Popular repositories Loading
-
usnjrnl-forensic
usnjrnl-forensic Public archiveThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomp…
Rust 31
Repositories
- forensic-vfs Public
Read-only forensic VFS contracts composing evidence into one positioned-read byte edge — ArchiveOpen · ContainerOpen · VolumeSystemOpen · EncryptionOpen · FileSystemOpen — with recursive PathSpec locators. The contract crate every fleet reader implements.
- timeglyph Public
Decode, identify & encode forensic timestamps — every reading ranked, scored, and cited — plus a timezone/DST/leap-aware reference calendar for interpreting them (DST folds, leap seconds, GPS week, format epochs, moon phase). Rust CLI + library, WASM playground, and a live hover-to-decode overlay.
- fleet-ci Public
Reusable GitHub Actions workflow for the SecurityRonin Rust fleet: fmt, clippy, test, MSRV, coverage, cargo-deny, cargo-vet, secret scan, and fuzz smoke in one callable job set.
- keychain-forensic Public
macOS Keychain forensic library — recover & decrypt login.keychain-db secrets (Chrome Safe Storage keys, generic/internet passwords) via PBKDF2/DES-CBC. Panic-free by lint, single static binary, no runtime deps.
- chromium-safestorage Public
Chromium Safe Storage key recovery — recover the OS-protected AES key encrypting Chromium cookies/passwords/messenger DBs (macOS Keychain, Windows DPAPI, Linux). Panic-free by lint, single static binary.
- xfs-forensic Public
XFS forensic library — parse XFS (superblock, AG headers, inodes, bmbt extents, directories), detect integrity anomalies, carve deleted inodes. Pure-Rust, panic-free, fuzzed, Tier-1 (dfvfs).
- vmdk-forensic Public
Pure-Rust VMware VMDK toolkit: vmdk-core reader (imported as vmdk; recovers damaged disks via the redundant grain directory) + vmdk-forensic analyzer (RGD adjudication, dangling-pointer & provenance findings)
- vhdx-forensic Public
Pure-Rust VHDX (Hyper-V) virtual-disk reader and forensic integrity analyzer: a hardened Read+Seek container reader (vhdx-core) plus a 63-code tamper/anomaly auditor with in-memory repair (vhdx-forensic) for DFIR.
- forensicnomicon Public
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
- archive-forensic Public
People
This organization has no public members. You must be a member to see who’s a part of this organization.
Top languages
Loading…
Most used topics
Loading…