#forensics (30 Repositories)
Ranked open-source repositories tagged with #forensics, scored by pull request acceptance likelihood and maintainer engagement velocity.
26.2%
9.7h
30 repositories tagged #forensics
Yamato-Security/suzaku
Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.
mvt-project/androidqf
androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of compromise.
BARGHEST-ngo/MESH
Wireless ADB, over the internet; not just local Wi-Fi. An encrypted, censorship-resistant mesh VPN making remote forensics and network monitoring seamless.
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
trailofbits/mquire
Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.
WerWolv/ImHex
🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
mandiant/macos-UnifiedLogs
A cross platform parser for Apple UnifiedLogs!
sleuthkit/sleuthkit
The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
Am0rphous/Awesome
Awesome collection of resources 😎 Work in progress🔥
tclahr/uac
UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.
RyanDFIR/hindsight
Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox
EricZimmerman/MFTECmd
Parses $MFT from NTFS file systems
rafael-santiago/pig
A Linux packet crafting tool.
google/turbinia
Automation and Scaling of Digital Forensics Tools
cgosec/Blauhaunt
A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts
botherder/androidqf
androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of compromise.
AnonCatalyst/Ominis-OSINT
This Python application is an OSINT (Open Source Intelligence) tool called "Ominis OSINT - Web Hunter." It performs online information gathering by querying Google for search results related to a user-inputted query. The tool extracts relevant information such as titles, URLs, and potential mentions of the query in the results.
ANSSI-FR/DFIR-O365RC
PowerShell module for Office 365 and Azure log collection
frankwxu/digital-forensics-lab
Free hands-on digital forensics labs for students and faculty
mozillazg/ptcpdump
Process-aware, eBPF-based tcpdump
AnonCatalyst/Coeus-OSINT-ToolBox
Coeus 🌐 is an OSINT ToolBox empowering users with tools for effective intelligence gathering from open sources. From social media monitoring 📱 to data analysis 📊, it offers a centralized platform for seamless OSINT investigations.
bb1nfosec/Information-Security-Tasks
This repository is created only for infosec professionals whom work day to day basis to equip ourself with uptodate skillset, We can daily contribute daily one hour for day to day tasks and work on problem statements daily, Please contribute by providing problem statements and solutions
teamdfir/sift-saltstack
Salt States for Configuring the SIFT Workstation
BSI-Bund/RdpCacheStitcher
RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
pandaadir05/ghost
Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process hollowing. Built in Rust for speed. Includes CLI and TUI interfaces.
ChmaraX/forensix
Google Chrome forensic tool to process, analyze and visualize browsing artifacts
ShaneK2/inVtero.net
inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques
JPCERTCC/MalConfScan
Volatility plugin for extracts configuration data of known malware
Gregwar/fatcat
FAT filesystems explore, extract, repair, and forensic tool
wanshuiyin/Anti-Autoresearch
Don't trust an autoresearch paper at face value. Reviewer-side integrity forensics (self-consistency + fabrication), deterministic verdict. 61 signals: 46 integrity hack-patterns (families A–H, verdict-bearing) + 13 zero-weight AI writing-style impressions (AIS) + 2 advisory. Not an opaque AI-text classifier. The dual of ARIS.