Change the repository type filter
All
Repositories list
105 repositories
homebrew-tap
Publicissen
PublicPoint it at disk + memory evidence; get a correlated, ATT&CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps…nameback
PublicGive meaningful names to recovered files (normally only got placeholder names), based on their embedded metadata and/or contents extracted using OCRforensicnomicon
PublicDFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offli…winreg-forensic
Publicsqlite-forensic
PublicRead-only SQLite forensic toolkit: carve deleted records (freelist/in-page/dropped-table/WAL/journal), read index b-trees & WITHOUT ROWID tables, WAL version hi…usb-forensic
PublicUSB device-history correlation engine — reconstructs USB connection history from every Windows artifact (registry, SetupAPI, event logs, LNK) plus macOS/Linux, …winevt-forensic
PublicEVTX forensic library suite — carve records from corrupt files, detect tampering indicators, analyze ETW sessions. No runtime deps.memory-forensic
PublicWalk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.ewf-forensic
PublicForensic integrity analysis and repair for EWF (Expert Witness Format / E01) imagesblazehash
PublicForensic file hasher — BLAKE3 at 1,640 MB/s, 25 hash algorithms, Ed25519 + post-quantum signing, Bitcoin timestamps, YARA scanning, 50+ remote backends. hashdee…disk-forensic
Publiciso9660-forensic
PublicForensic ISO 9660 reader & tamper analyzer in pure Rust — analyse() surfaces 23 anomaly findings (redundancy, slack, EDC/ECC, concealment) across multi-session,…forensic-vfs
PublicRead-only forensic VFS contracts composing evidence into one positioned-read byte edge — ArchiveOpen · ContainerOpen · VolumeSystemOpen · EncryptionOpen · FileS…forensic-vfs-engine
PublicThe forensic-vfs registry + resolver — one Vfs::open(path) that detects the container/volume/filesystem stack and mounts a read-only dyn FileSystem. Batteries-i…udf-forensic
Publicarchive-forensic
Publicext4fs-forensic
PublicForensic-grade ext4 filesystem parser — pure safe Rust, MIT licensed. Deleted file recovery, journal parsing, timeline generation, slack space analysis, and mor…fat-forensic
Publicluks-forensic
PublicLUKS forensic library — parse LUKS1/LUKS2 headers, derive the master key, and decrypt the payload. Panic-free, no unsafe, cryptsetup-validated.filevault-forensic
PublicApple FileVault 2 / CoreStorage (FVDE) forensic library — parse the encryption context, unlock via password, decrypt AES-XTS volumes, and grade protector/encryp…bitlocker-forensic
PublicBitLocker Drive Encryption (BDE) forensic library — parse FVE metadata, unlock via password, decrypt AES-CBC+Elephant-Diffuser volumes, and grade key-protector/…veracrypt-forensic
PublicVeraCrypt/TrueCrypt forensic library — brute the header PRF+cipher from a password, recover the master key, and decrypt the volume (AES/Serpent/Twofish, 5 PRFs,…xfs-forensic
Publictimeglyph
PublicDecode, identify & encode forensic timestamps — every reading ranked, scored, and cited — plus a forensic calendar (DST, leap seconds, GPS week, format epochs, …apfs-forensic
PublicApple File System (APFS) forensic library — from-scratch pure-Rust reader (apfs-core) + anomaly analyzer (apfs-forensic) for container, volume, snapshot, encryp…ntfs-forensic
PublicFrom-scratch NTFS reader (ntfs-core: MFT, attributes, indexes, data runs, LZNT1, $UsnJrnl:$J change journal over Read+Seek) plus a graded anomaly auditor (ntfs-…btrfs-forensic
Publicufs-forensic
Public
ProTip! When viewing an organization's repositories, you can use the
props. filter to filter by custom property.