puffyCid's Stars
Jmcleodfoss/pstreader
Java library for reading Microsoft Outlook pst and ost files
lief-project/LIEF
LIEF - Library to Instrument Executable Formats (C++, Python, Rust)
ForensicRS/frnsc-prefetch
Pure rust windows prefetch parser implementation
AndrewRathbun/DFIRArtifactMuseum
The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact validation processes as well as increase access to artifacts that may no longer be readily available anymore.
rust-unofficial/awesome-rust
A curated list of Rust code and resources.
Velocidex/velociraptor
Digging Deeper....
jamf/aftermath
Aftermath is a free macOS IR framework
hack-different/apple-knowledge
A collection of reverse engineered Apple things, as well as a machine-readable database of Apple hardware
its-a-feature/Mythic
A collaborative, multi-platform, red teaming framework
ForensicArtifacts/artifacts
Digital Forensics artifact repository
Cisco-Talos/clamav
ClamAV - Documentation is here: https://docs.clamav.net
sleuthkit/sleuthkit
The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
osquery/osquery
SQL powered operating system instrumentation, monitoring, and analytics.
sleuthkit/autopsy
Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.
MobSF/Mobile-Security-Framework-MobSF
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
google/grr
GRR Rapid Response: remote live forensics for incident response
frida/frida
Clone this repo to build Frida
radareorg/radare2
UNIX-like reverse engineering framework and command-line toolset