Skip to content
#

e01

Here are 22 public repositories matching this topic...

TRACE-Forensic-Toolkit

Open-source digital forensics (DFIR) toolkit with a desktop GUI: analyse E01, AFF4, raw/dd and VMDK disk images, recover deleted files by file carving, build timelines, search evidence and run YARA/Sigma rules. Windows, macOS, Linux.

  • Updated Oct 8, 2026
  • Python

Free, open-source automation of Windows forensic examinations: load an E01/raw/VMDK/VHDX image, pick a case type (DLP, USB, malware, phishing, ClickFix, RMM, ransomware), get answered questions, every parsed artifact as CSV and a court-ready report. Validated against NIST CFReDS.

  • Updated Oct 7, 2026
  • Python

End-to-end digital forensics lab — forensic image acquisition with FTK Imager (E01 format, MD5/SHA-1 verification) and deleted file recovery & artifact analysis with Autopsy (The Sleuth Kit). Recovered 70+ deleted files from unallocated NTFS sectors. Educational DFIR project aligned with NIST SP 800-86.

  • Updated Oct 8, 2026

Add this topic to your repo

To associate your repository with the e01 topic, visit your repo's landing page and select "manage topics."

Learn more