Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- ronin-issen Public
The SecurityRonin forensic fleet — 86 pure-Rust DFIR libraries fronted by Issen: point it at a disk image + memory dump, get one correlated ATT&CK-mapped timeline. Governance, ADRs, and the component map.
- userassist-forensic Public
UserAssist forensic analyzer — decodes Windows GUI execution evidence (NTUSER.DAT) and flags masquerade/staging anomalies. Rust: userassist-core reader + userassist-forensic analyzer/CLI.
- useract-forensic Public
User-activity forensics — unify shell history, peripheral connections (and v0.2: LNK/shellbags/SRUM/UserAssist/MRU) into one per-user timeline with cross-source correlation. Pure Rust meta-analyzer.
- shimcache-forensic Public
Windows AppCompatCache (ShimCache) forensic analyzer — reads the AppCompatCache value from a SYSTEM hive and r
- safe-decode Public
Panic-free, allocating byte-to-value transforms with no format knowledge: ROT13, the UTF-16 decoder family with its NUL policy named in each function, and hex rendering.
- prefetch-forensic Public
Windows Prefetch forensic library — parse MAM/Xpress-Huffman + SCCA v30/31 (run count, last-8 run times, loaded files), grade masquerade & suspicious-location execution. Cross-platform, panic-free, no Windows API.
- ntfs-forensic Public
From-scratch NTFS reader (ntfs-core: MFT, attributes, indexes, data runs, LZNT1, $UsnJrnl:$J change journal over Read+Seek) plus a graded anomaly auditor (ntfs-forensic: timestomping, alternate data streams, deleted records, MFT/LogFile tamper checks) — panic-free, fuzzed, no unsafe
- lnk-forensic Public
Windows Shell Link (.lnk) forensics — parse target path, volume serial, MAC times, tracker machine ID; detect removable-media and network targets. Pure Rust. (JumpLists in v0.2.)
- elephant-diffuser Public
The BitLocker Elephant Diffuser (Diffuser A + Diffuser B + sector-key XOR) in pure Rust — the format primitive with no ecosystem crate, validated in-situ against libbde. no_std, panic-free.
- bam-forensic Public
Background Activity Moderator (BAM/DAM) forensic analyzer — per-user last-execution evidence from the Windows SYSTEM hive. Rust: bam-core reader + bam-forensic analyzer/CLI.
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…