computer-forensics

There are 39 repositories under computer-forensics topic.

  • cugu/awesome-forensics

    ⭐️ A curated list of awesome forensic analysis tools and resources

  • Srinivas11789/PcapXray

    :snowflake: PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight important communication and file extraction

    Language:Python1.7k7823280
  • tclahr/uac

    UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.

    Language:Shell7972856124
  • xiosec/Computer-forensics

    The best tools and resources for forensic analysis.

  • CIRCL/factual-rules-generator

    Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.

    Language:Python761006
  • op7ic/unix_collector

    unix_collector is a Live Response collection script for Incident Response on UNIX-like systems using native binaries. Supports AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.

    Language:Shell32245
  • jz543fm/kali-dockerized

    Kali Linux in Docker + Ubuntu 22.04 in Docker for Bug Bounty, Penetration Testing, Security Research, Computer Forensics and Reverse Engineering. Kali Linux inside with Docker with or without support with systemd, repository also contains Proof of Concept with kind (Kubernetes in Docker) to test Kali Linux with enabled systemd in K8s cluster

    Language:Dockerfile22205
  • mbrown1413/SqliteFind

    A Volatility plugin for finding sqlite database rows

    Language:Python22314
  • tthtlc/awesome_malware_techniques

    This will compile a list of Android, iOS, Linux malware techniques for attacking and detection purposes.

  • jp-slackspace/x-tension-c-sharp

    An updated C# port of X-Ways X-Tensions API.

    Language:C#12341
  • thomaslaurenson/LiveDiff

    LiveDiff is a portable system-level differencing tool for Microsoft Windows-based operating systems

    Language:C#93234
  • ggulgun/Forensic-Docker

    Docker images of open source forensic tools

    Language:Shell8101
  • ivan-sincek/domain-extractor

    Extract valid or partially valid domain names and IPs from malicious or invalid URLs.

    Language:Python8203
  • sydp/goewf

    Access Expert Witness Format (ewf/E01/L01) files using Golang

    Language:Go8300
  • bolisettynihith/ActivitiesCacheParser

    A python-based tool to extract forensic info from ActivitiesCache.db (Windows Activity Timeline)

    Language:Python5102
  • Pruthviraj-S/Computer-Forensics

    CFREDS case study for subject code: CTMTCS S2 P2

  • TheProGhost/Digital_Forensics_CaseStudy

    The forensic analysis write-up / walkthrough for forensic disk image.

  • 0xmmalik/CTF-Suite

    CTF Suite is a collection of tools you can use during Capture The Flag competitions. These tools are aimed at specific categories of problems and are specific to Jeopardy-style CTFs.

    Language:Python4300
  • ivan-sincek/memory-dumper

    Dump a process memory and extract data based on regular expressions.

    Language:C++4203
  • Caume/CIAT

    Crypto implementations analysis toolkit

    Language:C3200
  • cyberknightX/Guymager

    Guymager is a free forensic imager for media acquisition. It is based on libewf and libguytools.

    Language:C++3101
  • faisouq/forensic-tools

    This repository contains the forensic tools we made.

    Language:Python3100
  • thomaslaurenson/CellXML-Registry

    CellXML-Registry.exe is a portable Windows tool that parses an offline Windows Registry hive file and converts it to the RegXML format. CellXML-Registry leverages the Registry parser project by Eric Zimmerman to aid in parsing the Registry structure.

    Language:C#33132
  • jz543fm/docker-parrot

    Parrot OS (Core/Security) or just Parrot Tools in Docker with the usage of Makefile, Dockerfiles and docker-compose.yaml for Bug Bounty, Penetration Testing, Security Research, Computer Forensics and Reverse Engineering, repository also contains Proof of Concept with kind (K8s in Docker) for ParrotOS with/without systemd in K8s cluster

    Language:Makefile2100
  • computerforensicslab/IPED

    IPED Digital Forensic Tool Ultimate: It is an open source software that can be used to process and analyse digital evidence, often seized at crime scenes by law enforcement or in a corporate investigation by private examiners.

    Language:Java1000
  • cyberknightX/Cyberknight

    The Main Software Repository

  • githubfoam/forensics-experience

    computer forensics

    Language:C112
  • tristan-gy/BMP_HiddenFileFinder

    This program searches .bmp for files hidden using LSB subsitution.

    Language:C++1200
  • yogeshkanwade21/EXIF-Analyser

    A Python script to extract and analyse EXIF data

    Language:Python1201
  • computerforensicslab/AvillaForensics

    Avilla Forensics 3.0: Avilla Forensics is a comprehensive and feature-rich tool for mobile forensics, offering a wide range of functionalities for both Android and iOS devices. The tool’s integration with various third-party tools enhances its capabilities.

    Language:C#0001
  • cyberknightX/dcfldd

    dcfldd is a modified version of GNU dd.

    Language:C0100
  • daniel-radesjo/rdd-copy

    Fork of rdd-copy (https://sourceforge.net/projects/rdd/) developed by NFI (the Netherlands Forensic Institute) and updated to work with new version of libewf.

    Language:C0100
  • FilipIvic/CF_Labs

    College lab tasks for Computer Forensics class & Hack The Box intro

    Language:Python0100
  • idvlecio3silva/Cyber-Tech-Articles

    Repositório que a apresenta os meus artigos sobre tecnologia - Linux, Cibersegurança, Computação Forense e Gestão de Projectos

  • msoto5/cs42_recovery

    Given a range of dates, is capable of extracting various information from a Windows system in said time range

    Language:Python0100
  • gustavonaldoni/bfcpf

    bfcpf stands for "Brute Force CPF" and it is a CLI tool that breaks a partial CPF, finding all valid ones within the pattern given by the user.

    Language:Python10