-
fse_dump
Dumps the fseventsd entries from a mac
-
yara-x
A pure Rust implementation of YARA
-
ntdsextract2
Display contents of Active Directory database files (ntds.dit)
-
malwaredb
Service for storing malicious, benign, or unknown files and related metadata and relationships
-
mquire
Memory forensics and analysis tool for querying Linux kernel memory dumps using SQL
-
innodb-utils
InnoDB file analysis toolkit
-
forensic-rs
A Rust-based framework to build tools that analyze forensic artifacts and can be reused as libraries across multiple projects without changing anything
-
macos-unifiedlogs
help parse macOS UnifiedLogs
-
memprocfs
Physical Memory Analysis Framework
-
dionysos
Scanner for various IoCs
-
zff
interact with zff, a file format for forensic images
-
palisade-errors
Security-conscious error handling with operational security principles
-
nt_hive2
forensic parser library for Windows registry hive files
-
usnjrnl-forensic
NTFS USN Journal parser with full path reconstruction via journal rewind
-
ewf
Pure Rust reader for Expert Witness Format (E01/EWF) forensic disk images
-
zffacquire
A command line utility for acquiring data into the forensic format Zff
-
lumination
A very basic library to display network connections
-
emdumper
acquire the physical memory on linux systems (root is necessary)
-
archivum
— deterministic, split, checksummed, compressed archive system with faithful restore
-
frnsc-prefetch
Pure rust windows prefetch parser implementation
-
frnsc-hive
Implements RegistryReader from forensic-rs to access the windows registry from Hive files
-
telfhash-rs
Rust 2024 implementation of Trend Micro telfhash for ELF similarity hashing
-
precursor
Pre-protocol payload tagging, similarity clustering, and packet/firmware triage CLI
-
zffmount
A command line utility to mount a zff container using FUSE
-
aicheck
Detect AI-generated content via provenance signals (C2PA, XMP/IPTC, EXIF)
-
chat4n6
CLI for chat4n6: extract WhatsApp forensic artifacts from Android filesystem images
-
oxiddd
High-performance forensic disk imaging tool with verified NTP timestamping and binding hashes
-
sunlight
A very simple Protobuf binary parser
-
blazehash
Forensic file hasher — hashdeep for the modern era, BLAKE3 by default
-
calf
A very basic library to read QCOW files
-
notatin
parsing offline Windows Registry files
-
ext4-fs
A very basic library to read the ext4 filesystem
-
wxtla
Wired eXploring Target Layer Accessor
-
oximedia-forensics
Video and image forensics and tampering detection for OxiMedia
-
boundary-report
Report generators for boundary analysis results
-
certlogview
Analyse contents of the Microsoft AD CS Log file
-
malwaredb-client
Client application and library for connecting to MalwareDB
-
emd-ebpf
contains the eBPF binary for emd
-
malwaredb-types
Data types and parsers for MalwareDB
-
regf
parsing, manipulating, and writing Windows Registry hive files (regf format)
-
threatflux-string-analysis
Advanced string analysis and categorization library for security applications
-
lemmeknow
Identify any mysterious text or analyze strings from a file
-
malwaredb-server
Server data storage logic for MalwareDB
-
evtxtools
tools for the analysis of evtx files
-
malwaredb-client-py
Python client for MalwareDB
-
dma-rs
hardware DMA interaction on Windows
-
malwaredb-api
Common API endpoints and data types for MalwareDB components
-
carbon14
file-system forensics
-
rustkernel-behavioral
RustKernels Behavioral domain kernels
-
emd-common
Various common stuff, necessary for emd
-
nullsec-spoof
High-performance metadata spoofing toolkit for anti-forensics - Randomize timestamps, MAC addresses, EXIF data, and file attributes
-
frnsc-liveregistry-rs
Implements RegistryReader from forensic-rs using the Windows API to access the registry of a live system
-
bitgrep
Binary grep for numerical data types
-
vex-verify
Lightweight cryptographic verification engine for the VEX protocol
-
jumplist_parser
parse Windows Jumplist files (automaticDestinations-ms and customDestinations-ms)
-
notepad_parser
Notepad TabState file parser
-
chat4n6-report
HTML report generator for chat4n6 forensic extraction results
-
chat4n6-sqlite-forensics
Zero-copy SQLite forensics library: B-tree walker, WAL parser, and FTS recovery
-
libprefetch
Forensic library; parser and reader for Microsoft Prefetch File
-
archlinux-userland-fs-cmp
Forensic tool to read all installed packages from a mounted Arch Linux drive and compare the filesystem to a trusted source
-
chat4n6-plugin-api
Shared plugin API types for the chat4n6 forensic toolkit
-
boundary-core
Core types, graph structures, and metrics for boundary
-
frnsc-amcache
Pure rust AmCache parser
-
prefetchkit
A powerful forensic commandline tool for analysing Microsoft Prefetch Files
-
zffanalyze
A command line utility to analyze zff files
-
dmalibrary
that makes it easy to work with DMA cards for memory forensics and video game hacking
-
chat4n6-whatsapp
WhatsApp forensic plugin: chat extraction, decryption, and call log recovery
-
lime-rs
Parser for LiME file format based on binrw
-
sams-blackbox
High-performance forensic logger for signed semantic atoms. Provides immutable audit trails for long-term archival and mandatory cybersecurity compliance.
-
reg-analyzer-rs
Forensic library to analyze Registry artifacts using forensic-rs framework
-
velociraptor_api
API client for Velociraptor (https://github.com/Velocidex/velociraptor)
-
chat4n6-core
DAR archive parser and filesystem abstraction for chat4n6
-
thumbsdbkit
forensic command line tool for analyzing and extracting thumbnails from Microsoft Thumbs.db files
-
emd-ebpf-impl
The internal eBPF implementation (for use by emd-ebpf). This implementation is intended to use only with bpfel-unknown-none target
-
zffmetareader
A command line utility to read the metadata of a zff image
-
frnsc-sqlite
Sqlite implementation of SqlDb trait of ForensicRS
-
pol_export
Exporter for Windows Registry Policy Files
-
dfirtk-sessionevent-derive
CLI tools for digital forensics and incident response
Try searching with DuckDuckGo.