Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- timeglyph Public
Decode, identify & encode forensic timestamps — every reading ranked, scored, and cited — plus a forensic calendar (DST, leap seconds, GPS week, format epochs, moon phase). Rust CLI + library, WASM playground, and a live hover-to-decode overlay.
- memory-forensic Public
Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.
- disk-forensic Public
Forensic disk-image orchestrator — decodes E01/VMDK/VHDX/VHD/QCOW2/DMG containers, auto-detects MBR/GPT/APM, and routes ISO 9660 to filesystem analysis
- sqlite-forensic Public
Read-only SQLite forensic toolkit: carve deleted records (freelist/in-page/dropped-table/WAL/journal), read index b-trees & WITHOUT ROWID tables, WAL version history, anti-forensic + encryption-scheme diagnostics, BLOB typing/SHA-256/decode, CASE/UCO export. Panic-free, forbid-unsafe, validated vs undark/fqlite. CLI + Rust libs + Python.
- useract-forensic Public
User-activity forensics — unify shell history, peripheral connections (and v0.2: LNK/shellbags/SRUM/UserAssist/MRU) into one per-user timeline with cross-source correlation. Pure Rust meta-analyzer.
- snss-forensic Public
Chromium/Brave/Edge SNSS session-file forensic decoder — panic-free, read-only; validates the SNSS command stream, decodes navigation base::Pickle payloads, replays per-window tab state. No runtime deps.
- git-forensic Public
Git forensic library suite — read loose + packfile objects from any .git, detect backdated commits, rewritten history, unsigned commits, and unreachable objects. Pure Rust, no libgit2.
- segb-forensic Public
Apple SEGB (Biome) forensic analyzer + reader — decode SEGB v1/v2 records and flag CRC-mismatch, deletion-residue, and timestamp-order anomalies as graded findings. Panic-free, no unsafe.
- usb-forensic Public
USB device-history correlation engine — reconstructs USB connection history from every Windows artifact (registry, SetupAPI, event logs, LNK) plus macOS/Linux, and scores cross-source timestamp consistency by tamper-independence. Runs headless on any OS; pipeline-native JSONL, reproducible, panic-free.
- prefetch-forensic Public
Windows Prefetch forensic library — parse MAM/Xpress-Huffman + SCCA v30/31 (run count, last-8 run times, loaded files), grade masquerade & suspicious-location execution. Cross-platform, panic-free, no Windows API.
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…