USB Storage Parser (usp)
32-bit Version | 64-bit Version | |||
Windows: | usp32.v.0.77.win.zip | usp64.v.0.77.win.zip | md5/sha1 | |
Linux: | usp32.v.0.76.lin.tar.gz* | usp64.v.0.76.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | usp.v.0.76.dmg | md5/sha1 | |
Timeline ActivitiesCache Parser (tac)
32-bit Version | 64-bit Version | |||
Windows: | tac32.v.0.31.win.zip | tac64.v.0.31.win.zip | md5/sha1 | |
Linux: | tac32.v.0.30.lin.tar.gz* | tac64.v.0.30.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | tac.v.0.30.dmg | md5/sha1 | |
Windows Jump List Parser (jmp)
32-bit Version | 64-bit Version | |||
Windows: | jmp32.v.0.61.win.zip | jmp64.v.0.61.win.zip | md5/sha1 | |
Linux: | jmp32.v.0.60.lin.tar.gz* | jmp64.v.0.60.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | jmp.v.0.60.dmg | md5/sha1 | |
Windows Shim Database (SDB) Parser (shims)
32-bit Version | 64-bit Version | |||
Windows: | shims32.v.0.42.win.zip | shims64.v.0.42.win.zip | md5/sha1 | |
Linux: | shims32.v.0.41.lin.tar.gz* | shims64.v.0.41.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | shims.v.0.41.dmg | md5/sha1 | |
Trash Inspection & Analysis (tia)
32-bit Version | 64-bit Version | |||
Windows: | tia32.v.0.34.win.zip | tia64.v.0.34.win.zip | md5/sha1 | |
Linux: | tia32.v.0.33.lin.tar.gz* | tia64.v.0.33.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | tia.v.0.33.dmg | md5/sha1 | |
Safari Artifact Parser (sap)
32-bit Version | 64-bit Version | |||
Windows: | sap32.v.0.15.win.zip | sap64.v.0.15.win.zip | md5/sha1 | |
Linux: | sap32.v.0.14.lin.tar.gz* | sap64.v.0.14.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | sap.v.0.14.dmg | md5/sha1 | |
Windows Push Notification DB Parser (wpn)
32-bit Version | 64-bit Version | |||
Windows: | wpn32.v.0.27.win.zip | wpn64.v.0.27.win.zip | md5/sha1 | |
Linux: | wpn32.v.0.26.lin.tar.gz* | wpn64.v.0.26.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | wpn.v.0.26.dmg | md5/sha1 | |
MS Office Backstage Parser (bs)
32-bit Version | 64-bit Version | |||
Windows: | bs32.v.0.20.win.zip | bs64.v.0.20.win.zip | md5/sha1 | |
Linux: | bs32.v.0.19.lin.tar.gz* | bs64.v.0.19.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | bs.v.0.19.dmg | md5/sha1 | |
Chromium SQLite Parser (csp)
32-bit Version | 64-bit Version | |||
Windows: | csp32.v.0.23.win.zip | csp64.v.0.23.win.zip | md5/sha1 | |
Linux: | csp32.v.0.22.lin.tar.gz* | csp64.v.0.22.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | csp.v.0.22.dmg | md5/sha1 | |
Mozilla SQLite Parser (msp)
32-bit Version | 64-bit Version | |||
Windows: | msp32.v.0.17.win.zip | msp64.v.0.17.win.zip | md5/sha1 | |
Linux: | msp32.v.0.16.lin.tar.gz* | msp64.v.0.16.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | msp.v.0.16.dmg | md5/sha1 | |
Mozilla Cache Parser (mcp)
32-bit Version | 64-bit Version | |||
Windows: | mcp32.v.0.19.win.zip | mcp64.v.0.19.win.zip | md5/sha1 | |
Linux: | mcp32.v.0.18.lin.tar.gz* | mcp64.v.0.18.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | mcp.v.0.18.dmg | md5/sha1 | |
Chromium Cache Parser (ccp)
32-bit Version | 64-bit Version | |||
Windows: | ccp32.v.0.12.win.zip | ccp64.v.0.12.win.zip | md5/sha1 | |
Linux: | ccp32.v.0.11.lin.tar.gz* | ccp64.v.0.11.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | ccp.v.0.11.dmg | md5/sha1 | |
FAT32 & exFAT Analysis (fata)
32-bit Version | 64-bit Version | |||
Windows: | fata32.v.0.10.win.zip | fata64.v.0.10.win.zip | md5/sha1 | |
Linux: | fata32.v.0.10.lin.tar.gz* | fata64.v.0.10.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | fata.v.0.10.dmg | md5/sha1 | |
Registry and Event Log Analysis (top)
Yet Another Registry Utility (yaru)
32-bit Version | 64-bit Version | |||
Windows: | yaru32.v.1.87.win.zip | yaru64.v.1.87.win.zip | md5/sha1 | |
Linux: | yaru32.v.1.85.lin.tar.gz* | yaru64.v.1.85.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | yaru.v.1.85.dmg | md5/sha1 | |
Windows Event Log Viewer (evtx_view)
32-bit Version | 64-bit Version | |||
Windows: | evtx_view32.v.1.19.win.zip | evtx_view64.v.1.19.win.zip | md5/sha1 | |
Linux: | evtx_view32.v.1.18.lin.tar.gz* | evtx_view64.v.1.18.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | evtx_view.v.1.18.dmg | md5/sha1 | |
Windows ShellBag Parser (sbag)
32-bit Version | 64-bit Version | |||
Windows: | sbag32.v.0.77.win.zip | sbag64.v.0.77.win.zip | md5/sha1 | |
Linux: | sbag32.v.0.76.lin.tar.gz* | sbag64.v.0.76.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | sbag.v.0.76.dmg | md5/sha1 | |
Computer Account Forensic Artifact Extractor (cafae)
32-bit Version | 64-bit Version | |||
Windows: | cafae32.v.0.77.win.zip | cafae64.v.0.77.win.zip | md5/sha1 | |
Linux: | cafae32.v.0.76.lin.tar.gz* | cafae64.v.0.76.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | cafae.v.0.76.dmg | md5/sha1 | |
Windows Event Log Parser (evtwalk)
32-bit Version | 64-bit Version | |||
Windows: | evtwalk32.v.0.62.win.zip | evtwalk64.v.0.62.win.zip | md5/sha1 | |
Linux: | evtwalk32.v.0.61.lin.tar.gz* | evtwalk64.v.0.61.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | evtwalk.v.0.61.dmg | md5/sha1 | |
Windows AppCompatibility Cache Utility (wacu)
32-bit Version | 64-bit Version | |||
Windows: | wacu32.v.0.50.win.zip | wacu64.v.0.50.win.zip | md5/sha1 | |
Linux: | wacu32.v.0.49.lin.tar.gz* | wacu64.v.0.49.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | wacu.v.0.49.dmg | md5/sha1 | |
Event Log MessageTables Offline (elmo)
32-bit Version | 64-bit Version | |||
Windows: | elmo32.v.0.42.win.zip | elmo64.v.0.42.win.zip | md5/sha1 | |
Linux: | elmo32.v.0.41.lin.tar.gz* | elmo64.v.0.41.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | elmo.v.0.41.dmg | md5/sha1 | |
Trace Event Log and Analysis (tela)
32-bit Version | 64-bit Version | |||
Windows: | tela32.v.0.28.win.zip | tela64.v.0.28.win.zip | md5/sha1 | |
Linux: | tela32.v.0.27.lin.tar.gz* | tela64.v.0.27.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | tela.v.0.27.dmg | md5/sha1 | |
Windows EVTX Fragment eXtension Parser (evtfx)
32-bit Version | 64-bit Version | |||
Windows: | evtfx32.v.0.13.win.zip | evtfx64.v.0.13.win.zip | md5/sha1 | |
Linux: | evtfx32.v.0.12.lin.tar.gz* | evtfx64.v.0.12.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | evtfx.v.0.12.dmg | md5/sha1 | |
NTFS Filesystem Analysis (top)
Windows Journal Parser (jp)
32-bit Version | 64-bit Version | |||
Windows: | jp32.v.1.47.win.zip | jp64.v.1.47.win.zip | md5/sha1 | |
Linux: | jp32.v.1.46.lin.tar.gz* | jp64.v.1.46.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | jp.v.1.46.dmg | md5/sha1 | |
NTFS Directory Enumerator (ntfsdir)
32-bit Version | 64-bit Version | |||
Windows: | ntfsdir32.v.1.43.win.zip | ntfsdir64.v.1.43.win.zip | md5/sha1 | |
Linux: | ntfsdir32.v.1.41.lin.tar.gz* | ntfsdir64.v.1.41.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | ntfsdir.v.1.41.dmg | md5/sha1 | |
NTFS File Copy Utility (ntfscopy)
32-bit Version | 64-bit Version | |||
Windows: | ntfscopy32.v.1.11.win.zip | ntfscopy64.v.1.11.win.zip | md5/sha1 | |
Linux: | ntfscopy32.v.1.10.lin.tar.gz* | ntfscopy64.v.1.10.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | ntfscopy.v.1.10.dmg | md5/sha1 | |
Windows $MFT and NTFS Metadata Extractor Tool (ntfswalk)
32-bit Version | 64-bit Version | |||
Windows: | ntfswalk32.v.0.92.win.zip | ntfswalk64.v.0.92.win.zip | md5/sha1 | |
Linux: | ntfswalk32.v.0.91.lin.tar.gz* | ntfswalk64.v.0.91.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | ntfswalk.v.0.91.dmg | md5/sha1 | |
Windows INDX Slack Parser (wisp)
32-bit Version | 64-bit Version | |||
Windows: | wisp32.v.0.56.win.zip | wisp64.v.0.56.win.zip | md5/sha1 | |
Linux: | wisp32.v.0.55.lin.tar.gz* | wisp64.v.0.55.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | wisp.v.0.55.dmg | md5/sha1 | |
Graphical Engine for NTFS Analysis (gena)
32-bit Version | 64-bit Version | |||
Windows: | gena32.v.0.57.win.zip | gena64.v.0.57.win.zip | md5/sha1 | |
Linux: | gena32.v.0.56.lin.tar.gz* | gena64.v.0.56.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | gena.v.0.56.dmg | md5/sha1 | |
$MFT and $LogFile Analysis (mala)
32-bit Version | 64-bit Version | |||
Windows: | mala32.v.0.21.win.zip | mala64.v.0.21.win.zip | md5/sha1 | |
Linux: | mala32.v.0.20.lin.tar.gz* | mala64.v.0.20.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | mala.v.0.20.dmg | md5/sha1 | |
Network Support Utilities (top)
DNS Query Utility (dqu)
32-bit Version | 64-bit Version | |||
Windows: | dqu32.v.0.46.win.zip | dqu64.v.0.46.win.zip | md5/sha1 | |
Linux: | dqu32.v.0.45.lin.tar.gz* | dqu64.v.0.45.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | dqu.v.0.45.dmg | md5/sha1 | |
Packet Capture ICMP Carver (pic)
32-bit Version | 64-bit Version | |||
Windows: | pic32.v.0.37.win.zip | pic64.v.0.37.win.zip | md5/sha1 | |
Linux: | pic32.v.0.36.lin.tar.gz* | pic64.v.0.36.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | Not Available | ||
Network Xfer Client/Server Utility (nx)
32-bit Version | 64-bit Version | |||
Windows: | nx32.v.0.40.win.zip | nx64.v.0.40.win.zip | md5/sha1 | |
Linux: | nx32.v.0.39.lin.tar.gz* | nx64.v.0.39.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | nx.v.0.39.dmg | md5/sha1 | |
Modular Inspection Network Xfer Agent (minx)
32-bit Version | 64-bit Version | |||
Windows: | minx32.v.0.26.win.zip | minx64.v.0.26.win.zip | md5/sha1 | |
Linux: | minx32.v.0.25.lin.tar.gz* | minx64.v.0.25.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | minx.v.0.25.dmg | md5/sha1 | |
Portable Executable Utilities (top)
Windows Portable Executable Viewer (pe_view)
32-bit Version | 64-bit Version | |||
Windows: | pe_view32.v.1.24.win.zip | pe_view64.v.1.24.win.zip | md5/sha1 | |
Linux: | pe_view32.v.1.23.lin.tar.gz* | pe_view64.v.1.23.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | pe_view.v.1.23.dmg | md5/sha1 | |
Portable Executable Scanner (pescan)
32-bit Version | 64-bit Version | |||
Windows: | pescan32.v.0.63.win.zip | pescan64.v.0.63.win.zip | md5/sha1 | |
Linux: | pescan32.v.0.62.lin.tar.gz* | pescan64.v.0.62.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | pescan.v.0.62.dmg | md5/sha1 | |
Miscellaneous Tools (top)
Volume Shadow Snapshot Enumerator (vssenum)
32-bit Version | 64-bit Version | |||
Windows: | vssenum32.v.0.35.win.zip | vssenum64.v.0.35.win.zip | md5/sha1 | |
Linux: | Not Available | Not Available | ||
macOS: | Not Available | Not Available | ||
Windows Symbol Fetch Utility (sf)
32-bit Version | 64-bit Version | |||
Windows: | sf32.v.0.61.win.zip | sf64.v.0.61.win.zip | md5/sha1 | |
Linux: | Not Available | Not Available | ||
macOS: | Not Available | Not Available | ||
CSV Data eXchange (csvdx)
32-bit Version | 64-bit Version | |||
Windows: | csvdx32.v.0.39.win.zip | csvdx64.v.0.39.win.zip | md5/sha1 | |
Linux: | csvdx32.v.0.38.lin.tar.gz* | csvdx64.v.0.38.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | csvdx.v.0.38.dmg | md5/sha1 | |
Disk Utility & Packer (dup)
32-bit Version | 64-bit Version | |||
Windows: | dup32.v.0.43.win.zip | dup64.v.0.43.win.zip | md5/sha1 | |
Linux: | Not Available | dup64.v.0.43.lin.tar.gz | md5/sha1 | |
macOS: | Not Available | dup.v.0.43.dmg | md5/sha1 | |
Package Builds (top)
Dec 2022 build (package)
32-bit Version | 64-bit Version | |||
Windows: | 2022.12.12.win32.zip | 2022.12.12.win64.zip | md5/sha1 | |
Linux: | Not Available | 2022.12.12.lin64.zip | md5/sha1 | |
macOS: | Not Available | 2022.12.12.mac.dmg | md5/sha1 | |
*32bit apps can run in a 64bit linux distribution if "ia32-libs" (and dependencies) are present. |