Mobius Forensic Toolkit is a forensic framework written in Python/GTK that manages cases and case items, providing an abstract interface for developing extensions. Cases and item categories are defined using XML files for easy integration with other tools.
| Tags | Security Forensics |
|---|---|
| Licenses | GPLv2 |
| Operating Systems | OS Independent |
| Implementation | Python |
Recent releases


Release Notes: This release features 14 new registry reports: autorun, services, IE download folder, IE typed URLs, MRU files opened/saved, MRU files executed, search assistant, printer ports, processors, all devices, enumerated devices, HID devices, network devices, and stream devices. Minor improvements were made.


Release Notes: This release introduces the Integrated Case Environment (ICE) extension, which replaces the Case Viewer extension. A new and improved data representation of the case model was developed. Several minor improvements were made.


Release Notes: The new extension Datasource Dossier handles Logicube Dossier imagefiles. The Hive Report features 3 new reports: LSA secrets, Protected storage, and Cached Credentials, and both user password report and email accounts report show the passwords when available. The Part Catalogue has been improved. Several other improvements were made.


Release Notes: The Hive (registry viewer) features three new reports: email accounts, TCP/IP interfaces, and computer descriptions. All registry reports can be exported as CSV and the user password report can be exported in a format suitable for John the Ripper as well. Minor improvements were made.


Release Notes: Six news registry reports were added: user assist, recent docs, product keys, O.S. folders, user logon info, and computer info. Minor improvements were made.