Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- blazehash Public
Forensic file hasher — BLAKE3 at 1,640 MB/s, 25 hash algorithms, Ed25519 + post-quantum signing, Bitcoin timestamps, YARA scanning, 50+ remote backends. hashdeep for the modern era.
- qcow2-forensic Public
Pure-Rust QCOW2 forensics: reader (qcow2-core) + anomaly auditor (qcow2-forensic) — backing files, snapshots, encryption, refcount orphans on the forensicnomicon report model
- state-history-forensic Public
State-history forensic vocabulary — zero-dependency [H] KNOWLEDGE-tier types and traits lifting each forensic navigation primitive to a time-indexed variant. No deps, no I/O.
- winevt-forensic Public
EVTX forensic library suite — carve records from corrupt files, detect tampering indicators, analyze ETW sessions. No runtime deps.
- blob-decoder Public
Scored identify + decode of unknown forensic BLOBs (bplist/base64/hex/uuid/gzip/zlib/snappy), with recursive unwrap
- docx-mcp Public
MCP server for reading and editing Word (.docx) documents with track changes, comments, footnotes, and structural validation
- shellitem Public
Windows Shell Item / ITEMIDLIST (PIDL) parser — decode .lnk LinkTargetIDList and registry ShellBags into typed items + a reconstructed path. A reusable forensic primitive. Pure Rust.
- vmdk-forensic Public
Pure-Rust VMware VMDK toolkit: vmdk-core reader (imported as vmdk; recovers damaged disks via the redundant grain directory) + vmdk-forensic analyzer (RGD adjudication, dangling-pointer & provenance findings)
- vhdx-forensic Public
Pure-Rust VHDX (Hyper-V) virtual-disk reader and forensic integrity analyzer: a hardened Read+Seek container reader (vhdx-core) plus a 63-code tamper/anomaly auditor with in-memory repair (vhdx-forensic) for DFIR.
- dmg-forensic Public
Apple Disk Image (DMG/UDIF) forensic library — read UDIF + sparse/sparsebundle images, audit koly-trailer integrity as graded findings. Pure Rust, no C deps.
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…