Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- forensic-vfs-engine Public
The forensic-vfs registry + resolver — one Vfs::open(path) that detects the container/volume/filesystem stack and mounts a read-only dyn FileSystem. Batteries-included: every fleet reader compiled in.
- udf-forensic Public
Forensic-grade UDF (ECMA-167/OSTA) reader — volume recognition, partition maps, File Entry/FID traversal, file data
- archive-forensic Public
- iso9660-forensic Public
Forensic ISO 9660 reader & tamper analyzer in pure Rust — analyse() surfaces 23 anomaly findings (redundancy, slack, EDC/ECC, concealment) across multi-session, Rock Ridge, Joliet, El Torito & raw CD images
- ext4fs-forensic Public
Forensic-grade ext4 filesystem parser — pure safe Rust, MIT licensed. Deleted file recovery, journal parsing, timeline generation, slack space analysis, and more.
- forensic-vfs Public
Read-only forensic VFS contracts composing evidence into one positioned-read byte edge — ArchiveOpen · ContainerOpen · VolumeSystemOpen · EncryptionOpen · FileSystemOpen — with recursive PathSpec locators. The contract crate every fleet reader implements.
- fat-forensic Public
FAT/exFAT forensic library — parse FAT12/16/32 and exFAT filesystems, detect boot-sector/FAT-mirror anomalies, carve deleted entries. Single static binary, no runtime deps.
- luks-forensic Public
LUKS forensic library — parse LUKS1/LUKS2 headers, derive the master key, and decrypt the payload. Panic-free, no unsafe, cryptsetup-validated.
- filevault-forensic Public
Apple FileVault 2 / CoreStorage (FVDE) forensic library — parse the encryption context, unlock via password, decrypt AES-XTS volumes, and grade protector/encryption-state/weak-KDF findings. Panic-free, validated byte-for-byte against libfvde.
- bitlocker-forensic Public
BitLocker Drive Encryption (BDE) forensic library — parse FVE metadata, unlock via password, decrypt AES-CBC+Elephant-Diffuser volumes, and grade key-protector/clear-key/weak-cipher findings. Panic-free, validated byte-for-byte against libbde.
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…