Byte Breach Forensic Utilities is a pocket digital-forensics lab for examiners,
investigators, IT auditors and cybersecurity students. Every analysis runs
fully on your device — evidence files are opened read-only and are never
uploaded anywhere.
22 EXAMINER TOOLS
• CDR / IPDR Analyser — import call-detail or IP-detail records from .csv/.xlsx
and get an instant dashboard: top contacts, hourly activity, night calls,
call-type split, IMEI & cell-tower analysis, SIM-swap indicators; for IPDR:
top destination IPs, ports, protocols and data volume. Export the full
report as CSV or PDF.
• SQL DB Analyser — open SQLite databases (.db/.sqlite), browse table data
in-app, parse .sql scripts including INSERT data, triage SQL Server
.mdf/.ldf structure, and export schema + data.
• SQLite Explorer — read-only SQL queries against any SQLite artifact.
• Excel Dashboard — .xlsx/.csv statistics, column profiling and preview.
• Hashing — 14 algorithms (MD5→SHA-3, BLAKE2/3, RIPEMD) plus fuzzy hashing.
• Hash Checker — verify files against known hash sets, identify hash types.
• File Type — magic-byte identification and extension-mismatch detection.
• Metadata — EXIF, PDF, PNG and ID3 metadata extraction.
• Steganography — appended data, embedded signatures, LSB screening.
• Strings & Entropy — printable-string extraction and encryption detection.
• Encoding — Base64, hex, URL decode and lookup tables.
• Browser Artifacts — history, cookies and downloads from browser databases.
• Email Headers — .eml received-chain mapping, hop IPs, SPF/DKIM results.
• Windows Artifacts — .lnk shortcut parsing and Recycle Bin $I records.
• PCAP Viewer — conversations, DNS and HTTP from packet captures.
• Credential Files — structural triage of logins.json and .rdp (no decryption).
• Device Details — build, patch level, root indicators, battery.
• Live Triage — WiFi and LAN scanning (the only online tool, on your action).
• Hardware Reference — examiner's reference for storage and server hardware.
• Cases — evidence register with a tamper-evident chain-of-custody log.
• PC Companion — checklists for desk-side acquisition.
• Watermarked reports — every module exports branded CSV/PDF reports.
BUILT FOR EVIDENCE HANDLING
• 100% on-device analysis — nothing is uploaded, no account needed.
• Evidence is opened read-only via the system file picker.
• Case actions are recorded in a hash-chained audit log.
• Reports carry timestamps and the examiner ID you set.
On-device digital forensics: CDR/IPDR, hashing, metadata, SQL, PCAP & reports.