Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- vhd-forensic Public
Legacy VHD (Virtual PC) disk-image forensic reader — pure-Rust, read-only, no runtime deps.
- forensic-vfs Public
Read-only forensic VFS contracts composing evidence into one positioned-read byte edge — ArchiveOpen · ContainerOpen · VolumeSystemOpen · EncryptionOpen · FileSystemOpen — with recursive PathSpec locators. The contract crate every fleet reader implements.
- sqlite-forensic Public
Read-only SQLite forensic toolkit: carve deleted records (freelist/in-page/dropped-table/WAL/journal), read index b-trees & WITHOUT ROWID tables, WAL version history, anti-forensic + encryption-scheme diagnostics, BLOB typing/SHA-256/decode, CASE/UCO export. Panic-free, forbid-unsafe, validated vs undark/fqlite. CLI + Rust libs + Python.
- winreg-forensic Public
Windows Registry hive forensics — panic-free reader, artifact decoders, carving & recovery (SecurityRonin fleet)
- memory-forensic Public
Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.
- leveldb-forensic Public
Read-only forensic LevelDB reader + Chrome Local/Session Storage decoder (recovers deleted records)
- ronin-issen Public
The SecurityRonin forensic fleet — 86 pure-Rust DFIR libraries fronted by Issen: point it at a disk image + memory dump, get one correlated ATT&CK-mapped timeline. Governance, ADRs, and the component map.
- winevt-forensic Public
EVTX forensic library suite — carve records from corrupt files, detect tampering indicators, analyze ETW sessions. No runtime deps.
- srum-forensic Public
SRUM forensics: prove whether a human was at the keyboard. Parse SRUDB.dat on Linux/macOS. Detect malware, exfiltration, and automated execution. Single static Rust binary.
- xfs-forensic Public
XFS forensic library — parse XFS (superblock, AG headers, inodes, bmbt extents, directories), detect integrity anomalies, carve deleted inodes. Pure-Rust, panic-free, fuzzed, Tier-1 (dfvfs).
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…