Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- archive-forensic Public
- apfs-forensic Public
Apple File System (APFS) forensic library — from-scratch pure-Rust reader (apfs-core) + anomaly analyzer (apfs-forensic) for container, volume, snapshot, encryption and sealed-volume structures. Panic-free, no runtime deps. Design + scaffold; implementation in progress.
- exec-pe-forensic Public
PE (Windows executable) forensic analyzer — pe-core parses PE32/PE64 headers (sections, imports, entropy); pe-analysis grades MITRE-tagged anomalies (suspicious imports, packing/entropy, process-injection IOCs)
- wire-desktop-forensic Public
Wire desktop forensic parser — recover conversations/records from IndexedDB; encrypted values surfaced not fabricated. Panic-free by lint.
- veracrypt-forensic Public
VeraCrypt/TrueCrypt forensic library — brute the header PRF+cipher from a password, recover the master key, and decrypt the volume (AES/Serpent/Twofish, 5 PRFs, hidden volumes). Panic-free, no unsafe.
- btrfs-forensic Public
Btrfs forensic library — parse superblock/chunk-tree/fs-tree/extents, detect integrity anomalies, carve deleted files via CoW backup roots. Pure-Rust, panic-free, fuzzed, Tier-1-validated.
- forensic-vfs-engine Public
The forensic-vfs registry + resolver — one Vfs::open(path) that detects the container/volume/filesystem stack and mounts a read-only dyn FileSystem. Batteries-included: every fleet reader compiled in.
- hfsplus-forensic Public
Forensic-grade Apple HFS+/HFSX reader — volume header, catalog B-tree directory listing, and data-fork file extraction
- livedisk-forensic Public
Cross-platform live block-device enumeration (macOS/Linux/Windows) with partition-layout rendering and acquisition-integrity forensics — fleet *-core/*-forensic split
- vhdx-forensic Public
Pure-Rust VHDX (Hyper-V) virtual-disk reader and forensic integrity analyzer: a hardened Read+Seek container reader (vhdx-core) plus a 63-code tamper/anomaly auditor with in-memory repair (vhdx-forensic) for DFIR.
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…