We have hosted the application redact in order to run this application in our online workstations with Wine or directly.


Quick description about redact:

REDACT 3.3.0 is an open-source Windows anti-forensics & artifact sanitization suite that permanently destroys 255 system artifacts — browser history, registry traces, NTFS change journals, Windows Recall AI snapshots, live RAM, and encrypted volume key material.

New in 3.3.0: Auto-Trigger Engine — USB Panic Trigger, Login Failure Trigger, and Dead Man's Switch fire a HIGH-tier wipe automatically without manual interaction.

BitLocker and VeraCrypt header destruction renders encrypted volumes permanently unrecoverable. EFS key wipe and Windows Hello NGC store included.

Zero-footprint: Transient Execution Splitting, NTFS File Cliff Masking, Registry LastWrite Spoofing.

4 wipe standards: 1-Pass Quick, NIST SP 800-88, 7-Pass DoD 5220.22-M, 35-Pass Gutmann.

10 browsers: Chrome, Edge, Firefox, Brave, Vivaldi, Arc, Zen, Pale Moon, Tor, Comet.

Companion: AAD-50 — firmware-level NVMe sanitization adopted into linux-nvme/nvme-cli in 14 days. Free. No telemetry.

Features:
  • 255 sanitization targets — 60 low, 70 medium, 125 high-sensitivity items across registry hives, caches, browser data, and forensic artifact stores
  • 4 wipe standards — 1-Pass Quick (SSD-optimised), NIST SP 800-88, 7-Pass DoD 5220.22-M, 35-Pass Gutmann.
  • Transient Execution Splitting — clones to a randomised temporary name on launch, reducing visibility in Prefetch and BAM.
  • NTFS File Cliff Masking — writes and immediately deletes dummy files after each wipe batch to obscure deletion spikes in NTFS metadata.
  • Registry LastWrite Spoofing — rolls parent key timestamps forward before deletion to mask erasure events.
  • 10-browser coverage — Chrome, Edge, Firefox, Brave, Vivaldi, Arc, Zen, Pale Moon, Tor, Comet. Cache, history, cookies, saved passwords.
  • Windows Recall / CoreAI destruction — permanently deletes the AI screenshot store and semantic timeline SQLite database.
  • Deep forensic artifact removal — AmCache, ShimCache, BAM, NTFS $UsnJrnl, $LogFile, Shell Bags, UserAssist, SRUM database, USB device history.
  • USB device history erasure — removes all USBSTOR registry entries including serial numbers, vendor strings, and connection timestamps.
  • Auto process handle termination — detects locked files and offers to terminate the blocking process to complete the wipe.
  • Windows 11 Fluent Dark UI — per-item toggle switches across tier-grouped cards. Safe Selection preset in one click.
  • Auto-UAC elevation — requests Administrator privileges on launch automatically.
  • No external dependencies — pure Python standard library. No pip packages required to run.
  • Live RAM Overwrite — allocates 85% of free physical RAM and fills with random bytes then zeros, defeating live acquisition tools like DumpIt and Magnet RAM Capture
  • BitLocker header destruction — overwrites VMK headers on all drive volumes rendering encrypted data permanently unrecoverable. NIST 800-88 Cryptographic Erase compliant.
  • VeraCrypt container nuke — overwrites primary and backup headers of all .vc/.hc files found on the system without mounting or decrypting
  • EFS key material wipe — destroys RSA private keys and DPAPI master keys making all EFS-encrypted files permanently unreadable even with valid login credentials
  • Windows Hello and NGC key store destruction — wipes PIN, fingerprint, and facial recognition key material and detaches Azure AD device binding
  • Auto-Trigger Engine — USB Panic Trigger — auto-wipe fires instantly when a pre-armed USB drive is removed. No interaction required.
  • Auto-Trigger Engine — Login Failure Trigger — monitors failed Windows login attempts and fires a full wipe after a user-defined threshold.
  • Auto-Trigger Engine — Dead Man's Switch — countdown timer fires a HIGH-tier wipe at zero. All three triggers run simultaneously and independently.


Audience: Advanced End Users, Information Technology, Legal Industry, Security, Security Professionals, System Administrators.
User interface: Win32 (MS Windows).
Programming Language: Python.
Categories:
Cryptography, Cybersecurity, Data Wipe

Page navigation:

©2024. Winfy. All Rights Reserved.

By OD Group OU – Registry code: 1609791 -VAT number: EE102345621.