#dfir

  1. dfir-toolkit

    CLI tools for digital forensics and incident response

    v0.12.3 1.5K #digital-forensics #incident-response #dfir #toolkit #format
  2. flow-record

    create records to be used by the rdump cli utility

    v0.4.10 650 #record #rdump #dfir #header #descriptor #messagepack #32-bit
  3. dfir_lang

    Hydro's Dataflow Intermediate Representation (DFIR) implementation

    v0.15.0 420 #dfir #intermediate-representation #hydro #dataflow #construct #ide #distributed-systems #hf
  4. geoipsed

    Inline decoration of IPv4 and IPv6 address geolocations

    v0.3.0 #ip-geolocation #dfir #geo-ip
  5. masstin

    Lateral movement tracker for anything! A DFIR tool that parses forensic artifacts and visualizes lateral movement in graph databases. Written by Toño Díaz (@jupyterjones)

    v0.10.0 #graph-database #csv #forensics #memgraph #artifact #dfir #lateral #neo4j #evtx #windows-event
  6. vshadow

    Pure Rust parser for Windows Volume Shadow Copy (VSS) snapshots. Read-only access to VSS stores from forensic disk images without Windows APIs.

    v0.2.0 #forensics #vss #ntfs #dfir #shadow-copy
  7. blazehash

    Forensic file hasher — hashdeep for the modern era, BLAKE3 by default

    v0.2.2 #blake3 #hashdeep #dfir #forensics #hash
  8. hydroflow_cli_integration

    hydro_cli integration for Hydroflow

    v0.5.2 430 #dataflow #hydroflow #stream-processing #service #hydro #intermediate-representation #memory-safety #dfir #distributed #ide
  9. oxiddd

    High-performance forensic disk imaging tool with verified NTP timestamping and binding hashes

    v0.2.0 #forensics #disk-image #dd #dfir #security
  10. hydroflow_deploy_integration

    hydro_deploy integration for Hydroflow

    v0.12.0 320 #framework #hydroflow #dataflow #run-time #hydro-deploy #distributed #intermediate-representation #distributed-systems #memory-safety #dfir
  11. bitgrep

    Binary grep for numerical data types

    v0.1.5 #grep #dfir #security #forensics
  12. hydroflow_datalog_core

    Datalog implementation for Hydroflow

    v0.10.0 950 #hydroflow #logic-programming #datalog #dataflow #hydro #stream-processing #intermediate-representation #memory-safety #dfir #distributed
  13. Try searching with DuckDuckGo.

  14. jumplist_parser

    parse Windows Jumplist files (automaticDestinations-ms and customDestinations-ms)

    v0.1.0 #jump-list #forensics #windows #dfir #artifact #jumplist
  15. dfir_macro

    Macro for using Hydro's Data Flow Intermediate Representation (DFIR)

    v0.15.0 290 #hydro #intermediate-representation #dataflow #dfir #framework #distributed #distributed-systems
  16. notepad_parser

    Notepad TabState file parser

    v0.1.0 #notepad #dfir #windows #forensics #artifact
  17. dfir_datalog

    Datalog proc-macro for DFIR

    v0.13.0 260 #dfir #datalog #hydro #framework #distributed #proc-macro #distributed-systems #intermediate-representation #stream-processing #dataflow
  18. dfir_datalog_core

    Datalog implementation for DFIR

    v0.13.0 #dfir #dataflow #framework #distributed #datalog #distributed-systems #hydro #stream-processing #intermediate-representation #memory-safety
  19. hydroflow_datalog

    Datalog proc-macro for Hydroflow

    v0.10.0 140 #hydroflow #datalog #proc-macro #hydro #distributed #intermediate-representation #stream-processing #dataflow #memory-safety #dfir
  20. hydro_build_utils

    build and test utils for hydro

    v0.0.1 #hydro #framework #distributed #correct #distributed-systems #intermediate-representation #stream-processing #dataflow #memory-safety #dfir