Forensic Scripts
Python Perl
Permalink
Failed to load latest commit information.
README.md Update README.md Jun 21, 2015
WP8_AppPerms.py Parses App Manifest Capabilities/Permissions from Windows Phone 8.1 f… Apr 30, 2015
bing-bar-parser.pl Parses Bing Bar searchhs.dat files Jan 23, 2014
chunkymonkey.py Helps find optimal chunk sizes & search algorithm when searching bina… Aug 20, 2015
dextract.def Sample Template Definition File for dextract.py Jan 23, 2014
dextract.py Template Based Data Extraction Python Script Jan 23, 2014
docx-font-extractor.pl Extracts Font information from .DOCX & .XLSX files Jan 23, 2014
exif2map.pl Extracts GPS EXIF data and outputs HTML links to Google Maps Jan 23, 2014
fbmsg-extractor.py Update fbmsg-extractor.py Feb 3, 2014
gis4cookie.pl Greps a file/directory of files for selected Google Analytic parameters Jan 23, 2014
google-ei-time.py Python script takes a Google Search URL or ei parameter and returns a… Oct 10, 2014
imgcache-parse-mod.py Extracts JPG's & metadata from Android Gallery3D app imgcache (8 byte… Aug 4, 2016
imgcache-parse.py Extracts JPG's & metadata from Android Gallery3D app imgcache (UTF16L… Aug 4, 2016
json-printer.pl Pretty Prints .JSON Files Jan 23, 2014
msoffice-pic-extractor.py Extracts pictures from MS Office 2007 .docx, .xlsx, .pptx files Jun 5, 2015
plist2db.py Extracts XML/Binary Plist data to an SQLite DB Jul 30, 2014
print_apk_perms.py Prints Android Manifest permission strings from an .apk file/director… Jun 13, 2015
s2-cellid2latlong.py Converts a 64 bit Google S2 cellid to a lat, long and S2 cellid level Aug 12, 2016
s2-latlong2cellid.py Converts lat, long and cellid level to a 64 bit Google S2 cellid Aug 12, 2016
sms-grep-sample-config.txt sms-grep.pl sample configuration file Jan 23, 2014
sms-grep.pl Greps a file containing SQLite SMS messages using a given number Jan 23, 2014
sqlite-base64-decode.py Extracts/decodes base64 field from SQLite DBs Jun 27, 2015
sqlite-blob-dumper.py Dump BLOB fields from SQLite Databases Jul 3, 2015
sqlite-parser.pl Parses selected SQLite Database header fields (including SQLite version) Jan 23, 2014
squirrelgripper-README.txt README File containing Installation/Running Instructions for Squirrel… Jan 23, 2014
squirrelgripper.pl Extracts ExifTool metadata from a directory's files into an SQLite Da… Jan 23, 2014
timediff32.pl Calculates number of seconds between a reference date/time and a targ… Jan 23, 2014
vmail-db-2-html.pl Conjures up an HTML table from an iPhone's voicemail.db SQLite database Jan 23, 2014
wp8-1-callhistory.py Adapted for CallHistory from Lumia 530 Windows Phone 8.10 Sep 10, 2015
wp8-1-contacts.py Adapted to parse Contacts from Lumia 530 running Windows Phone 8.10 Sep 10, 2015
wp8-1-mms-filesort.py Sorts/prints .dat file metadata for Windows Phone 8.10 Dec 5, 2015
wp8-1-mms.py Prints MMS transaction data for Windows Phone 8.10 Dec 5, 2015
wp8-1-sms.py Adapted to parse SMS from a Lumia 530 running Windows Phone 8.10 Sep 10, 2015
wp8-callhistory.py Parses Windows Phone 8.0 Call History Aug 20, 2015
wp8-contacts.py Parses Windows Phone 8.0 Contacts Aug 20, 2015
wp8-fb-msg.py Python script extracts JSON Facebook Messages from Win Phone 8.0 page… Oct 5, 2014
wp8-sha256-pin-finder.py Determines a salted SHA256 hashed Windows Phone 8 PIN Jul 30, 2015
wp8-sms.py Parses Windows Phone 8.0 SMS Aug 20, 2015
wwf-chat-parser.py Parses Android Words With Friends v7.1.4 chat data Jul 16, 2014

README.md

4n6-scripts

Forensic Scripts

Currently this project contains assorted Perl/Python scripts from http://cheeky4n6monkey.blogspot.com/

The scripts are mainly written for/tested on SANS SIFT Virtual Machines. MOST Perl scripts should also run with ActiveState Perl on Windows but ALL have been tested/run on SANS SIFT (v2). Python Scripts have been developed/tested on Ubuntu and/or Windows 7.

Copyright (C) 2012, 2013, 2014, 2015 Adrian Leong (cheeky4n6monkey at gmail dot com)

These programs are free software: you can redistribute them and/or modify them under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or any later version.

These programs are distributed in the hope that they will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You can view the GNU General Public License at http://www.gnu.org/licenses/