Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- vsc-forensic Public
Windows Volume Shadow Copy forensic library — reads VSS store/catalog structures, enumerates shadow copies, reconstructs each snapshot's point-in-time volume view (copy-on-write read-back), and grades deletion/timeline anomalies as forensicnomicon findings. Panic-free, fuzzed, Tier-1 validated against libvshadow.
- forensic-vfs-engine Public
The forensic-vfs registry + resolver — one Vfs::open(path) that detects the container/volume/filesystem stack and mounts a read-only dyn FileSystem. Batteries-included: every fleet reader compiled in.
- shellhist-forensic Public
Shell command-history forensic library suite — parse bash, zsh, fish, and PowerShell PSReadLine history; detect history clearing, back-dated entries, and download-pipe-to-shell. Pure Rust, no runtime deps.
- peripheral-forensic Public
External-device connection forensics — parse setupapi.dev.log into a typed DeviceConnection timeline across USB, FireWire, Thunderbolt, PCIe, eSATA, SD; classify DMA-capable vs storage vs HID threat. Pure Rust.
- useract-forensic Public
User-activity forensics — unify shell history, peripheral connections (and v0.2: LNK/shellbags/SRUM/UserAssist/MRU) into one per-user timeline with cross-source correlation. Pure Rust meta-analyzer.
- sqlite-forensic Public
Read-only SQLite forensic toolkit: carve deleted records (freelist/in-page/dropped-table/WAL/journal), read index b-trees & WITHOUT ROWID tables, WAL version history, anti-forensic + encryption-scheme diagnostics, BLOB typing/SHA-256/decode, CASE/UCO export. Panic-free, forbid-unsafe, validated vs undark/fqlite. CLI + Rust libs + Python.
- lnk-forensic Public
Windows Shell Link (.lnk) forensics — parse target path, volume serial, MAC times, tracker machine ID; detect removable-media and network targets. Pure Rust. (JumpLists in v0.2.)
- journald-forensic Public
From-scratch systemd journal (.journal) forensic reader — parse entries without journalctl/systemd, carve from unallocated space, and flag tampering (sequence gaps, timestamp regressions, truncation, online-state)
- forensic-vfs-mount Public
- exec-pe-forensic Public
PE (Windows executable) forensic analyzer — pe-core parses PE32/PE64 headers (sections, imports, entropy); pe-analysis grades MITRE-tagged anomalies (suspicious imports, packing/entropy, process-injection IOCs)
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…