Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- usb-forensic Public
USB device-history correlation engine — reconstructs USB connection history from every Windows artifact (registry, SetupAPI, event logs, LNK) plus macOS/Linux, and scores cross-source timestamp consistency by tamper-independence. Runs headless on any OS; pipeline-native JSONL, reproducible, panic-free.
- ext4fs-forensic Public
Forensic-grade ext4 filesystem parser — pure safe Rust, MIT licensed. Deleted file recovery, journal parsing, timeline generation, slack space analysis, and more.
- blazehash Public
Forensic file hasher — BLAKE3 at 1,640 MB/s, 25 hash algorithms, Ed25519 + post-quantum signing, Bitcoin timestamps, YARA scanning, 50+ remote backends. hashdeep for the modern era.
- issen Public
Point it at disk + memory evidence; get a correlated, ATT&CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps, parses NTFS/registry/EVTX/prefetch/LNK/SRUM/browser/Amcache + memory (processes, netstat, injection), correlates into a DuckDB super-timeline, scans threat-intel, and reports.
- forensicnomicon Public
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
- winevt-forensic Public
EVTX forensic library suite — carve records from corrupt files, detect tampering indicators, analyze ETW sessions. No runtime deps.
- 4n6mount Public
Mount forensic disk images, archives & memory dumps as a filesystem on Linux/macOS/Windows — ext4/NTFS/exFAT/HFS+/APFS/ISO, EWF/VMDK/AFF4, AD1, zip/7z/tar, LiME/AVML/crash dumps. FUSE + Dokan, ro/rw COW overlay, deleted-file browsing, NSRL filtering. Pure Rust, Apache-2.0.
- forensic-vfs-engine Public
The forensic-vfs registry + resolver — one Vfs::open(path) that detects the container/volume/filesystem stack and mounts a read-only dyn FileSystem. Batteries-included: every fleet reader compiled in.
- disk-forensic Public
Forensic disk-image orchestrator — decodes E01/VMDK/VHDX/VHD/QCOW2/DMG containers, auto-detects MBR/GPT/APM, and routes ISO 9660 to filesystem analysis
- vsc-forensic Public
Windows Volume Shadow Copy forensic library — reads VSS store/catalog structures, enumerates shadow copies, reconstructs each snapshot's point-in-time volume view (copy-on-write read-back), and grades deletion/timeline anomalies as forensicnomicon findings. Panic-free, fuzzed, Tier-1 validated against libvshadow.
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…