CLI tools for forensic investigation of Windows artifacts
-
Updated
Jul 21, 2025 - Rust
CLI tools for forensic investigation of Windows artifacts
Unified digital forensics platform bringing disk, RAM, container drift, logical acquisition, and backup analysis together for Windows, Linux, Docker, Android, and iOS.
Cutting Edge Reverse-Engineering tool & VSCode extension | API call analysis, function discovery, PE-triage
Unified Memory Forensics MCP Server - Multi-tier engine combining Rust speed with Vol3 coverage.
Simple file carver written in Rust, similar to Scalpel
Unprivileged NTFS Alternate Data Stream manager. All in one NTFS-ADS tool!
Как volatility, только на Rust, чтобы было blazingly fast (нет).
Pure-Rust VMware VMDK toolkit: vmdk-core reader (imported as vmdk; recovers damaged disks via the redundant grain directory) + vmdk-forensic analyzer (RGD adjudication, dangling-pointer & provenance findings)
Tool for extracting the text from .doc files
Programmable digital forensics framework for endpoint investigation, evidence integrity, and verification.
Local forensic triage workbench built in Rust for case snapshots, file timelines, hashes, suspicious artifacts and defensive reports.
Pure-Rust VHDX (Hyper-V) virtual-disk reader and forensic integrity analyzer: a hardened Read+Seek container reader (vhdx-core) plus a 63-code tamper/anomaly auditor with in-memory repair (vhdx-forensic) for DFIR.
🦀 Tool for developing memory-safe programs while detecting and capturing possibly malicious bytes.
⛔️ DEPRECATED: Use https://github.com/dfir-dd/dfir-toolkit instead
Forensics tool to scan disk images and live Windows volumes for deleted file recovery.
To associate your repository with the forensic-analysis topic, visit your repo's landing page and select "manage topics."