Scan for deleted files, extract artifacts, and carve out data from unallocated space to help investigate cyber incidents.
Wreckage is an open-source digital forensics and incident response tool for analyzing disk images. It is designed to help security analysts and forensic investigators efficiently scan disk images to uncover indicators of compromise after a cyberattack.
Some of the key features of Wreckage include:
With its extensive artifact parsing and data carving capabilities optimized for speed, Wreckage can save significant analyst time during cyber investigations. The modular extensible design makes it adaptable for multiple investigation scenarios.
Here are some alternatives to Wreckage:
Suggest an alternative ❐