Curated tools and references for DFIR investigations, including timelining, parsing, and analysis.
Powerful access to data
Projects and experiments by @easymetadata. This page lists public repositories directly from GitHub.
Welcome to EasyMetaData. We focus on helping you understand and analyze information better. Whether you are an IT professional, InfoSec practitioner, or DFIR analyst, our tools aim to make exploring the metadata that lurks in everthing.
Lists
Feeds and tools for IP reputation, ASN data, and threat intelligence enrichment.
A collection for metadata-related resources and tooling. May be empty as it evolves.
Resources focused on IoT security, forensics, and analysis.
Projects
MetaDiver
An easy-to-use solution for extracting and reviewing metadata from files, email, and system artifacts on Windows. Supports PST, MSG, EML, PDF, Office, images, media, and thousands more via engines like Apache Tika and Outlook Redemption.
IP Tools
IP geo ip and threat lookup enrichment python scripts.
ShadowKit
Recover previous versions of files on Windows, including versions not available via Explorer. Especially useful on Windows 8 and later.
Projects on GitHub
Explore scripts, tools, and experiments maintained under the EasyMetaData GitHub account.
GitHub Repositories
Loading repositories…
Books on Forensics
A practical guide covering techniques and processes used in computer forensics.
Techniques and case studies from the Hacking Exposed series focused on forensics.