Log forensic artifacts as JSON in ECS format. Part of the Forensic Artifacts Collecting Toolkit.
-
Updated
Mar 28, 2026 - Go
Log forensic artifacts as JSON in ECS format. Part of the Forensic Artifacts Collecting Toolkit.
Mount various disk images for forensic read-only processing. Part of the Forensic Artifacts Collecting Toolkit.
Find forensic artifacts in mount points or the live system. Part of the Forensic Artifacts Collecting Toolkit.
Extract the BootKey from an offline system hive.
Add a description, image, and links to the forensic-tool topic page so that developers can more easily learn about it.
To associate your repository with the forensic-tool topic, visit your repo's landing page and select "manage topics."