Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
-
memory-forensic
memory-forensic PublicWalk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.
Repositories
- disk-forensic Public
Forensic disk-image orchestrator — decodes E01/VMDK/VHDX/VHD/QCOW2/DMG containers, auto-detects MBR/GPT/APM, and routes ISO 9660 to filesystem analysis
- forensic-hashdb Public
File hash databases for digital forensics — NSRL/CIRCL known-good, malware known-bad, known-vulnerable Windows drivers (loldrivers), and analyst-supplied MD5/SHA1/SHA256 feeds.
- forensic-vfs Public
Read-only forensic VFS contracts composing evidence into one positioned-read byte edge — ArchiveOpen · ContainerOpen · VolumeSystemOpen · EncryptionOpen · FileSystemOpen — with recursive PathSpec locators. The contract crate every fleet reader implements.
- sqlite-forensic Public
Read-only SQLite forensic toolkit: carve deleted records (freelist/in-page/dropped-table/WAL/journal), read index b-trees & WITHOUT ROWID tables, WAL version history, anti-forensic + encryption-scheme diagnostics, BLOB typing/SHA-256/decode, CASE/UCO export. Panic-free, forbid-unsafe, validated vs undark/fqlite. CLI + Rust libs + Python.
- iso9660-forensic Public
Forensic ISO 9660 reader & tamper analyzer in pure Rust — analyse() surfaces 23 anomaly findings (redundancy, slack, EDC/ECC, concealment) across multi-session, Rock Ridge, Joliet, El Torito & raw CD images
- lzo Public
GPL-free, safe, no_std pure-Rust LZO1X decompressor — decode lzo1x_1 / lzo1x_999 streams (lzop, kernel/initramfs, btrfs, liblzo2) with zero C, zero dependencies, and #![forbid(unsafe_code)]; validated against liblzo2 and fuzz-hardened against malicious input.
- vhd-forensic Public
Legacy VHD (Virtual PC) disk-image forensic reader — pure-Rust, read-only, no runtime deps.
- lzvn Public
Safe, no_std pure-Rust Apple LZVN decompressor — length-tolerant for real macOS decmpfs resource-fork blocks. Published as lzvn-core (lib name lzvn).
- peira Public
A knowledge system that refuses to promote a claim you have not examined — with gates drawn from Socratic elenchus, 金剛經, Nyāya, Madhyamaka and the causal ladder.
- dmg-forensic Public
Apple Disk Image (DMG/UDIF) forensic library — read UDIF + sparse/sparsebundle images, audit koly-trailer integrity as graded findings. Pure Rust, no C deps.
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…