Forensics Artifact Extractor & Parser is an intelligent and completely automated digital forensics tool designed to extract and parse artifacts from forensic disk images, especially E01 files. Just load the image and let the tool do everything: extract, process, and generate parsed outputs using industry-standard tools β all in one click.
Itβs built for DFIR professionals, forensic analysts, and cybersecurity researchers who want speed, reliability, and automation while investigating E01 images.
- π Full Artifact Extraction from
.E01images - π§° Built-in Integration with top tools:
RegRipperAmcacheParserHindsightEvtxECmdMFTECmd- and many more...
- π Auto-parsing of:
NTUSER.DAT,SAM,SYSTEM,SOFTWAREAmcache.hve,SRUDB.dat,PrefetchEvent Logs,Web History, etc.
- π₯οΈ Clean GUI (or CLI optional)
- π§Ύ Consolidated and human-readable output
- π Saves parsed output with proper timestamped folders
- β±οΈ Minimal manual intervention
| Artifact Type | Tool Used |
|---|---|
| Registry Hives | RegRipper |
| Web Artifacts | Hindsight |
| App Execution | AmcacheParser |
| User Activity | SRUM Parser |
| Prefetch Files | PECmd |
| Event Logs | EvtxECmd |
| MFT / USN Journal | MFTECmd / UsnJrnlParser |
- Python 3.10+
- pip
- Windows OS (Recommended for tool compatibility)
- Admin permissions
- Postgres DB
- Option A
git clone https://github.com/sujayadkesar/FAEP.git
cd FAEP
pip install -r requirements.txt
python FAEP_GUI.py- Option B (recommended) Direct installer (exe)
Then, follow the GUI prompts to:
- Load
.E01file - Choose Output Directory
- Hit
Process All - Parsed results will be saved in
ParsedArtifacts/YYYY-MM-DD_HH-MM/
You can also run in headless mode for batch automation. (Docs coming soon)
PRs and suggestions are welcome! Please fork the repository and open an issue or submit a pull request.
- Akhil Dara
- Jnana Ramakrishna
- Eric Zimmerman Tools
- Hindsight by Ryan Benson
- RegRipper by Harlan Carvey
digital forensics, E01 parser, amcache parser, registry parser, forensic automation tool, DFIR, hindsight automation, SRUM parser, artifact extractor, python forensic tool, AutoForenParse, Forensic artifacts parser