Tools

BFIP (Bulk Forensic Image Processor)
100% GUI-Driven Front-End for Griffeye Analyze CLI.  Provides streamlined GUI access to Analyze CLI functionality, offering the ability to automate case creation with the ability to bulk select multiple evidence sources and have it automatically located sources, generate names, and process in one step.  Provides additional forensic image processing options using the included Breakpoint Processing Engine.
  • Exclusive Breakpoint Processing Engine for automated carving, extraction, and VICS package generation of allocated, deleted, and unallocated media files.
  • Automate the processing of your media-based examinations at breakneck speeds!
  • GUI-based mode selection for either Standard Process (allocated files only), LACE Carver Processing, or Breakpoint Processing Engine.
  • Bulk ingestion of all forensic images/JSONs simply by designating the parent folder that contains them.
  • GUI-Integrated console output window with logging and processing feedback.
  • Multithreaded Parallel Carving of Forensic Images.
  • Includes additional support for parsing forensic images containing APFS(Apple File System), with automated extraction of media files and import into Griffeye with no additional addon plugins required.
  • Option Mode for Griffeye Processing Engine (GPE) providing GUI-based interface to GPE, eliminating complex CLI commands.
Current Release:
Version 5.1
2/29/2024
Download:
BFIP 5
MD5:0e220339cfb817242971e8ce1475e45d
BFIP V5 – User Manual
 

 

Changelog

Description

 

FastHash

Simple multithreaded MD5 file hashing utility.

 

3 Different Processing Options:
1.Drop the executable in a directory of files and/or folders you want to process and then simply run FastHash. It will recursively process the hash values of all files in the same directory and any subdirectories. 
2.Drag and drop a folder containing any files you want to hash onto the FastHash executable, and it will recursively hash all files in the folder/subfolders.
3.Drag and drop a single file onto the FastHash executable, and it will hash just that file.
 
Results are then saved to both simple text file and more detailed CSV.
Current Release:
Version 1.2
2/22/2024
Download:
FastHash
MD5:
f76f0b86cbd5eebef9c84ffa6441e2ec
FileSifter
FileSifter is a digital forensics live-triage collection tool designed for deployment across multiple OS platforms including Windows, MacOS, and Linux.

Primary Features

-Live File Collection to either ZIP or TAR packages, and/or VICS JSON Packages.
-Keyword Filtering function.  Allows import of custom keyword dictionary file that when enabled will only collect files with match in keyword list.
-Easy targeting of files/folders to be collected using simple user interface and case setup.
-Support for targeted collection of Image, Video, Archives, and/or Documents and packaging into VICS JSON evidence package for easy import and review into tools such as Griffeye Analyze.
-Automatically generates CSV report for all files collected storing original metadata such as MAC times, paths, etc.
-Forensically sound. When FileSifter is executed from a forensic collection drive, program data, reports, and other generated data is only saved to the examiners connected drive.
Current Release:
Version 1.3.7
1/2/2023
Description

Changelog

Download:
FileSifter(Windows)
MD5:78baa6e97681d927073d555d0ad85c11
FileSifter(MacOS)
MD5:3e43c535fec3d68ffedca4f15ec6ba15
FileSifter(Linux)
MD5:35653d2453875033b5fd398d46813723
FileSifter – User Manual
MD5:4f3240337b90b1adfd954f5a5e0a65e4
GK Password Parser
Simple utility that parses either the passwords text file, or PC History file, generated from IOS Graykey dumps. 
Password List:
The passwords file is parsed based on user selectable minimum/maximum password size, and a simple trimmed and sorted list of passwords is generated.
Quickly pair down what can be a very large list of data, filled with long complex tokens, and identify the clear-text passwords immediately.     
Passcode History:
Ingests the Passcode History file generated from Graykey Full Filesystem extractions and automates the ability to brute-force the historic 4/6 digit pin-codes using an integrated version of Hashcat.
Current Release:
Version 1.5 — 12/27/2023 
Download:
GK Password Parser
MD5:1ef37ce13f9800f20d9be7bfb4bc663c
1.5 Changelog

 

PackNHash Auto Archiver
Auto Archiving Utility to bulk archive, validate, hash, and prep complex project folder structures to individual archives.
  • GUI driven for easy configuration.
  • Generates unique logs for each case folder containing:
    • Full directory listing
    • File integrity verifications logs
    • Hashing of generated archives
Current Release:
Version 4.4.2
3/14/2024
Downloads:
PacknHash Auto Archiver
MD5:51207d37794674a480ac6cdec2ba56e8
PackNHash 4 User Guide

Changelog

More Information

VICS JSON Builder
Provides a standalone version of the VICS JSON Utility from BFIP4Griffeye.
Ingests standard output from BFIP and/or PhotoRec and builds a VICS compliant JSON for import into tools such as Griffeye. 
Can be used independently from BFIP4Griffeye to manually generate a VICS compliant JSON from contents of folder.
Includes Universal VICS JSON Format Cleaning tool.  Corrects JSON file formatting by adding missing line-breaks and indentation for easier viewing. 
  • GUI driven for easy use.
  • Opensource

jsonbuilder3.exe

Source Code

MD5 Verification: c91472f17f2d5343a6f1ce20ab02edf7

Support Request