Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- peripheral-forensic Public
External-device connection forensics — parse setupapi.dev.log into a typed DeviceConnection timeline across USB, FireWire, Thunderbolt, PCIe, eSATA, SD; classify DMA-capable vs storage vs HID threat. Pure Rust.
- shrinkpath Public
Smart cross-platform path shortening for Rust — target-length guarantee, identity preservation, zero dependencies
- forensic-hashdb Public
File hash databases for digital forensics — NSRL/CIRCL known-good, malware known-bad, known-vulnerable Windows drivers (loldrivers), and analyst-supplied MD5/SHA1/SHA256 feeds.
- xfs-forensic Public
XFS forensic library — parse XFS (superblock, AG headers, inodes, bmbt extents, directories), detect integrity anomalies, carve deleted inodes. Pure-Rust, panic-free, fuzzed, Tier-1 (dfvfs).
- lzvn Public
Safe, no_std pure-Rust Apple LZVN decompressor — length-tolerant for real macOS decmpfs resource-fork blocks. Published as lzvn-core (lib name lzvn).
- blob-decoder Public
Scored identify + decode of unknown forensic BLOBs (bplist/base64/hex/uuid/gzip/zlib/snappy), with recursive unwrap
- lzo Public
GPL-free, safe, no_std pure-Rust LZO1X decompressor — decode lzo1x_1 / lzo1x_999 streams (lzop, kernel/initramfs, btrfs, liblzo2) with zero C, zero dependencies, and #![forbid(unsafe_code)]; validated against liblzo2 and fuzz-hardened against malicious input.
- disk-forensic Public
Forensic disk-image orchestrator — decodes E01/VMDK/VHDX/VHD/QCOW2/DMG containers, auto-detects MBR/GPT/APM, and routes ISO 9660 to filesystem analysis
- git-forensic Public
Git forensic library suite — read loose + packfile objects from any .git, detect backdated commits, rewritten history, unsigned commits, and unreachable objects. Pure Rust, no libgit2.
- usb-forensic Public
USB device-history correlation engine — reconstructs USB connection history from every Windows artifact (registry, SetupAPI, event logs, LNK) plus macOS/Linux, and scores cross-source timestamp consistency by tamper-independence. Runs headless on any OS; pipeline-native JSONL, reproducible, panic-free.
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…