Repositories list
123 repositories
forensicnomicon
PublicDFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offli…chat4n6
PublicForensic extraction for WhatsApp, Signal, and Telegram — 8-layer SQLite recovery, anti-forensics detection, court-ready reports.homebrew-tap
Publicpeira
Publictimeglyph
PublicDecode, identify & encode forensic timestamps — every reading ranked, scored, and cited — plus a timezone/DST/leap-aware reference calendar for interpreting the…ios-backup-forensic
PublicNative, read-only, panic-free reader and anomaly auditor for iOS device backups (Finder / iTunes / MobileSync), including encrypted backups.ronin-issen
PublicThe SecurityRonin forensic fleet — 86 pure-Rust DFIR libraries fronted by Issen: point it at a disk image + memory dump, get one correlated ATT&CK-mapped timeli…btrfs-forensic
Publicntfs-forensic
PublicFrom-scratch NTFS reader (ntfs-core: MFT, attributes, indexes, data runs, LZNT1, $UsnJrnl:$J change journal over Read+Seek) plus a graded anomaly auditor (ntfs-…shellitem
PublicWindows Shell Item / ITEMIDLIST (PIDL) parser — decode .lnk LinkTargetIDList and registry ShellBags into typed items + a reconstructed path. A reusable forensic…4n6mount
PublicMount forensic disk images, archives & memory dumps as a filesystem on Linux/macOS/Windows — ext4/NTFS/exFAT/HFS+/APFS/ISO, EWF/VMDK/AFF4, AD1, zip/7z/tar, LiME…journald-forensic
PublicFrom-scratch systemd journal (.journal) forensic reader — parse entries without journalctl/systemd, carve from unallocated space, and flag tampering (sequence g…discord-desktop-forensic
PublicDiscord desktop forensic parser — recover account/token/cached channels+messages from Chromium LevelDB. Token redacted by default. Panic-free by lint.sqlite-forensic
PublicRead-only SQLite forensic toolkit: carve deleted records (freelist/in-page/dropped-table/WAL/journal), read index b-trees & WITHOUT ROWID tables, WAL version hi…- Chromium storage forensic readers — decode Simple Cache, IndexedDB-over-LevelDB (V8/Blink values), and Local Storage from Chromium profiles. Panic-free by lint,…
state-history-forensic
PublicState-history forensic vocabulary — zero-dependency [H] KNOWLEDGE-tier types and traits lifting each forensic navigation primitive to a time-indexed variant. No…forensic-vfs-mount
Publicexec-pe-forensic
PublicPE (Windows executable) forensic analyzer — pe-core parses PE32/PE64 headers (sections, imports, entropy); pe-analysis grades MITRE-tagged anomalies (suspicious…ewf-forensic
PublicForensic integrity analysis and repair for EWF (Expert Witness Format / E01) imagesiso9660-forensic
PublicForensic ISO 9660 reader & tamper analyzer in pure Rust — analyse() surfaces 23 anomaly findings (redundancy, slack, EDC/ECC, concealment) across multi-session,…apfs-forensic
PublicApple File System (APFS) forensic library — from-scratch pure-Rust reader (apfs-core) + anomaly analyzer (apfs-forensic) for container, volume, snapshot, encryp…forensic-vfs
PublicRead-only forensic VFS contracts composing evidence into one positioned-read byte edge — ArchiveOpen · ContainerOpen · VolumeSystemOpen · EncryptionOpen · FileS…zfs-forensic
Publicufs-forensic
Publicudf-forensic
Publicxfs-forensic
Publicext4fs-forensic
PublicForensic-grade ext4 filesystem parser — pure safe Rust, MIT licensed. Deleted file recovery, journal parsing, timeline generation, slack space analysis, and mor…hfsplus-forensic
Publiccryptlab
Publicbrowser-forensic
PublicParse Chrome/Firefox/Safari and embedded-Chromium app artifacts — history, cookies, web storage, integrity/tampering, free-page carving, container discovery — i…
ProTip! When viewing an organization's repositories, you can use the
props. filter to filter by custom property.