Change the repository type filter
All
Repositories list
121 repositories
memory-forensic
PublicWalk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.peira
Publicforensicnomicon
PublicDFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offli…ewf-forensic
PublicForensic integrity analysis and repair for EWF (Expert Witness Format / E01) imagesusb-forensic
PublicUSB device-history correlation engine — reconstructs USB connection history from every Windows artifact (registry, SetupAPI, event logs, LNK) plus macOS/Linux, …state-history-forensic
PublicState-history forensic vocabulary — zero-dependency [H] KNOWLEDGE-tier types and traits lifting each forensic navigation primitive to a time-indexed variant. No…udf-forensic
Publicshellitem
PublicWindows Shell Item / ITEMIDLIST (PIDL) parser — decode .lnk LinkTargetIDList and registry ShellBags into typed items + a reconstructed path. A reusable forensic…lzo
PublicGPL-free, safe, no_std pure-Rust LZO1X decompressor — decode lzo1x_1 / lzo1x_999 streams (lzop, kernel/initramfs, btrfs, liblzo2) with zero C, zero dependencies…safe-decode
Publiclzvn
Publicjsonguard
PublicSecure output sanitization and input inspection for JSON/JSONL, CSV, and TSV — guards against formula injection, bidi-override, control-character, and encoding …hfsplus-forensic
Publicforensic-vfs-mount
Publicforensic-hashdb
PublicFile hash databases for digital forensics — NSRL/CIRCL known-good, malware known-bad, known-vulnerable Windows drivers (loldrivers), and analyst-supplied MD5/SH…forensic-carve
PublicFleet carving contract + single-pass sweep engine: signature detection over unallocated/memory regions dispatched to per-format carvers.elephant-diffuser
PublicThe BitLocker Elephant Diffuser (Diffuser A + Diffuser B + sector-key XOR) in pure Rust — the format primitive with no ecosystem crate, validated in-situ agains…wire-desktop-forensic
PublicWire desktop forensic parser — recover conversations/records from IndexedDB; encrypted values surfaced not fabricated. Panic-free by lint.veracrypt-forensic
PublicVeraCrypt/TrueCrypt forensic library — brute the header PRF+cipher from a password, recover the master key, and decrypt the volume (AES/Serpent/Twofish, 5 PRFs,…disk-forensic
Publiczip-forensic
Publiczfs-forensic
Publicxfs-forensic
Publicvsc-forensic
PublicWindows Volume Shadow Copy forensic library — reads VSS store/catalog structures, enumerates shadow copies, reconstructs each snapshot's point-in-time volume vi…vmdk-forensic
PublicPure-Rust VMware VMDK toolkit: vmdk-core reader (imported as vmdk; recovers damaged disks via the redundant grain directory) + vmdk-forensic analyzer (RGD adjud…vhd-forensic
Publicufs-forensic
Publiccfb-forensic
PublicOLE/CFB ([MS-CFB]) forensic analyzer — carves compound files for orphaned (deleted) directory entries, free-sector + slack residue, and structural tamper tells.…blob-decoder
Public4n6mount
PublicMount forensic disk images, archives & memory dumps as a filesystem on Linux/macOS/Windows — ext4/NTFS/exFAT/HFS+/APFS/ISO, EWF/VMDK/AFF4, AD1, zip/7z/tar, LiME…
ProTip! When viewing an organization's repositories, you can use the
props. filter to filter by custom property.