-
dfir-toolkit
CLI tools for digital forensics and incident response
-
flow-record
create records to be used by the rdump cli utility
-
dfir_lang
Hydro's Dataflow Intermediate Representation (DFIR) implementation
-
geoipsed
Inline decoration of IPv4 and IPv6 address geolocations
-
masstin
Lateral movement tracker for anything! A DFIR tool that parses forensic artifacts and visualizes lateral movement in graph databases. Written by Toño Díaz (@jupyterjones)
-
vshadow
Pure Rust parser for Windows Volume Shadow Copy (VSS) snapshots. Read-only access to VSS stores from forensic disk images without Windows APIs.
-
blazehash
Forensic file hasher — hashdeep for the modern era, BLAKE3 by default
-
hydroflow_cli_integration
hydro_cliintegration for Hydroflow -
oxiddd
High-performance forensic disk imaging tool with verified NTP timestamping and binding hashes
-
hydroflow_deploy_integration
hydro_deployintegration for Hydroflow -
bitgrep
Binary grep for numerical data types
-
hydroflow_datalog_core
Datalog implementation for Hydroflow
-
jumplist_parser
parse Windows Jumplist files (automaticDestinations-ms and customDestinations-ms)
-
dfir_macro
Macro for using Hydro's Data Flow Intermediate Representation (DFIR)
-
notepad_parser
Notepad TabState file parser
-
dfir_datalog
Datalog proc-macro for DFIR
-
dfir_datalog_core
Datalog implementation for DFIR
-
hydroflow_datalog
Datalog proc-macro for Hydroflow
-
hydro_build_utils
build and test utils for hydro
Try searching with DuckDuckGo.