Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- leveldb-forensic Public
Read-only forensic LevelDB reader + Chrome Local/Session Storage decoder (recovers deleted records)
- wire-desktop-forensic Public
Wire desktop forensic parser — recover conversations/records from IndexedDB; encrypted values surfaced not fabricated. Panic-free by lint.
- whatsapp-desktop-forensic Public
WhatsApp Desktop forensic parser — recover chats/messages/contacts/media from IndexedDB (V8). Encrypted bodies fail loud, never fabricated. Panic-free by lint.
- protobuf-forensic Public
Schemaless forensic Protocol Buffers decoder — decode protobuf wire format with no .proto, with field-type heuristics + timeglyph timestamp flagging
- trash-forensic Public
Read-only readers + forensic analyzers for trash / deleted-file artifacts across Windows, Linux, macOS, Android & iOS — recover who deleted what, when, with tampering already graded.
- ronin-issen Public
The SecurityRonin forensic fleet — 86 pure-Rust DFIR libraries fronted by Issen: point it at a disk image + memory dump, get one correlated ATT&CK-mapped timeline. Governance, ADRs, and the component map.
- peira Public
A knowledge system that refuses to promote a claim you have not examined — with gates drawn from Socratic elenchus, 金剛經, Nyāya, Madhyamaka and the causal ladder.
- ios-backup-forensic Public
Native, read-only, panic-free reader and anomaly auditor for iOS device backups (Finder / iTunes / MobileSync), including encrypted backups.
- sqlite-forensic Public
Read-only SQLite forensic toolkit: carve deleted records (freelist/in-page/dropped-table/WAL/journal), read index b-trees & WITHOUT ROWID tables, WAL version history, anti-forensic + encryption-scheme diagnostics, BLOB typing/SHA-256/decode, CASE/UCO export. Panic-free, forbid-unsafe, validated vs undark/fqlite. CLI + Rust libs + Python.
- forensic-vfs Public
Read-only forensic VFS contracts composing evidence into one positioned-read byte edge — ArchiveOpen · ContainerOpen · VolumeSystemOpen · EncryptionOpen · FileSystemOpen — with recursive PathSpec locators. The contract crate every fleet reader implements.
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…