01Performs string carving and automatic classification with over 290 classes in Hashcat notation.
02Dumps critical forensic artifacts including Active Directory, EDB, Windows shortcut, prefetch, Linux ELF, and Windows PE/COFF executables.
03Integrates utility functions akin to `grep`, `head`, `tail`, `uniq`, `wc`, and `hexdump` with syntax highlighting.
04Offers a dedicated "Hunt" mode for carving Linux Journals and Windows Event Logs, generating super timelines in Common Event Format (CEF), and filtering events using Sigma Rules.
05Supports verification of IPs, URLs, Domains, and files via the VirusTotal API.
062 GitHub stars