Forensic Scripts
Switch branches/tags
Nothing to show
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Failed to load latest commit information.
python-tutorials Sample Contact data file for running with "" Aug 21, 2017 Update Jun 21, 2015 Parses App Manifest Capabilities/Permissions from Windows Phone 8.1 f… Apr 30, 2015 Parses Bing Bar searchhs.dat files Jan 23, 2014 Helps find optimal chunk sizes & search algorithm when searching bina… Aug 20, 2015
dextract.def Sample Template Definition File for Jan 23, 2014 Template Based Data Extraction Python Script Jan 23, 2014 Extracts Font information from .DOCX & .XLSX files Jan 23, 2014 Extracts GPS EXIF data and outputs HTML links to Google Maps Jan 23, 2014 Update Feb 3, 2014 Greps a file/directory of files for selected Google Analytic parameters Jan 23, 2014 Python script takes a Google Search URL or ei parameter and returns a… Oct 10, 2014 Extracts JPG's & metadata from Android Gallery3D app imgcache (8 byte… Aug 4, 2016 Extracts JPG's & metadata from Android Gallery3D app imgcache (UTF16L… Aug 4, 2016 Pretty Prints .JSON Files Jan 23, 2014 Extracts pictures from MS Office 2007 .docx, .xlsx, .pptx files Jun 5, 2015 Extracts XML/Binary Plist data to an SQLite DB Jul 30, 2014 Prints Android Manifest permission strings from an .apk file/director… Jun 13, 2015 Converts a 64 bit Google S2 cellid to a lat, long and S2 cellid level Aug 12, 2016 Converts lat, long and cellid level to a 64 bit Google S2 cellid Aug 12, 2016
sms-grep-sample-config.txt sample configuration file Jan 23, 2014 Greps a file containing SQLite SMS messages using a given number Jan 23, 2014 Extracts/decodes base64 field from SQLite DBs Jun 27, 2015 Dump BLOB fields from SQLite Databases Jul 3, 2015 Parses selected SQLite Database header fields (including SQLite version) Jan 23, 2014
squirrelgripper-README.txt README File containing Installation/Running Instructions for Squirrel… Jan 23, 2014 Extracts ExifTool metadata from a directory's files into an SQLite Da… Jan 23, 2014 Calculates number of seconds between a reference date/time and a targ… Jan 23, 2014 Conjures up an HTML table from an iPhone's voicemail.db SQLite database Jan 23, 2014 Adapted for CallHistory from Lumia 530 Windows Phone 8.10 Sep 10, 2015 Adapted to parse Contacts from Lumia 530 running Windows Phone 8.10 Sep 10, 2015 Sorts/prints .dat file metadata for Windows Phone 8.10 Dec 5, 2015 Prints MMS transaction data for Windows Phone 8.10 Dec 5, 2015 Adapted to parse SMS from a Lumia 530 running Windows Phone 8.10 Sep 10, 2015 Parses Windows Phone 8.0 Call History Aug 20, 2015 Parses Windows Phone 8.0 Contacts Aug 20, 2015 Python script extracts JSON Facebook Messages from Win Phone 8.0 page… Oct 5, 2014 Determines a salted SHA256 hashed Windows Phone 8 PIN Jul 30, 2015 Parses Windows Phone 8.0 SMS Aug 20, 2015 Parses Android Words With Friends v7.1.4 chat data Jul 16, 2014


Forensic Scripts

Currently this project contains assorted Perl/Python scripts from

The scripts are mainly written for/tested on SANS SIFT Virtual Machines. MOST Perl scripts should also run with ActiveState Perl on Windows but ALL have been tested/run on SANS SIFT (v2). Python Scripts have been developed/tested on Ubuntu and/or Windows 7.

Copyright (C) 2012, 2013, 2014, 2015 Adrian Leong (cheeky4n6monkey at gmail dot com)

These programs are free software: you can redistribute them and/or modify them under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or any later version.

These programs are distributed in the hope that they will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You can view the GNU General Public License at